Live Sim Feed
CLICKEDj.sharma@acmecorp.com · "Urgent: IT Password Reset" · Link clicked · Training assigned TRAINEDFinance team · 12 employees completed phishing module · Avg score 94% REPORTEDr.patel@acmecorp.com · Correctly identified and reported phishing simulation · +50 pts SUBMITTEDa.kumar@acmecorp.com · Submitted credentials on fake login page · Immediate training triggered
Gordon Security Awareness · by Mitigata

Transform Your Employees Into
Your Strongest Firewall.

Gordon Phish, powered by Mitigata's advanced AI, runs continuous, hyper-realistic phishing simulations, delivers adaptive micro-learning, and tracks every employee's security risk score in real time. Turn human vulnerability into your most impenetrable, proactive defence layer.

Realistic Phishing Simulations — test employees with up-to-date, targeted attack scenarios
Adaptive Micro-Learning — instant, role-specific training triggered on simulation failure
Employee Risk Scoring — per-user risk scores for CISO reporting and targeted remediation
91%
Breaches start with humans
73%
Click rate reduction in 90d
5 min
Per module training time
Gordon Awareness — Live Campaign
RUNNING
Platform Capabilities

What Mitigata Security Awareness Delivers.
Continuous. Adaptive. Measurable.

Phishing Simulation Campaigns

Run realistic phishing simulations using a library of up-to-date attack templates — CEO fraud, invoice scams, IT helpdesk, credential harvesting, and smishing. Campaigns are personalised per employee using their name, department, and role.

Adaptive Security Training

When an employee clicks a phishing link, they're immediately redirected to a targeted training module explaining what they missed and why. Training adapts to each employee's specific failure pattern — not generic compliance videos.

Employee Risk Scoring & Reporting

Every employee gets a Human Risk Score based on simulation performance, training completion, and reporting behaviour. CISOs get a clear view of the riskiest employees, departments, and locations at a glance.

Multi-Language Training Library

Access training modules covering phishing, password hygiene, social engineering, ransomware, data handling, and insider threats. Content is available in English, Hindi, Tamil, Telugu, and other regional languages.

Phishing Report Button

One-click phishing report button for Outlook, Gmail, and mobile. Employees who correctly report simulations earn points and recognition — creating a positive security culture rather than a blame culture.

Compliance & Board Reporting

Generate security awareness compliance reports for ISO 27001, DPDP Act, RBI IT Framework, and SEBI CSCRF — with click rates, training completion rates, and improvement trends over time.

How It Works

Simulate. Catch. Train. Improve.
Automatically.

LIVE EMPLOYEE TRAINING JOURNEY — RISK SCORE REDUCTION
LIVE CAMPAIGN
Clicked phishing link
In training
Reported phish / Safe
01

Connect Your Directory

Sync employees from Active Directory, Google Workspace, or Okta in minutes. Gordon automatically groups employees by department, role, and location for targeted campaign design.

02

Launch Simulations

Select from 50+ phishing templates or create custom ones. Gordon schedules campaigns automatically, randomises send times to avoid detection, and tracks every click, credential submission, and report.

03

Auto-Assign Training

Employees who fail receive an immediate, personalised training module. Gordon tracks completion, sends reminders, and escalates to managers if training is not completed within the SLA.

04

Track & Report

Monitor click rates, training completion, and risk scores over time. Generate compliance reports for your board, auditors, and regulators — showing measurable improvement in human risk posture.

Real-World Impact

Click rates cut.
Security culture built.

BANKING

RBI Awareness Mandate

CHALLENGE

A private bank with 3,200 employees needed to demonstrate security awareness training for RBI's IT Framework. Their existing annual training had 34% click rates on simulations.

OUTCOME

After 90 days of Gordon's adaptive simulations, click rates dropped to 6%. RBI inspection passed with zero findings on awareness training. Board received monthly risk score dashboards.

34% → 6%
Click rate
90 days
To achieve
Pass
RBI audit
IT SERVICES

Preventing BEC Attacks

CHALLENGE

An IT services firm had suffered two Business Email Compromise (BEC) incidents in 12 months, losing ₹48 lakhs. Their finance team was the highest-risk group.

OUTCOME

Gordon ran targeted CEO-fraud simulations for the finance team. After 6 weeks, the team's risk score improved from 28 to 81. Zero BEC incidents in the 18 months since deployment.

28 → 81
Risk score
0
BEC incidents
₹48L saved
Annually
HEALTHCARE

DPDP Compliance Training

CHALLENGE

A hospital chain needed to train 1,800 staff on data protection under India's DPDP Act — including doctors, nurses, and administrative staff with varying levels of tech literacy.

OUTCOME

Gordon delivered role-specific training in Hindi and English, with 5-minute modules designed for non-technical staff. 94% completion rate in 30 days. Full DPDP training documentation generated automatically.

94%
Completion rate
30 days
Full rollout
DPDP
Compliant
Pricing

Security Awareness is included in every plan.

Choose the plan that fits your team. Security Awareness features are highlighted below — scroll down to see the full platform included in every plan.

Monthly
Annual Save vs monthly
Free
$0
15-day trial
 
Get Started
Enterprise
$79,000
/yr
Save vs monthly
Start Free Trial
Custom
Custom
Flexible terms
 
Talk to Sales
Included Not available Text = Usage limit
Features Free Startup Enterprise Custom
Overview(3 features)
Gordon AI Credits (monthly)50 credits500 credits2,500 creditsCustom allocation
Dashboard
Account (User) Limit1 accountUp to 5Up to 20Unlimited
Assess(7 features)
Security Checklist (60-point)Strong & Standard onlyDynamic + AnalyticsDynamic Checklist
VAPT (Vulnerability Assessment)5 API + 10 Dynamic PagesCustom
Third Party Risk3 vendorsUnlimited
Financial Impact — Risk Quantification
Financial Impact — Security ROI
Security Awareness (Phishing Sim + Training)5 Campaigns10 Campaigns
Cyber ForceOn DemandOn Demand
All other platform modules included
Identify(8 features)Other modules
Monitored Domains1520Unlimited
Monitored IPs550500Unlimited
Monitored Web Apps1520Unlimited
Tech & Services
Phishing Risk (Lookalike Domain + Email Security)
Code Workspace (GitHub, GitLab, Bitbucket)2 WorkspacesCustom
Cloud Security ComplianceSingle Cloud (3 instances)Multi Cloud (10+)
Workforce Risk Monitoring
Monitor (SOC & Threat)(10 features)Other modules
SOC Overview5 SOC Reports
Alert Triage5,000 alerts/moUnlimited
Investigation50 investigationsUnlimited
Threat Hunting1 exerciseCustomCustom
Auto Response
Risk Monitoring5 Category dashboards
Threat Intelligence (Threats, IOCs, Campaigns)10 threats, 5 IOCs, 2 campaignsUnlimitedCustom
Alert Center
Brand Intelligence (Monitoring + Takedown)50 notifications1 Company monitoringFull + TakedownFull + Custom feeds
Dark Web MonitoringCredential & Org LeaksIndustry + APT + Recent leaks
Risk Transfer(2 features)Other modules
Cyber Insurance
Incident Hotline (24/7)
Compliance (GRC)(2 features)Other modules
GRC Module1 Policy creation1 framework3 frameworksAll + Custom
Unlimited Policy Generation
Extras & Integrations(3 features)Other modules
Integrations3 active15 activeAll 26+ & Custom API
Marketplace
Credit Add-on Packs
Support & SLA(4 features)Other modules
Support ChannelDocs onlyEmail (48h SLA)Hotline + CSM (8h SLA)24/7 Engineer (1h SLA)
Dedicated Security Engineer
White-label / MSSP
API Access

All plans include a 15-day free trial — no credit card required.

FAQ

Common questions
answered honestly.

Simulations are designed to be indistinguishable from real phishing emails. Employees are not told in advance when simulations will run — this is essential for measuring genuine susceptibility. However, your organisation's security policy should inform employees that simulations occur as part of the security programme. Gordon provides a communication template for this.
Gordon flags repeat offenders and allows you to assign intensive training tracks, require manager sign-off on completion, or escalate to HR. The platform is designed to be corrective rather than punitive — the goal is behaviour change, not blame. We recommend using risk scores for coaching conversations rather than disciplinary action.
Yes. Professional and Enterprise plans include a template builder where you can create custom phishing emails mimicking your specific vendors, internal tools, or industry-specific lures (e.g., SEBI notifications for financial firms, CDSCO alerts for pharma). Enterprise customers get custom templates built by our team.
Modules are designed for busy employees — most are 3–7 minutes long, delivered as interactive micro-learning rather than passive video. Employees can complete them on mobile during a break. Annual compliance training programmes are structured as 10-minute monthly modules rather than a single 2-hour session, which significantly improves retention.
Gordon integrates with major LMS platforms (Moodle, Cornerstone, SAP SuccessFactors) via SCORM and xAPI. Training completion data syncs back to your LMS for unified reporting. Enterprise plans include custom LMS integrations. Gordon also integrates with Active Directory, Google Workspace, Okta, and Azure AD for employee management.
Gordon's awareness programme satisfies requirements under RBI IT Framework (Section 4.5 — Security Awareness), SEBI CSCRF, IRDAI cyber security guidelines, ISO 27001 Annex A.7.2.2, DPDP Act (staff training on data protection), and SOC 2 CC1.4. Compliance reports are pre-formatted for each framework.
Get Started Today

Your employees are
your last line of defence.

91% of breaches start with a human. Make sure yours are trained, tested, and ready. Start a free phishing simulation today.

Start Free Simulation Book a Demo