Skip to content

Phishing simulation

Test your teams before a real attacker does

Send realistic phishing simulations. Those who fall for them get an instant micro-lesson. Track progress by department and adjust scenarios.

Phishing simulation illustration
The cost of a click

Phishing by the numbers: what's at stake for an SMB

€130,000

average cost per incident

Ransom, business interruption, legal fees, regulator notification. The real cost of a cyberattack for an SMB under 250 employees.

Source: Hiscox Report, 2023

43%

of SMBs affected

of French SMBs experienced at least one cyberattack in 2025. One in two via phishing email.

Source: CESIN Barometer, 2025

86%

reduction

reduction in click rate after 12 months of regular simulations with point-of-error training.

Source: KnowBe4, 2025

How it works

Your teams get tested. Those who fall for it learn. You see everything.

01
Step: Import your team
01

Import your team

Copy-paste from your directory or connect Active Directory. One coffee and you're done.

02
Step: Turn on autopilot
02

Turn on autopilot

You configure once. nophi.sh sends the right campaigns to the right people, with gradual difficulty and randomized scenarios each time. Fake WeTransfer, fake supplier follow-up, fake CEO message.

03
Step: Those who click get a micro-lesson
03

Those who click get a micro-lesson

3 minutes, on the exact mistake they just made. You track progress by department in your dashboard.

What makes our simulations realistic

What makes our simulations believable

Realistic, varied domains

Automatic rotation across multiple credible sending domains. Each campaign uses a different sender.

Templates based on real threats

Fake WeTransfer, fake DocuSign, fake management requests. Inspired by the campaigns ANSSI documents each quarter.

Staggered, smart delivery

Emails arrive at different times, across several days. Not 50 identical emails on Monday at 9am.

Per-department results

Accounting clicks more than marketing? You'll know. Risk score per team, 6-month trends.

9:47
ModifierBoite de reception
MD
Marie Dupont9:41
Re: Devis Q2 valide
Super, je transmets au service...
S
Slack9:38
3 messages non lus
Pierre: La reunion de 14h est...
O
OVHcloud9:15
Votre facture de mars
Montant : 47,90 EUR - Votre...
9:48
Boite de reception
D
DocuSign <docu-sign@notif-secure.com>
a : j.martin@entreprise.fr
Signature requise - Facture #F-2847
DocuSign

Bonjour Julien,

La facture #F-2847 de TECH SOLUTIONS LTD necessite votre signature.

Ce document expire dans 24 heures.

CONSULTER ET SIGNER
Propulse par DocuSign • Ne pas repondre
9:48
micros0ft-login.com
Microsoft
Sign in
j.martin@entreprise.fr
Password
Sign in
Forgot my password
No account? Create one!
9:48
C'etait un test
Cet email etait une simulation envoyee par votre equipe securite via nophi.sh
Signaux d'alerte
Domaine « notif-secure.com » ≠ docusign.com
Urgence artificielle : « expire dans 24h »
Faux portail : micros0ft-login.com
Commencer la micro-formation →
9:49
Email 1/5
Score 0🔥 0
DG
Direction Generale
direction.generale@acme-corp-group.com
FACILE
Urgent et confidentiel - Mise a jour virement

Bonjour,

Les coordonnees bancaires pour les redevances ont ete mises a jour. Veuillez telecharger les nouvelles instructions.

https://secure-transfer-portal.com/wire

Merci de traiter avec discretion.

LEGITIME
PHISHING
nophi.sh • Security Awareness Training
9:49
Email 1/5
Score 0🔥 0
DG
Direction Generale
direction.generale@acme-corp-group.com
FACILE
Urgent et confidentiel - Mise a jour virement

Bonjour,

Les coordonnees bancaires pour les redevances ont ete mises a jour. Veuillez telecharger les nouvelles instructions.

https://secure-transfer-portal.com/wire

Merci de traiter avec discretion.

LEGITIME
PHISHING
nophi.sh • Security Awareness Training
9:52
Formation terminee !
Score : 4/5 - Bon reflexe !
Votre score de securite
C+
Avant
B
Apres
Votre score a ete ameliore ↑
Measured results

Click rates drop. The numbers prove it.

Before

30%

Average phishing email click rate, all industries

After 6 months

<5%

After a regular simulation program with point-of-error training

-86%

KnowBe4 Phishing By Industry Benchmarking Report 2025 - 67.7 million simulations

First campaign in 15 minutes

15 minutes to configure. First results the same day.

Hosted in France
GDPR compliant
French-speaking support