Adversarial testing

    Phishing simulation software for companies in Colombia and LATAM

    Each person receives the simulation most likely to fool them specifically, and the retest later verifies they actually learned.

    How it works

    A phishing simulation is a controlled attack a company sends to itself to measure who falls, for which kind of lure, and how often. It matters because more than 90 percent of successful cyberattacks start with a phishing email (CISA): training that reflex is training the door almost everything comes through.

    Fensivo's difference is not sending everyone the same email. The system picks, for each person, the simulation most likely to make them fall, cross-referencing their past behavior, role and department, the platforms their company actually uses, and any credentials leaked about them (the signal that dark web monitoring feeds in). It sends one to three simulations per employee per month, at the right moment. For smaller companies without a dedicated team to build campaigns, that automatic matching is what makes the program operable.

    Adaptive templates, not random ones

    Around 400 curated templates

    About 200 in Spanish and 200 in English, in nine categories by the instinct they exploit: executive authority, financial pretext, urgency, and more.

    Controlled personalization

    By field substitution over reviewed templates, not AI-generated emails: it prioritizes consistency and controlled realism, without surprises.

    Smart matching lifts effectiveness over random sending, because it concentrates each test where the chance of falling is highest: more signal, less fatigue. If someone resists one kind of pretext, the system tries another until it finds their weak point. Why realism matters is detailed in personalized phishing simulations that cut real risk.

    What it measures, and what is not enough

    Each simulation records who clicks, who submits credentials, and who reports. But the click rate alone is misleading: it drops when simulations become easy or predictable. The early signal of a working culture is the report rate.

    What to look at and in what order is in report rate, click rate and retest, and how often to test by role, in how often to send simulations.

    What happens next: the retest

    Here is the differentiator: whoever falls receives, within minutes, a micro-lesson specific to the deception, and three weeks later the system sends a simulation of the same type and difficulty but with a different template. That retest validates that the person changed their behavior, not that they remembered an email, and a failure sets a risk floor that only lifts after several consecutive passes. A simulation without this step measures a one-off; with a retest it measures resilience over time.

    It is the same cycle that keeps a human risk management platform from being just a trap-email generator: the simulation feeds training and the retest validates it. The category guide is at human risk management and the full platform, at product.

    See a real simulation from your industry

    A 30-minute demo with simulated data from your sector. Live in 1 day via OAuth; first report with risk scores in 48 hours. From 25 employees.

    Per-employee pricing on the calculator. Honest comparisons with other platforms at Fensivo vs. KnowBe4.