
Low-Touch Security Awareness Training and Phishing Simulation for Human Risk
Founded in 2018 and based in Leeds, England, Boxphish sells a low-touch cyber security awareness training platform aimed at IT and security teams that lack the headcount to run an awareness programme by hand. The intended buyer is a mid-sized to large organisation, and published customers span local authorities, education, retail, financial services and policing, including Macmillan, Police Scotland, Cambridge University and North Yorkshire County Council. Phishing simulation, training content and analytics sit in one product.
Administrators launch simulations from a ready-made template library or build their own, with clickers routed either to an educational landing page carrying prevention tips or to a plain 404 page when the goal is clean benchmarking; template freshness draws on email security partnerships monitoring over two million endpoints. Automated learning journeys then push three-to-five-minute video modules and quizzes mapped to National Cyber Security Centre guidance. User directories sync from Microsoft 365 or Google, with single sign-on and an in-inbox phish report button.
Differentiation rests on measurement and low administrative overhead rather than content volume: composite user risk scores blend click and report rates, training completion, assessment results, policy acceptance and incident history, and the system automatically assigns extra modules to higher-risk individuals. Manager-level reporting licences push departmental visibility outward, while dark web credential scanning, bespoke branded content and Arabic-language courseware extend the core. The vendor holds Cyber Essentials Plus certification, is an AWS partner, and positions its audit trail as evidence for cyber insurance and governance requirements.



