Phishing-report rate at a regional bank, in 9 weeks.
One customer’s result. Outcomes vary.Security awareness training that proves human risk went down
ASAT gives each employee training matched to their role and behavior, steps in the moment someone falls for a simulated attack, and turns every result into a Human Risk Management you can show your board.
30 days·5 users·No credit cardTrusted by security teams at
- Banks
- Healthcare
- Government
- Telecoms
- Managed service providers
- Mid-market teams
A completed course is a starting point.
A safer decision is the outcome.
Most security awareness training reports who finished the course. That tells you who sat through a video, not who would hand their password to a fake login page. ASAT trains people at the moment they make a mistake, and scores human risk so you can see it fall.
A focused lesson, delivered while the decision is still fresh.
Triggered by a simulated mistake.Per month, to start. Try it with five users for 30 days.
Rates vary by plan and team sizeFour steps.
One continuous learning loop.
- 01
Enroll everyone
Sync users from Active Directory or Okta, with SAML 2.0 sign-in support. Assign a learning path matched to each role.
- 02
Train in short lessons
Build skills through ten-minute videos, animations, stories and games. Difficulty adapts as people learn.
- 03
Coach at the moment of a mistake
A simulated click or credential submission opens a two-minute lesson on the exact clues someone missed.
- 04
Prove it with a risk score
Connect clicks, reports, learning and credential exposure into a score per person and department.
Interface illustrations show example workflows and sample data.
Train for every channel
attackers use.
Phishing isn’t only email any more. Teach people what to notice, what to question and how to respond, wherever a request arrives.
Email phishing
Recognize AI-written lures that imitate real services and colleagues. Check the sender and the request.
Smishing
Spot delivery and payment lures in text messages, including local languages and scripts.
Vishing
Verify urgent requests from familiar voices, even when an executive’s voice has been cloned.
Deepfake video
Question unexpected requests on video. Use an independent channel to verify identity.
QR code phishing
Check codes on emails, posters and parking meters, including stickers covering genuine codes.
Pair learning with safe simulations. Simulation channels and availability vary by plan.
Explore phishing simulationTraining people finish.
And remember.
Finance learns invoice fraud. Executives learn impersonation. IT learns credential attacks. Paths adapt when someone joins, changes role or needs extra support.
Ten-minute videos, animations, stories and games make learning easier to fit into a working day. Difficulty adjusts to each learner.
Support your awareness program with courses mapped to ISO 27001, PCI DSS, GDPR, HIPAA and SOX. Training is one part of your compliance program.
Reach a global workforce with 300+ role-based modules in 40+ languages. Give people relevant learning they can understand and put into practice.
Recurring lessons, games and quizzes reinforce what people learn. A simulated mistake triggers a focused two-minute lesson while the decision is still fresh.
Per person. Per team.
A clearer picture of risk.
Every action feeds one score: simulations clicked or reported, lessons completed, exams passed and work credentials exposed on the dark web. ASAT updates the picture continuously and rolls it up by department.
- Per-person risk scoresFocus extra support on the people who need it.
- Department heatmapsSee where risk concentrates across your teams.
- Trends over timeShow what changed since last quarter.
- Credential exposureConnect leaked work passwords to focused training.
| Department | Apr | May | Jun | Jul | Aug | Sep |
|---|---|---|---|---|---|---|
| Finance | 82 | 78 | 70 | 64 | 53 | 46 |
| Customer service | 74 | 68 | 56 | 49 | 43 | 35 |
| Operations | 67 | 60 | 52 | 43 | 35 | 28 |
| Sales | 64 | 61 | 55 | 48 | 38 | 33 |
| IT | 50 | 41 | 35 | 29 | 25 | 21 |
| Executives | 80 | 75 | 69 | 62 | 54 | 48 |
Aspire SATILLUSTRATIVEPhishing and Social Engineering Essentials
12-month validity
Learning completed.
Evidence ready.
Verifiable certificates
Each learner who passes receives a PDF certificate with your logo. Auditors can check it by code or QR and see whether it is valid, expiring or expired.
Automatic renewal
Certificates last 12 months. Reminders arrive before expiry, and overdue learners are flagged for follow-up.
Audit-ready reports
Export training, completion, certificate and phishing reports on demand, mapped to the frameworks you are assessed against.
Training and reports support your audit evidence alongside the other controls your framework requires.
Built for a security team of one.
Set the rules once.
ASAT enrolls people, sends reminders, escalates and reports automatically. Most organizations are live within a week and run the program with under an hour of administration a month.
- 50%ReminderThe employee
- 70%Copied inProgram admin
- 80%EscalatedManager, IT head or CISO
- 90%EscalatedHR
- 100%OptionalCEO or MD
Example ladder: percentage of the training deadline elapsed. Each step is configurable. Rollout timing depends on your directory, audience and internal setup.
From an annual deadline
to continuous risk reduction.
| Annual compliance training | With ASAT |
|---|---|
| Once a year, on a deadline | Monthly, and at the moment of a mistake |
| The same course for everyone | A path for each role and weak spot |
| A report of who finished | Human risk trends that show what changed |
| Email phishing only | Learning for email, SMS, voice, deepfake and QR |
| Chasing people by email | Automated reminders and escalation |
| A completion export for audit | Verifiable certificates and mapped reports |
The channel row describes training topics. Paired simulations depend on your plan.
Good questions.
Clear answers.
Work through the details of your training program, rollout and reporting.
Talk to our teamHow is security awareness training different from an annual course?
Move from one annual deadline to monthly learning and coaching at the moment of a mistake; from the same course for everyone to paths matched to roles and weak spots; and from a completion percentage to human risk trends. Email-only practice expands to SMS, voice, deepfake and QR scenarios where supported. Automated reminders replace manual chasing, while verifiable certificates and framework-mapped reports support audit review.
Which threats does the training cover?
Email phishing lessons cover AI-written messages that imitate real services or colleagues, including sender-domain mismatches. Smishing lessons cover delivery and payment lures in local languages and scripts. Vishing teaches employees to verify urgent requests from cloned executive voices. Deepfake training examines lip sync, lighting and the request itself, alongside independent identity checks. QR lessons cover codes on posters, parking meters and emails that can evade link filters, including stickers placed over genuine codes. Paired simulation channels depend on the plan.
Is phishing awareness a separate product?
Phishing awareness is a learning topic within Security Awareness Training. Lessons teach employees to recognize, verify and report suspicious messages. Phishing Simulation is the product for running controlled attacks and measuring how employees respond.
What goes into a Human Risk Management?
Simulation responses, threat reports, lesson completion, exam results and dark-web credential exposure contribute to the score. Individual and department trends help teams decide where to focus support.
How can auditors verify certificates?
A certificate can be checked using its code or QR scan to see whether it is valid, expiring or expired. Certificates last 12 months, with renewal reminders and reporting for overdue learners.
Does training guarantee regulatory compliance?
No. Courses, certificates and exports support an organization’s awareness and audit evidence. Compliance also depends on the policies, technical controls and processes required by the relevant framework.
What does the trial include, and how much does training cost?
Try ASAT for 30 days with five users, no credit card and no sales call. Published awareness training plans start at $1.17 per user per month; prices depend on the plan and employee range. See the pricing page for your team’s current rate, or book a 20-minute walkthrough.
How does the reminder and escalation ladder work?
Each step is configurable as a percentage of the training deadline elapsed. At 50%, remind the employee; at 70%, copy the program administrator; at 80%, escalate to the manager, IT head or CISO; at 90%, involve HR; and at 100%, optionally notify the CEO or MD. This keeps follow-up moving without manually chasing every learner.
How much administration does the program need?
Set the enrollment, reminder, escalation and reporting rules once. Most organizations are live within a week and run the program with less than an hour of administration per month. Rollout timing depends on your directory, audience and internal setup.
What are the four stages of the training workflow?
Enroll everyone through supported Active Directory or Okta integrations, with SAML 2.0 sign-in support. Train in short videos, animation, stories and games with adaptive difficulty. Intervene immediately after a simulated mistake. Finally, combine clicks, reports, learning and credential exposure into a Human Risk Management by person and department.
See what changes
when learning connects to risk.
Bring your people, your program and the questions you need to answer. We’ll show you how ASAT fits.
- A 20-minute walkthrough, built around your team
- Role-based learning and immediate coaching
- Risk trends and evidence you can share
Tell us about your training needs.
Connect with the Aspire SAT team.
Preparing your form…








