Live Sim Feed
CLICKEDj.sharma@acmecorp.com · "Urgent: IT Password Reset" · Link clicked · Training assigned TRAINEDFinance team · 12 employees completed phishing module · Avg score 94% REPORTEDr.patel@acmecorp.com · Correctly identified and reported phishing simulation · +50 pts SUBMITTEDa.kumar@acmecorp.com · Submitted credentials on fake login page · Immediate training triggered
Gordon Security Awareness · by Mitigata

Transform Your Employees Into
Your Strongest Firewall.

Gordon Phish, powered by Mitigata's advanced AI, runs continuous, hyper-realistic phishing simulations, delivers adaptive micro-learning, and tracks every employee's security risk score in real time. Turn human vulnerability into your most impenetrable, proactive defence layer.

Realistic Phishing Simulations — test employees with up-to-date, targeted attack scenarios
Adaptive Micro-Learning — instant, role-specific training triggered on simulation failure
Employee Risk Scoring — per-user risk scores for CISO reporting and targeted remediation
91%
Breaches start with humans
73%
Click rate reduction in 90d
5 min
Per module training time
Gordon Awareness — Live Campaign
RUNNING
Platform Capabilities

What Mitigata Security Awareness Delivers.
Continuous. Adaptive. Measurable.

Phishing Simulation Campaigns

Run realistic phishing simulations using a library of up-to-date attack templates — CEO fraud, invoice scams, IT helpdesk, credential harvesting, and smishing. Campaigns are personalised per employee using their name, department, and role.

Adaptive Security Training

When an employee clicks a phishing link, they're immediately redirected to a targeted training module explaining what they missed and why. Training adapts to each employee's specific failure pattern — not generic compliance videos.

Employee Risk Scoring & Reporting

Every employee gets a Human Risk Score based on simulation performance, training completion, and reporting behaviour. CISOs get a clear view of the riskiest employees, departments, and locations at a glance.

Multi-Language Training Library

Access training modules covering phishing, password hygiene, social engineering, ransomware, data handling, and insider threats. Content is available in English, Hindi, Tamil, Telugu, and other regional languages.

Phishing Report Button

One-click phishing report button for Outlook, Gmail, and mobile. Employees who correctly report simulations earn points and recognition — creating a positive security culture rather than a blame culture.

Compliance & Board Reporting

Generate security awareness compliance reports for ISO 27001, DPDP Act, RBI IT Framework, and SEBI CSCRF — with click rates, training completion rates, and improvement trends over time.

How It Works

Simulate. Catch. Train. Improve.
Automatically.

LIVE EMPLOYEE TRAINING JOURNEY — RISK SCORE REDUCTION
LIVE CAMPAIGN
Clicked phishing link
In training
Reported phish / Safe
01

Connect Your Directory

Sync employees from Active Directory, Google Workspace, or Okta in minutes. Gordon automatically groups employees by department, role, and location for targeted campaign design.

02

Launch Simulations

Select from 50+ phishing templates or create custom ones. Gordon schedules campaigns automatically, randomises send times to avoid detection, and tracks every click, credential submission, and report.

03

Auto-Assign Training

Employees who fail receive an immediate, personalised training module. Gordon tracks completion, sends reminders, and escalates to managers if training is not completed within the SLA.

04

Track & Report

Monitor click rates, training completion, and risk scores over time. Generate compliance reports for your board, auditors, and regulators — showing measurable improvement in human risk posture.

Real-World Impact

Click rates cut.
Security culture built.

BANKING

RBI Awareness Mandate

CHALLENGE

A private bank with 3,200 employees needed to demonstrate security awareness training for RBI's IT Framework. Their existing annual training had 34% click rates on simulations.

OUTCOME

After 90 days of Gordon's adaptive simulations, click rates dropped to 6%. RBI inspection passed with zero findings on awareness training. Board received monthly risk score dashboards.

34% → 6%
Click rate
90 days
To achieve
Pass
RBI audit
IT SERVICES

Preventing BEC Attacks

CHALLENGE

An IT services firm had suffered two Business Email Compromise (BEC) incidents in 12 months, losing ₹48 lakhs. Their finance team was the highest-risk group.

OUTCOME

Gordon ran targeted CEO-fraud simulations for the finance team. After 6 weeks, the team's risk score improved from 28 to 81. Zero BEC incidents in the 18 months since deployment.

28 → 81
Risk score
0
BEC incidents
₹48L saved
Annually
HEALTHCARE

DPDP Compliance Training

CHALLENGE

A hospital chain needed to train 1,800 staff on data protection under India's DPDP Act — including doctors, nurses, and administrative staff with varying levels of tech literacy.

OUTCOME

Gordon delivered role-specific training in Hindi and English, with 5-minute modules designed for non-technical staff. 94% completion rate in 30 days. Full DPDP training documentation generated automatically.

94%
Completion rate
30 days
Full rollout
DPDP
Compliant
Pricing

Full-Stack Cyber Resilience, Powered by AI.

Choose the plan that fits your team. Upgrade or cancel anytime.

Monthly
Annual SAVE VS MONTHLY
Free
$0
15-day trial
 

Explore the platform with limited access. No credit card required.

Get Started
Mid-Market
$33,820
/yr
Save ~$6,764 vs monthly

For companies with 100–500 employees. Expanded limits across all modules.

Start Free Trial
Enterprise
$66,070
/yr
Save ~$13,214 vs monthly

For large enterprises 500+ employees. Unlimited scale, dedicated support, and custom SLAs.

Talk to Sales
Included Not available limit = Usage limit
Features Free Startup
$1,787/mo
Mid-Market
$3,382/mo
Enterprise
$6,607/mo
Attack Surface Monitoring12 scans/year
Monitored Assets (Domains, IPs, Mobile Apps)3 assets10 assets
Exposed subdomains & open ports
SSL/TLS certificate health
DNS anomalies & misconfigurations
Web technology fingerprinting
CVE & vulnerability scoring
Continuous monitoring & alerts
SOC Monitoring24/7
Monitored EndpointsUpto 500Upto 2,000
AI-powered alert triage
Kill-chain reconstruction (MITRE ATT&CK)
Automated response playbooks
CERT-In 6-hour incident reporting
Threat intelligence (IOCs, Campaigns)50 threats, 20 IOCsUnlimited
Workforce Risk & Security Awareness
Monitored EmployeesUpto 500Upto 2,000
Email phishing simulation
Custom phishing templates
Security awareness training + LMS
Dark Web Monitoring
Monitored Keywords (brand, legal name, vendors)1 keyword5 keywords
Tor forums, paste sites, Telegram channels
Breach databases & data dumps
Ransomware & APT group monitoring
Cloud Security & Billing Monitoring
Cloud Instances Monitored2 instances5 instances
Misconfiguration detection (CIS 572 benchmark)
IAM & privilege escalation checks
S3 / Blob public exposure alerts
Cloud billing tracking & optimisation
GRC & ComplianceAudit charges extra
Compliance Frameworks4 frameworks5 frameworks
Automated control mapping
AI gap assessment & remediation tasks
Policy & procedure auto-generation
Risk register automation
AI-based internal audit & audit-ready reports
Trust center
Third Party Risk Management (TPRM)
Vendors Monitored250 vendors1,000 vendors
AI security questionnaire dispatch & scoring
Continuous external surface scan
Breach & dark web alerts for vendor
Risk rating (A–F) with trend
Gordon AI
AI Credits / Tokens1,000 credits1,000 credits
Auto-generated risk narratives
One-click remediation playbooks
Executive summary generation
AI-assisted questionnaire filling (CRQ)
Threat intelligence summaries
Brand Intelligence & Takedowns
Brand Assets Monitored3 assets, 60 keywords5 assets, 100 keywords
Fake domain / phishing page / typosquat monitoring
Reverse imaging / logo detection
Social media & counterfeit listing monitoring
Takedowns (Rogue app, DMCA, Phishing pages)100 takedowns125 takedowns
Consent Manager (DPDPA)
Unique Consents (website / mobile app users)100K consents500K consents
Granular consent collection & withdrawal
15+ platform integrations
22 Indian language translation (DPDPA Art. 18)
Cookie scanner, data deletion & grievance requests
Google Consent Mode V2 support

All plans include a 15-day free trial — no credit card required.

FAQ

Common questions
answered honestly.

Simulations are designed to be indistinguishable from real phishing emails. Employees are not told in advance when simulations will run — this is essential for measuring genuine susceptibility. However, your organisation's security policy should inform employees that simulations occur as part of the security programme. Gordon provides a communication template for this.
Gordon flags repeat offenders and allows you to assign intensive training tracks, require manager sign-off on completion, or escalate to HR. The platform is designed to be corrective rather than punitive — the goal is behaviour change, not blame. We recommend using risk scores for coaching conversations rather than disciplinary action.
Yes. Professional and Enterprise plans include a template builder where you can create custom phishing emails mimicking your specific vendors, internal tools, or industry-specific lures (e.g., SEBI notifications for financial firms, CDSCO alerts for pharma). Enterprise customers get custom templates built by our team.
Modules are designed for busy employees — most are 3–7 minutes long, delivered as interactive micro-learning rather than passive video. Employees can complete them on mobile during a break. Annual compliance training programmes are structured as 10-minute monthly modules rather than a single 2-hour session, which significantly improves retention.
Gordon integrates with major LMS platforms (Moodle, Cornerstone, SAP SuccessFactors) via SCORM and xAPI. Training completion data syncs back to your LMS for unified reporting. Enterprise plans include custom LMS integrations. Gordon also integrates with Active Directory, Google Workspace, Okta, and Azure AD for employee management.
Gordon's awareness programme satisfies requirements under RBI IT Framework (Section 4.5 — Security Awareness), SEBI CSCRF, IRDAI cyber security guidelines, ISO 27001 Annex A.7.2.2, DPDP Act (staff training on data protection), and SOC 2 CC1.4. Compliance reports are pre-formatted for each framework.
Get Started Today

Your employees are
your last line of defence.

91% of breaches start with a human. Make sure yours are trained, tested, and ready. Start a free phishing simulation today.

Start Free Simulation Book a Demo