Human Cyber Risk, Measured

Prove your team can spot a phishing email

We run realistic phishing simulations for small and mid sized businesses, then give you the documented results. One week to run. Nothing installed on your side.

One week to run • Nothing installed • Insurer-ready reporting

Line graph shows risk score dropping from 30% in Q1 2025 to 15% in Q2 2026; bars show click rates by department
Sample results

Human risk, measured before and after

Workforce click rate dropped from 31.2% baseline to 9.6% close-out, a 21.6-point reduction.
Why NopTrace

A platform gives you software. NopTrace gives you the work done.

Traditional security-awareness platforms

Software-first. You configure and run the campaigns yourself. Generic reporting, primarily training-focused.

NopTrace

Service first. We run the whole cycle for you: scenario design, delivery, targeted remediation, before and after measurement, and a report written to be handed to someone.

What it costs

Priced for businesses without a security team

We handle the operational work so phishing testing becomes a simple quarterly cost rather than a project you have to staff.

The report

You get more than a phishing report

Campaign results. Human-risk metrics. Department-level analysis. Before/after measurement. Remediation tracking. Executive summary. Close-out documentation.

View the Sample Report
Service

Documented phishing defense quarterly

Cyber insurance applications ask whether your staff are tested on phishing. We run the simulations and produce the documentation, every quarter, without new software.

Deliverable

Initial risk report

A clean record of where your employees stand today, dated and ready to hand to your insurer.

NopTrace baseline report shows 31.2% clicked lure, 12.4% self-reported risk, 1,284 employees tested across six departments.
Deliverable

Vulnerability breakdown

We identify the specific people and departments carrying real risk. Not a pass or fail score.

Chart showing risk score at 31% for Q2 2026 and department click-through rates with Finance highest at 44.9%.
Deliverable

Before and after comparison

Proof the risk is dropping, built to serve as due-diligence evidence for auditors and insurers.

Workforce click rate drops from 31.2% baseline to 9.6% close-out, a 21.6-point reduction.
Cycle

Four stages repeat quarterly

A structured cycle that proves risk is decreasing.

Baseline where employees stand

We test everyone with a realistic simulated phishing email.

Target who carries risk

We identify the specific people and departments that clicked.

Educate the specific gap

We assign training that addresses the exact tactic they missed.

Retest to prove improvement

We run the simulation again and document the before and after.

Delivery

No software to install

We run simulations through GoPhish, or through Microsoft Attack Simulator if you already have Defender or E5. We manage the entire cycle.

Tool

GoPhish simulation engine

An open-source platform we configure and run for you. No setup on your side.

Tool

Microsoft Attack Simulator

If you already pay for Defender or E5, we use the licence you have rather than adding another tool.

Delivery

Fully done-for-you

We run the simulations, review the results, and prepare the reports.

Positioning

Built for SMB scale

KnowBe4 and Proofpoint are built for enterprise security teams and long procurement cycles. NopTrace is scoped and priced for businesses that do not have either.

Pricing

A predictable quarterly cost

One quarterly figure you can budget for. Not a one-off project fee.

Scope

Right-sized for smaller businesses

No enterprise overhead. No long procurement cycle. Just the testing and the documentation.

Credibility

Built on enterprise program experience

We have built and run enterprise phishing programs across member firms in more than 20 countries. The same program, sized for businesses without a security team.

Evidence

Reports you can hand over

Every stage produces a concrete deliverable for insurers and auditors.

Simplicity

Nothing to install or manage

We use GoPhish or Microsoft Attack Simulator. Your team does nothing.

Commitment

No long-term lock-in

A quarterly service you can start or stop as you need it.

See NopTrace in Action

Want to know where your team actually stands? A baseline simulation takes a week.

Cyber insurance applications now ask whether your staff are tested on phishing

60%

Of breaches involve the human element (error, social engineering, or misuse)

81%

Of organizations have security awareness training as a cyber-insurance coverage prerequisite

$4.8M

Average cost of a phishing-initiated breach

Sources: Verizon 2025 Data Breach Investigations Report; IBM Cost of a Data Breach Report, 2025; Huntress 2025 Cyber Insurance Trends Report.

For your leadership team

Evidence executives can actually use

NopTrace turns employee behavior into measurable evidence that can support security reviews, executive reporting, cyber-insurance discussions, compliance conversations, and security-awareness planning.

Illustrative example, not an actual client

What this looks like in practice

Meridian Logistics Group, a hypothetical 1,284-employee company across 6 departments, is the scenario used throughout this site's sample report. Baseline testing showed a 31.2% click rate. After one cycle of targeted remediation, close-out testing showed 9.6%, a 21.6-point reduction the business could hand directly to its insurer as documented evidence.

See the full sample report
Trust

Controlled by design

Simulations are authorized by the customer and run in a controlled manner. Real credentials are never captured or stored. Campaign data is encrypted in transit and at rest, access is limited to your assigned analyst, and nothing is sold or shared with third parties. Reporting is built around security outcomes, and customer data is handled according to the applicable agreement and our Privacy Policy.