Regulatory Note: OCR fines and state AG investigations can follow a single patient complaint or breach notification. Compliance is not optional.
Most organizations don't know — and the answer is usually higher than expected. First-run simulated phishing campaigns consistently show 20–35% click rates before training intervention. Book a free phishing simulation assessment and find out what your actual number is, not what you estimate it to be.
No disruption. No lengthy onboarding. A fast, smooth transition to a partner that has your back from day one.
A Gradius security specialist assesses your current phishing simulation and security awareness program — whether simulations are being run, what click rates look like, whether compliance documentation is current, and what the first simulated campaign would reveal about the organization's actual susceptibility. At no cost, no obligation.
A continuous phishing simulation program — realistic campaigns delivered on a defined schedule (typically monthly or quarterly), click rate reporting by employee and department, immediate just-in-time training for employees who click, escalating simulation difficulty as click rates improve, and compliance documentation generated after every campaign. Flat-rate per user.
Our engineers deploy, configure, and meet your team — typically live within 1–2 weeks without disrupting daily operations.
Click rate trends tracked across every campaign; compliance documentation current and organized; simulation templates updated to reflect current attack patterns; executive and high-risk user campaigns run on a separate schedule; and quarterly phishing simulation reviews that report on progress against baseline and industry benchmarks.
Gradius phishing simulation services include: realistic simulated phishing campaigns — industry-specific templates reflecting actual attack patterns, delivered on a monthly or quarterly schedule; click rate tracking — individual employee-level reporting identifying who clicked, who reported, and who opened without clicking; immediate just-in-time training — employees who click receive targeted training at the moment of the simulated click, explaining what made the email suspicious and what they should do next time; executive and high-risk user simulations — BEC-style campaigns targeting executives, finance staff, and other high-value targets; escalating difficulty — as click rates improve, simulation difficulty increases to maintain training effectiveness; and compliance documentation — campaign records, click rate reports, training completion documentation, and aggregate metrics for HIPAA, PCI, SEC, and other framework requirements. Continuous program, flat-rate per user.
First-run phishing simulation click rates for organizations without prior simulation consistently fall in the 20–35% range — meaning one in four to one in three employees clicks a simulated phishing link on the first campaign. This is not an indictment of employees — it reflects the effectiveness of modern phishing techniques and the reality that most employees have not been tested in a realistic context. Industry variations exist: organizations in financial services and healthcare, where employees deal with more targeted attacks, sometimes show lower baseline rates due to prior exposure; organizations in industries with less historical phishing attention sometimes show higher rates. After six to twelve months of continuous simulation with just-in-time training, well-run programs typically reduce click rates to under 5%. The first-run baseline is the starting point, not the destination.
This is the most common management concern about phishing simulation — and it's worth addressing directly. Research on security awareness training consistently shows that immediate, non-punitive just-in-time training after a simulated click is the most effective behavior change mechanism. The key is framing: employees should understand that phishing simulation is a training tool, not a surveillance or discipline mechanism. The message to employees is that simulated phishing is how the organization keeps its defenses strong, that clicking a simulated phishing link is how you learn to recognize the real ones, and that reporting a suspicious email is always the right action. Gradius recommends communicating the phishing simulation program to employees in advance — explaining the program's purpose and framing it as part of the organization's security culture rather than a test. This framing actually improves training effectiveness and increases report rates.
Several major compliance frameworks either require or strongly recommend phishing simulation as part of a security awareness program. HIPAA's Security Rule requires covered entities to implement a security awareness and training program — and OCR audit protocols specifically look for evidence that training addresses phishing, that training is ongoing rather than annual-only, and that training effectiveness is evaluated. PCI DSS Requirement 12.6 requires security awareness training that includes education on phishing attacks, and the spirit of the requirement includes testing as well as education. NIST CSF includes security awareness training in the Protect function (PR.AT). SEC cybersecurity rules for registered advisors include security awareness training as an expected component of a documented cybersecurity program. Cyber insurance carriers increasingly require documented phishing simulation as a condition of coverage or as a factor in premium calculation. Gradius generates the documentation that satisfies these requirements after every campaign.
No long-term lock-ins. We offer month-to-month and annual agreements. Organizations stay with Gradius phishing simulation because click rates decline measurably over time, compliance documentation is current when auditors ask, and the simulation program is continuously updated to reflect current attack patterns rather than stagnating. We earn the renewal every month through measurable security improvement.
We serve 12+ industries in NJ, NY & CT including healthcare, legal, financial services, construction, manufacturing, real estate, insurance, architecture, professional services, restaurants, nonprofits, and general business — each with specialized compliance and operational expertise built in.
Gradius IT Solutions serves businesses throughout the Tri-State area. Headquartered in Hackensack, NJ with coverage across Bergen, Hudson, Passaic, Essex, Union, Morris, Middlesex, Somerset, Sussex, Westchester, Rockland, and Fairfield Counties.