Skip to contentNewsAnnouncing our $3M Seed Round
Herd Security

Platform · Cross-Channel Phishing

Cross-channel phishing simulations that measure what actually happened

Herd runs simulations and training across email, SMS, QR, and voice deepfakes, so the reflex your team builds covers every channel attackers actually use.

EmailSMSQRVoice
The same campaign delivered as SMS: a text from an unknown number claiming a DocuSign security alert and asking the recipient to verify their identity.
A Herd phishing simulation delivered as email: an Okta password-reset notice, addressed to Alex, with a Reset Password button and a one-hour expiry.

Trusted by security and GRC teams at

  • ClearlyAI
  • OneBrief
  • Outfox logo
  • Resonata
  • RiseUp
  • Epsilon Systems
  • Beacon Health

Your Simulations Cover One Channel. Your Attackers Don't.

Inbox-only phishing tests measure a reflex your team needs everywhere.

Attackers changed channels

The pretext that used to arrive as an email now lands as a text, a QR code, a chat message, or a voice on the phone that sounds exactly like your CEO.

Email-only sims train one reflex

A team drilled only on inbox phishing learns to distrust email and nothing else. The suspicion doesn't transfer; each channel needs its own rehearsal.

The blind spot is measurable

If you have never simulated smishing or a deepfake call, you have no idea how your org would do. Cross-channel simulation turns that unknown into a number.

One program. Every channel they use.

  1. A Herd phishing simulation delivered as email: an Okta password-reset notice, addressed to Alex, with a Reset Password button and a one-hour expiry.

    Email.

    Branded templates that render properly, so they look like the real thing. Herd tracks clicks, attachment opens, and replies.

  2. A Herd smishing simulation: a text from an unknown number claiming a DocuSign security alert and asking the recipient to verify their identity.

    SMS/smishing

    Numbers sync from your identity provider, not from Slack. Herd shows the segment count and encoding as you write, then sends gradually with randomized spacing of about 30 to 40 seconds so carriers don't filter the batch. Landing pages and verified domains are the same ones your email campaigns use.

  3. QR/quishing

    Drop {{QR_CODE}} into an email template and each recipient gets a unique code that is their tracking link. It's testing the lure that walks off the managed laptop and onto a personal phone.

  4. Herd's voice deepfake simulation: step one records the employee's own voice in Slack, step two plays back two samples and asks which of them is the AI clone.

    Voice and Deepfakes

    Herd clones an employee's voice and asks them to spot the fake, directly in Slack. Once someone has failed to tell their own voice from the clone, the urgent call from the CEO stops working on them.

Count what people actually did.

Not every failure is the same failure. Herd scores 5 distinct ways a person can fall for a simulation, weights them, and assigns remediation.

How scoring works

Failure types scored

5: link click, QR scan, attachment open, reply, credential entry

Weighting

Credential entry 2×, the rest 1×: credential entry is the outcome a real attacker is after, so it's the only one weighted double

Open tracking

No pixel, once Gmail or Outlook is connected

No-repeat window

90 days by default, adjustable to 730

New lures

Nightly, from your app stack and live threats

Excluded from your averages

Campaigns under 3 recipients, and marked service accounts

  • Pick what counts as failing. Clicking the link, submitting credentials, or opening the attachment. You choose which of the three triggers remediation, so the bar matches your program's maturity.

  • The training assigns itself the moment the failure is recorded.

  • Herd re-phishes them with a different template. You set the delay anywhere from 1 to 7 days. A different lure, because re-sending the same one only teaches people to recognize that email.

  • Repeat clickers surface on their own. Everyone who clicked in a given month lands in that month's smart group, and the reports view carries a repeat-offenders panel across campaigns.

Frequently Asked

Your questions, answered

It is phishing simulation that mirrors how attackers actually operate: the same pretext delivered across email, SMS, QR codes, voice, and chat, instead of inbox-only tests. Employees build the reflex on every channel, and you learn where the org is actually exposed.

Most tools report a click. Herd separates 5 failure types and weights credential entry double, so a submitted password doesn't read the same as a curious click. Opens are measured differently too. With your mailbox connected, Herd drops the tracking pixel and reads the real read flag, so gateway scanners and image proxies can't register as readers.

Herd publishes allowlisting steps for Google Workspace and for Microsoft 365, and every campaign has a Share for Whitelisting action that generates what your mail team needs. The Microsoft path uses Defender Advanced Delivery, which requires Defender for Office 365 Plan 1 or 2, and your Herd rep supplies the sending IPs it asks for. SMS sends are spaced about 30 to 40 seconds apart with randomization so carriers don't treat the batch as spam.

No. Herd generates them nightly from your app stack and from live threats, and you can also describe an email in a sentence and have Herd draft the body. Everything lands pending your approval, unless you turn that off.

Phone numbers on the user record, synced from Okta, Entra ID, or Google Workspace. People without a number are hidden from the recipient picker rather than silently skipped.

Herd clones an employee's own voice, then plays back the original and the AI clone and asks them to tell which is which, directly in Slack. Hearing your own voice faked is the fastest way to stop trusting a familiar voice on an urgent call.

No. The page records that a submission happened and nothing about what was in it.

Sends honor business hours, marked service accounts are excluded, people on approved leave stop getting reminders and come back to shifted due dates, and every failure routes to a short lesson rather than a name on a list. Herd's own guidance is explicit that simulations shouldn't use paycheck, HR-conduct, or family-emergency lures.

The same channels that carry the simulations carry the coaching. Herd's agent delivers microtrainings, answers policy questions, and follows up on a failed simulation inside Slack and Teams, so the lesson arrives while the moment is still warm.

Set an ongoing campaign to weekly, biweekly, monthly, quarterly, or your own interval in days. It picks up new group members and stops phishing people who leave.

Join the Herd

Bring one of your policies. Watch it become a lesson.

In the demo we'll generate training from a document you actually use and show you what lands in Slack. 30 minutes.