PhishLens — Phishing Simulation & Awareness compliance software
Test and evidence security awareness — phishing campaigns, click analytics and executive reporting that feed your compliance frameworks.
What PhishLens requires
PhishLens is GRCLens's phishing simulation module: build campaigns from realistic templates, schedule dispatch to targeted recipient groups, and measure outcomes from delivery through click to repeat-clicker risk.
Awareness controls appear in nearly every framework — NCA-ECC's awareness domain, ISO 27001's people controls, PDPL's training obligations. Frameworks ask for evidence that awareness is tested, not just taught; simulation results are exactly that evidence.
Campaign analytics separate executive reporting from operational follow-up: leadership sees trend and risk concentration, while awareness teams see who needs targeted training — with results attachable to the controls they evidence.
Who it applies to
- Security awareness teams running simulation programmes
- Organisations evidencing awareness controls for ECC, ISO 27001 or PDPL
- Enterprises measuring phish-prone rates and repeat-clicker risk
- Tenants running multi-department campaigns with branded templates
At a glance
- Module type: Operational workspace (product module)
- Core objects: Campaigns, templates, recipients, click analytics
- Analytics: Delivery, opens, clicks, repeat-clickers, phish-prone rate
- Output: Executive and operational dashboards; PDF/Word campaign reports
How GRCLens supports PhishLens
PhishLens runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.
Campaign engine
Template-driven campaigns with scheduling, targeted recipient groups and safe dry-run dispatch.
Click and risk analytics
Delivery-to-click funnels, repeat-clicker identification and phish-prone trends across campaigns.
Executive reporting
Exportable campaign reports for leadership and audit use, with per-department breakdowns.
Framework evidence
Attach campaign results to the awareness controls they evidence in ECC, ISO 27001, PDPL and other assessments.
PhishLens frequently asked questions
Is PhishLens a compliance framework?
No — it is a simulation module. It produces the tested-awareness evidence that framework controls require.
Can campaigns be branded per tenant?
Yes. Tenants configure sender identity and branding, with administrative limits on targets and permitted domains.
How are results used in assessments?
Campaign reports and metrics attach as evidence to awareness and training controls, giving assessors measured outcomes rather than attendance sheets.
Is dispatch safe to test?
Campaigns support dry-run dispatch for validation before any live send, and sending is confined to configured domains.
One platform, many obligations
Talk to us about PhishLens
Security Solution Consultants provides Awareness programme advisory alongside the platform, so you can combine tooling with hands-on expertise.
Contact us