GRCLens platform module · International

PhishLens — Phishing Simulation & Awareness compliance software

Test and evidence security awareness — phishing campaigns, click analytics and executive reporting that feed your compliance frameworks.

Overview

What PhishLens requires

PhishLens is GRCLens's phishing simulation module: build campaigns from realistic templates, schedule dispatch to targeted recipient groups, and measure outcomes from delivery through click to repeat-clicker risk.

Awareness controls appear in nearly every framework — NCA-ECC's awareness domain, ISO 27001's people controls, PDPL's training obligations. Frameworks ask for evidence that awareness is tested, not just taught; simulation results are exactly that evidence.

Campaign analytics separate executive reporting from operational follow-up: leadership sees trend and risk concentration, while awareness teams see who needs targeted training — with results attachable to the controls they evidence.

Who it applies to

  • Security awareness teams running simulation programmes
  • Organisations evidencing awareness controls for ECC, ISO 27001 or PDPL
  • Enterprises measuring phish-prone rates and repeat-clicker risk
  • Tenants running multi-department campaigns with branded templates

At a glance

  • Module type: Operational workspace (product module)
  • Core objects: Campaigns, templates, recipients, click analytics
  • Analytics: Delivery, opens, clicks, repeat-clickers, phish-prone rate
  • Output: Executive and operational dashboards; PDF/Word campaign reports
In the platform

How GRCLens supports PhishLens

PhishLens runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.

Campaign engine

Template-driven campaigns with scheduling, targeted recipient groups and safe dry-run dispatch.

Click and risk analytics

Delivery-to-click funnels, repeat-clicker identification and phish-prone trends across campaigns.

Executive reporting

Exportable campaign reports for leadership and audit use, with per-department breakdowns.

Framework evidence

Attach campaign results to the awareness controls they evidence in ECC, ISO 27001, PDPL and other assessments.

Questions

PhishLens frequently asked questions

Is PhishLens a compliance framework?

No — it is a simulation module. It produces the tested-awareness evidence that framework controls require.

Can campaigns be branded per tenant?

Yes. Tenants configure sender identity and branding, with administrative limits on targets and permitted domains.

How are results used in assessments?

Campaign reports and metrics attach as evidence to awareness and training controls, giving assessors measured outcomes rather than attendance sheets.

Is dispatch safe to test?

Campaigns support dry-run dispatch for validation before any live send, and sending is confined to configured domains.

Talk to us about PhishLens

Security Solution Consultants provides Awareness programme advisory alongside the platform, so you can combine tooling with hands-on expertise.

Contact us