Phished Security Awareness Training
Phished is the security awareness training and phishing simulation platform 4iT deploys as standard for Australian businesses. Its argument, which matches what we see in practice, is that sending staff a test phishing email and recording who clicked does not by itself change behaviour. What changes behaviour is what happens in the moments after someone clicks, delivered automatically, at the right level of difficulty, and often enough that it sticks. Phished automates that loop so the training runs continuously rather than turning into an annual exercise nobody remembers.
Sydney MSP
Greater Sydney, NSW
- Microsoft Partner
- Sophos Partner
- Ubiquiti Partner
ISO 27001
or SOC 2 Access revoked the moment staff leave

Key facts
- Phished is a Belgian company headquartered in Leuven. It reports more than 6,500 customer organisations and around 250 partners across North America and Europe.
- Phishing simulations are AI-generated and levelled to each user, so a person who spots the obvious attempts moves up to harder ones instead of receiving the same test as everyone else.
- Phished Academy is the training side: short gamified sessions with certificates, across a curriculum spanning roughly 360 cyber topics, rather than one long annual module.
- Zero Incident Mail is a contained environment for the training, so a staff member who clicks a simulated link or opens an attachment is handled without the click reaching your infrastructure.
- The platform is multi-tenant and built for delivery by managed service providers, which is how 4iT runs it across client environments.
- Phished holds ISO 27001 and SOC 2 certification and maps to NIS2, DORA, NIST, PCI DSS and Cyber Essentials, which matters when a client is answering a security questionnaire or an insurer.
- 4iT deploys Phished as our standard platform for staff awareness training and phishing simulation, and runs it as a managed service rather than handing you a login and a dashboard.
Why does most phishing training fail to change anything?
Because it is built around measurement rather than learning. A typical programme sends the same simulated email to everyone once a quarter, produces a click rate, and stops there. The people who clicked get a note or a module weeks later, by which time the connection between the mistake and the lesson has gone. The people who did not click learn nothing at all, and the difficulty never increases, so the test stops measuring anything useful after the second round.
The other failure is repeat offenders. Every business has a handful of people who click more than once, and they carry a disproportionate share of the risk. A quarterly campaign with a shared report does not address them specifically, and singling them out manually is awkward and rarely done. Automated, individualised training is the only practical answer at SME scale, because nobody in a small business has time to run a tailored programme per person.
What does Phished do differently?
Three things worth understanding. The simulations adapt per person, so difficulty rises with demonstrated skill and the exercise keeps working past the first few rounds. The training triggers at the moment of the mistake rather than in a monthly report, which is when it is most likely to land. And the whole cycle is automated once configured, which is the difference between a programme that runs for years and one that quietly stops when the person managing it gets busy.
Zero Incident Mail is the part most competitors do not have. Training staff by sending them realistic phishing attempts creates a genuine tension: you want people to click so they learn, but a click on a link in a real inbox is exactly the behaviour you are trying to prevent. Phished contains the interaction so the lesson happens without the risk. It also means you can safely run harder simulations, which is where the useful learning is.
The Academy side is deliberately short-form. Brief sessions with certificates across a wide topic range work better in an SME than a one-hour annual module, because they fit into a working day and they repeat often enough to build habit. See our security awareness training page for how we structure a programme.
How does 4iT deploy and run it?
We set up your tenant, import staff from your directory so the user list maintains itself, configure simulation frequency and difficulty against how much risk your business carries, and allow-list the platform correctly so simulations reach inboxes rather than being caught by your own filtering. That last step is where self-managed rollouts most often go wrong, and a simulation that never arrives teaches nobody anything.
From there we run it as an ongoing service. We watch the results, follow up on repeat clickers, brief you on where the business stands rather than forwarding a dashboard, and connect the reporting to the evidence you need for insurance and client questionnaires. Awareness training is one layer, and it works alongside email and spam protection, multi-factor authentication and password management. Training reduces how often someone clicks; the technical layers decide what happens when they do.
Frequently Asked Questions
Phishing simulation is the test: controlled fake phishing emails sent to your own staff to see who clicks, reports it, or enters data. Security awareness training is the teaching, covering how attacks work and what to do about them. Simulation without training measures a problem without fixing it, and training without simulation produces staff who can describe phishing in theory but have never had to spot one under normal working pressure. A programme needs both, which is why the platforms bundle them.
It does when it is continuous, individualised and paired with immediate training, and it largely does not when it is a quarterly test with a report. The mechanisms that matter are frequency, so the skill stays current; difficulty that rises with the person's ability, so the exercise keeps teaching; training delivered at the moment of the mistake rather than weeks later; and specific follow-up on repeat clickers, who carry most of the risk. A programme missing those tends to produce a click rate that plateaus and stops improving.
It is a fair concern and it comes down to how the programme is framed. Handled badly, with public naming or an implication that clicking is a disciplinary matter, it damages trust and staff stop reporting real incidents, which is a worse position than where you started. Handled well, it is presented up front as training rather than a trap, results are used to direct support rather than blame, and reporting a suspicious email is treated as the win. We set programmes up on that basis, and we would push back on any request to use the results punitively.
Continuously rather than on a quarterly schedule, which is the shift that separates a programme that works from one that produces a report. Each person should receive simulations at a frequency and difficulty matched to how they have performed, so someone who consistently spots and reports attempts is tested less often but harder, while someone who has clicked recently sees more. That is impractical to run by hand, which is why it needs to be automated. In practice we configure it once against the risk the business carries and then leave it running, reviewing the direction of travel rather than chasing individual campaigns.
If your staff training is currently an annual module nobody remembers, or you are running simulations that have stopped improving anything, we can set up a programme that runs continuously and report on what it is doing. Request a callback and we will scope it for your team size.
Ready to Talk to a Sydney IT Specialist?
4iT Support covers SMEs across Greater Sydney including the Hills District, North Shore, Parramatta, and the CBD. No lock-in contracts. Straight answers.







