HERALD delivers automated phishing simulations, employee risk scoring, and adaptive training modules that continuously improve the human-layer security posture of the organisation.
HERALD addresses the weakest link in enterprise security: human behaviour. Automated phishing simulations run continuously against all employees — with difficulty and targeting adapted based on each individual's risk profile. Click rates, reporting rates, and repeat behaviour are tracked and scored. Employees who fall for simulations are automatically routed to targeted training modules. HERALD integrates with AUGUR to target simulations using the same techniques actively used by tracked threat actors against your industry.
Automated multi-vector phishing simulations — email, SMS, voice — adapted to individual risk profiles.
Continuous risk score per employee based on click rates, reporting behaviour, and training completion.
Training modules automatically assigned based on simulation failures and individual risk profile.
Simulations use real techniques from AUGUR-tracked threat actors currently targeting your industry.
Organisation-wide and department-level dashboards showing risk trends, click rates, and improvement over time.
HERALD activity contributes to security awareness controls in SOC 2, ISO 27001, HIPAA, and PCI-DSS.
Phishing campaign configured with target audience, techniques, difficulty, and schedule.
AUGUR provides current threat actor TTPs to ensure simulations mirror real-world techniques.
Email, SMS, or voice phishing sent to targeted employees. Click and report actions tracked.
Employee risk scores updated based on simulation results, reporting behaviour, and training completion.
Employees who click are automatically enrolled in targeted training modules relevant to the technique.
CIPHER ingests HERALD risk data for correlation with LYNX and ATLAS events for unified risk view.
HERALD shares real-time telemetry, threat intelligence, and response actions with every other application in the PHALANX ecosystem through the unified intelligence fabric.
Wire-speed multi-layered IDS with adversarial-resistant ML and JA4 TLS fingerprinting.
Threat feed aggregation, log correlation, and SOAR playbook automation in a streamlined platform.
CVE tracking and patch prioritisation by exploitability and business impact with full asset visibility.
Proprietary federated threat intelligence from all PHALANX nodes using privacy-preserving AI.