Use cases

    Use cases by role and by company type

    What each role gets, in which phases, and how the program looks depending on your company's size and sector. Only with what Fensivo does today.

    By role

    What each role gets, and in which phases

    Pick a role. The diagram on the right walks through the program's phases from day 1.

    CISO / Head of Security

    I need to show the board that human risk is under control

    Your situation

    The board asks how exposed our people are, and the only available answer is a course completion rate, which measures activity, not risk. You need a behavioral measure per person that holds up in front of the board, the insurer and the auditor.

    What you get

    • Risk score per person and per areaCalculated on how each person behaves under a simulated attack, not on completed courses, and tracked over time.
    • First executive report in 48 hoursA one-page PDF for the board. It starts with the credentials from your domain already circulating in more than 680 public breach databases and on the dark web.
    • A cycle that runs on its ownOne to three simulations per person per month, micro-learning minutes after a failure and a retest three weeks later. No team needed to build campaigns.
    • A dated record of every eventExposure, simulation, failure, micro-learning and retest are all logged, to back what you show the board and the auditor.
    See pricing

    The number you defend

    Risk score

    per person and per area, with its evolution over time

    The phases, in order

    Advances on its own; tap a phase to stop it
    By company type

    How the program looks by your size and sector

    The product is the same. What changes is who runs it, what they look at first and which deceptions resemble their daily work.

    No security team: the program runs on its own

    Who runs it: Run by the IT manager or general management, without dedicating hours to it.

    • OAuth connection in 1 day, no agents and no implementation consulting.
    • First executive report in 48 hours: the first concrete conversation about human risk with management.
    • Simulations are chosen and sent automatically, one to three per person per month. Nobody builds campaigns.
    • Minimum 25 employees: below that, the per-person score is not valid.

    The program's pace for your company

    Move the slider: the cycle sizes itself.

    80employees
    25500
    simulated emails per month
    80 a 240
    one to three per person
    people with a risk score
    80
    first executive report
    48 h
    to be operational
    1 day

    Minimum 25 employees. Over 500, Enterprise plan by quote.

    Calculate your investment

    Four sectors, four typical deceptions

    Financial services and fintech

    The typical deception
    The urgent order to approve a payment or the vendor changing bank accounts: executive authority and financial pretext, at month end.
    How the program responds
    Simulations from those categories for treasury, operations and sales; domain credentials monitored 24/7.
    What it measures
    Score per area and a dated record of every event, for the auditor or the regulator.

    Technology and SaaS

    The typical deception
    Fake repository and cloud-provider alerts, requests for access to production.
    How the program responds
    Simulations matched to the real stack, no agents; monitoring of technical credentials and shared accounts.
    What it measures
    Who needs reinforcement (MFA, permissions) before widening access.

    Healthcare

    The typical deception
    Medical record requests, urgent results, appointments: the pretext uses patient data and the urgency of care.
    How the program responds
    Each person gets the simulation closest to their daily work; micro-learning within minutes, without pulling anyone off their shift.
    What it measures
    A dated record per event, useful for data-protection audits.

    Professional services and BPO

    The typical deception
    The client asking for something urgent, the shared document that must be opened now. Many mailboxes and high turnover.
    How the program responds
    A perpetual cycle: nobody builds campaigns; simulations are chosen and sent on their own, month after month, and the retest validates whoever fell.
    What it measures
    Score per person and per area, to show the client the operation is covered.
    Why act now

    The context, from neutral sources

    90%+

    of successful cyberattacks begin with a phishing email.

    Source: CISA

    62%

    of the breaches analyzed in Verizon's 2026 DBIR involved the human element, up from 60% the previous year.

    Source: Verizon DBIR 2026

    3 times

    more effective is AI-driven phishing today compared with traditional campaigns.

    Source: Microsoft Digital Defense Report 2025

    4.4 million

    dollars was the average cost of a data breach in 2025, down 9% from the previous year thanks to faster identification and containment.

    Source: IBM Cost of a Data Breach 2025

    What Fensivo does today

    So that no use case promises more than the product delivers.

    Discover the product
    • Email is the simulation channel; quishing is included, because the QR code arrives inside the email.
    • No simulations by SMS, phone call or WhatsApp: those deceptions are trained as behavior and validated with a retest.
    • Companies with 25 to 500 employees on Google Workspace or Microsoft 365. Over 500, by quote.
    • The figures on this page come from product design or neutral sources, never from customer results.
    Next step

    Pick your role and see it with simulated data from your sector

    A 30-minute demo. Operational in 1 day via OAuth; first executive report in 48 hours.

    Public terms, no hidden lock-in
    Operational in 1 day
    Support in Spanish