Deepfake Simulation Vendors | Breacher.ai 2026

Categories: Deepfake,Published On: August 4th, 2026,
Vendor Roundup

Deepfake Phishing Simulation Vendors: Score Them Against One Threat, Not a Feature Grid

Six vendors, twelve criteria, scored on what each one publicly documents. Then the scenario that resolves the shortlist faster than any matrix will.

A feature grid tells you what a vendor sells. One scenario tells you where their sequence stops.

Bring the scenario you actually worry about. We will run it end to end.

Contact Us

Before the comparison, two admissions

Admission one

We are one of the vendors listed here. Read our column with that in mind. We have tried to earn the benefit of the doubt by scoring ourselves the same way we scored everyone else, by publishing the rows where we do not lead, and by naming the buyer situations where another vendor on this list is the better purchase. Verify any row that decides your shortlist directly with the vendor.

Admission two, and it is the larger one. Across our engagements the platform an organization runs has not predicted how it performs under simulation. That finding undercuts the premise of vendor roundups generally, including this one. It is covered in full further down, rather than buried at the end.

The one criterion: IT help desk impersonation over Teams

If you only have the appetite to evaluate one scenario, make it this one. An external tenant is stood up, employees are messaged inside Microsoft Teams by someone presenting as IT support, and they are talked into granting a remote session using legitimate tooling.

It is the most instructive scenario in the category for a reason that has nothing to do with the synthetic media. The pretext reads as a routine workflow rather than an alarming one, so the red flags that awareness training teaches never appear. Remote support is a normal weekday event. Support is frequently outsourced, so an unfamiliar voice is not anomalous. Instead of a red flag, the target gets a false green flag, and the training that was supposed to help produced nothing to notice.

We wrote up what this looks like on a live call in our remote support simulation write-up, and the field findings behind it in our AI vishing red team field notes.

Scored against that scenario, a vendor either reproduces the whole chain or stops somewhere inside it. Where they stop is the answer you are buying.

Whatever a platform cannot reproduce is exposure its report will not describe.

The vendors

Each assessment is drawn from what the vendor publishes. Where a dimension is not documented, we say so rather than guess. Our own entry leads, because a roundup that hides its author in the middle of the pack is harder to check. The other five follow alphabetically. The scorecard beneath scores all seven columns criterion by criterion.

Most of the entries carry a capture of the vendor's own page underneath, for the rows where a reader is most entitled to ask how we arrived at a mark. Two rows in this scorecard changed after those captures were reviewed, both of them in a competitor's favour, so showing the source seemed more useful than asking anyone to take the grid on trust. Our own entry carries one too, including a note on the row it does not support. Where a capture is absent, the cell is still sourced from the vendor's public pages, we simply have not reproduced it here.

  • Documented the vendor publicly documents it
  • Partial documented with a material caveat
  • No claim no public claim found
  • By design the vendor states the absence is deliberate
  • Scored in reverse stated as fact, not as a mark against
Full disclosure: this is us

Breacher.ai

We run the criterion above as a delivered engagement, from reconnaissance to blameless debrief, including the Teams contact, the conversational voice layer, the inbound callback, and the terminal action. The chain is one we run end to end against a live workforce rather than a scripted page, and our engine, OSES™, was built for sequenced simulation rather than parallel channels.

The rows we lead on are narrow and specific: conditional orchestration, where a later stage branches on what the target did earlier, and a real-time video avatar that joins a live call on Teams, Zoom or Meet. The report names the process that permitted the action rather than the person who answered the phone, and it ends in a peer vertical benchmark.

Our library is entirely generative. There is no stock catalogue to pick from, which is a deliberate choice rather than a gap. A security team builds modules against its own policies, procedures and simulation findings, and deploys them in minutes. Awareness training is always playing catch-up to the threat, so the useful thing is not a bigger catalogue but the ability to author against what you just found.

Where we are not the fit. If what you need is a large off-the-shelf compliance catalogue you can simply assign, thousands of self-serve seats, or a per-employee risk score as your headline board metric, buy one of the platforms above and use us for the adversarial layer. We are not the answer to solve. We are the answer to test and assess.

  • Orchestration
  • Live conversation
  • Teams, Zoom or Meet
  • Cloned voice and video
  • Process testing
  • Training generation
  • First-party research
  • Enterprise scale
  • Published pricing
  • Human risk scoring partial
  • Generative library by design
  • Argues against spot-the-deepfake
Evidence, interactive, conferencing and deepfakes Breacher.ai platform page headed Orchestration across every channel, with cards for AI voice cloning described as a cloned executive calling the target back, deepfake video described as live impersonation on Teams or Zoom, and agentic messaging covering email, SMS and chat.
Breacher.ai, our own page, held to the same standard. The cards substantiate cloned voice and video, live delivery on Teams and Zoom, and the inbound callback. They do not by themselves substantiate our orchestration mark: coordinating channels into a single engagement is not the same published claim as a later stage branching on what the target did earlier, which is the wording we require of everyone else. Source: breacher.ai, captured 20 September 2026.
Multi-channel plus OSINT

Adaptive Security

The most funded entrant in the category and the name AI models tend to return first. Published positioning is OSINT-driven multi-channel campaigns including deepfake executive calls, backed by the largest stock training catalogue in this set at more than 1,000 resources across 39 languages, and per-employee risk scores that update in real time.

Two things to scope rather than assume. A sequenced Teams help desk chain terminating in a remote-access outcome is not documented, and meeting-based simulation inside Teams, Zoom or Meet is not documented either, with Teams and Slack covered as chat messages. Put both in a proof of concept rather than a demo.

  • Live conversation
  • Cloned voice and video
  • Human risk scoring
  • Training generation
  • Stock library
  • Enterprise scale
  • Research partial
  • Pricing partial
  • No orchestration claim
  • No meeting delivery claim
  • No process testing claim
  • Teaches spot-the-deepfake
Evidence, spot-the-deepfake row Adaptive Security training page showing a simulated video call labelled deepfake detected, with numbered guidance to pay attention to strange movements and look for unnatural facial behavior.
Adaptive Security, artifact curriculum. The numbered guidance teaches perceptual tells. This is the capture behind the documented mark on the reverse-scored row of the scorecard below. Source: adaptivesecurity.com, captured 20 September 2026.
Self-serve, simulation-first

Brightside AI

Simulation-first and self-serve, with live AI voice calls, voice cloning and deepfake video alongside email. The live-call-plus-trackable-email hybrid is real sequencing and puts them closer to the orchestrated end than the channel list suggests. Their voice agents are documented as adapting live to what the employee says rather than running a script, which is the harder half of a voice simulation.

Two corrections to our own earlier scoring, made on a re-check on 20 September, and they run in opposite directions. We had credited them with published per-seat rates. We could not substantiate that: there is no pricing page and no rates anywhere on the site, so that mark is now a gap. Against that, we had them at no claim on enterprise scale, which was too harsh. They run a public trust center documenting GDPR, a SOC 2 Type II in progress, and security policies available under NDA, so that mark is now partial. A large regulated deployment still needs the completed SOC 2, and we found no ISO 27001, SCIM or named customers. The Teams-native help desk pretext is not documented.

  • Live conversation
  • Human risk scoring
  • Deepfakes partial
  • Training generation partial
  • Stock library partial
  • Enterprise scale partial
  • No orchestration claim
  • No meeting delivery claim
  • No process testing claim
  • No first-party research
  • No published pricing
  • Teaches tells, favours verification
Evidence, enterprise scale Brightside AI public trust center listing GDPR compliance and SOC 2 Type II marked in progress, alongside security control categories and policy documents available under NDA.
Brightside AI, the capture that corrected our own mark. We had scored enterprise scale as no claim found. This public trust center documents GDPR, a SOC 2 Type II in progress and policies available under NDA, which is why it now reads partial rather than absent. The completed SOC 2 is still outstanding. Source: trust.brside.com, captured 20 September 2026.
Process testing and impersonation defense

Doppel

This entry has changed materially since we first published this roundup, and the change runs in their favour. Our August assessment described a different center of gravity and marked our evaluation criterion as not documented. On a re-check in September they document a help desk mode that tests password reset and MFA re-enrollment procedures, and simulations delivered inside Teams and Zoom meetings. That is procedure testing rather than click counting, and it is the closest thing in this set to how we think the category should be measured.

They also publish named threat actor research from their own telemetry and carry the deepest compliance stack in this set, with SOC 2, ISO 27001, 27701 and 42001. Their published framing is worth quoting fairly: their pages are titled around recognizing deepfakes, but the mechanism they describe is rehearsing the seconds after the employee picks up, repeatedly and at increasing difficulty, to build a verification reflex that holds under social pressure. That is a procedural argument wearing a perceptual headline, and we agree with the substance of it. Branch logic between stages is still not stated, and pricing is demo-request only.

  • Live conversation
  • Teams, Zoom or Meet
  • Process testing
  • Human risk scoring
  • Training generation
  • First-party research
  • Enterprise scale
  • Orchestration partial
  • Deepfakes partial
  • Stock library partial
  • No published pricing
  • Recognition framing, procedural mechanism
Evidence, spot-the-deepfake row Doppel page headed Equip Your Employees to Recognize Deepfake Attacks, stating that simulations will not stop a synthetic voice reaching an employee and that rehearsal builds a verification reflex holding up under social pressure.
Doppel, perceptual headline over a procedural mechanism. The title says recognize, the body describes rehearsing the seconds after pickup to build a verification reflex. That split is why they read mixed rather than documented on the reverse-scored row below. Source: doppel.com, captured 20 September 2026.
Behaviour change at scale

Hoxhunt

The most credible deepfake capability among the large behaviour-change platforms, and the largest published research sample in this set, drawn from its own simulation volume rather than curated from elsewhere. Enterprise scale is not in question: millions of users, 129 or more countries, SSO, SCIM and multi-tenancy.

Two things to check. The meeting experience is documented as a simulated meeting window rather than a real call, and video scenarios are pre-scripted even though voice agents respond in real time. Measurement is per-user click and report behaviour, which is a genuine strength if human risk management is what you are buying, and a gap if you need to know whether a procedure held.

On the detection question they sit in both camps, and the better half deserves credit. They publish a spot-the-deepfake chart built on lighting, artifacting, lip-sync, blinking and skin texture, which is the decaying half. They also publish explicit process boundaries for high-risk workflows: never approve an urgent wire transfer or bank-detail change on a live call, never share credentials over voice, verify unexpected executive messages out of band. That second half is the durable guidance, and it is closer to our position than the first half is far from it.

  • Live conversation
  • Cloned voice and video
  • Human risk scoring
  • Stock library
  • First-party research
  • Enterprise scale
  • Meeting delivery partial
  • Process testing partial
  • Training generation partial
  • No orchestration claim
  • No published pricing
  • Teaches spot-the-deepfake
Evidence, process testing and spot-the-deepfake Hoxhunt page section headed Teach process boundaries for high-risk workflows, listing finance and vendor fraud, IT support scams and executive impersonation rules, above a chart titled How To Spot Deepfake Content listing context clues and face swapping tells.
Hoxhunt, both halves on one page. The process boundaries above are the durable guidance and the reason their process-testing mark reads partial. The chart beneath them is the capture that corrected their spot-the-deepfake mark from no claim to documented. Source: hoxhunt.com, captured 20 September 2026.
AI-native, federal-ready

Jericho Security

AI-native phishing generation with synthetic voice cloning, face-swap video and synthetic personas, sold self-serve across three published tiers. Training generation is a real strength: courses are generated from a topic or an uploaded policy document, with SCORM and xAPI export and a stated turnaround on custom video. Campaign tailoring is genuinely granular, customising subject line, requested information, name, company and department per recipient.

The distinguishing asset is federal procurement. They publish a US Department of War IL5 authorization and NASA SEWP V availability, which matters more than any feature row if you are buying on a government vehicle.

Their campaign page is also the clearest illustration of a distinction worth carrying into every vendor call. Depth of personalisation is not the same as orchestration. Tailoring the subject line, the requested information, the name, the company and the department makes stage one more convincing. Orchestration is what stage two does differently because of what the target did at stage one. A platform can be excellent at the first and have none of the second, and the report will read the same either way. Against our one criterion, sequenced Teams help desk impersonation with a live two-way conversation is not documented. The conversational claim describes back-and-forth email rather than a live agent, and the one staged follow-up description we found sits in press coverage rather than product documentation, so we scored it as not documented.

  • Cloned voice and video
  • Training generation
  • Enterprise scale
  • Human risk scoring partial
  • Stock library partial
  • Pricing partial
  • No orchestration claim
  • No live conversation claim
  • No meeting delivery claim
  • No process testing claim
  • No first-party research
  • Teaches spot-the-deepfake
Evidence, orchestration Jericho Security page section headed Ultra-personalized campaigns, describing tailoring each phishing simulation by customizing the email subject and requested information and adding names, company and department.
Jericho Security, personalisation rather than orchestration. Everything described here varies the content of one message. Nothing describes what a later stage does differently because of what the target did earlier, which is why their orchestration mark reads no claim. Source: jerichosecurity.com, captured 20 September 2026.

Already on a traditional email-first awareness platform? Assume it does not run this chain, and hold it to the same criterion.

Twelve criteria, seven options, scored on public evidence

Now the same six vendors, criterion by criterion. Each cell records what the vendor publicly documents as of September 2026, checked against their own product pages, pricing pages and published research. A blank cell means we could not find a public claim, which is not the same as the capability being absent. Several of these vendors gate their product documentation behind a login or a demo.

Columns follow the same order as the write-ups above. The order is not a ranking, and the row count a vendor leads on is not a score. Read the rows that matter to your program and ignore the rest.

  • ● Documented
  • ◐ Partial, or documented with a material caveat
  • ○ No public claim found
Vendor scorecard, public documentation as of September 2026
Criterion Breacher.ai Adaptive Brightside Doppel Hoxhunt Jericho Generic awareness training
OrchestrationLater stage branches on what the target did in the stage before ●YesOSES™ conditional sequencing is the product ○No claimDocuments coordinated multi-channel, not branch logic ○No claimHybrid voice plus email ◐PartialMulti-step campaigns documented; branch logic never stated ○No claimMulti-channel plus adaptive training difficulty ○No claimCampaign tailoring is documented as per-recipient personalisation of subject line, name, company and department. A staged follow-up appears in press coverage, not product documentation ○No claim
Interactive simulationsReal-time two-way conversation, not a recording ●YesInteractive video avatars that join Teams, Zoom or Meet and hold a conversation, plus conversational voice agents ●YesReal-time voice calls from deepfake personas ●YesAI adapts and responds during live phone calls; voice only ●YesConversational simulation with real-time follow-ups during a live call ●YesReal-time AI voice agents; video scenarios are pre-scripted ○No claimConversational phishing is described as back-and-forth email; no live two-way agent documented ○No claim
Video conferencing simulationsSimulations delivered inside Teams, Zoom or Meet ●YesTeams, Zoom and Meet ○NoTeams and Slack chat messages only; no meeting simulation documented ○No claimEmail and voice only ●YesTeams and Zoom meetings ◐PartialSimulated meeting window rather than a real call; Teams messaging documented separately ○No claimDeepfake video claimed generally; no named conferencing platform ○No claim
DeepfakesCloned voice and cloned video ●YesCloned voice and video ●YesCloned voice and video ◐PartialVoice self-serve; video only as a managed engagement ◐PartialVoice on the adversary side; video documented for training content ●YesCloned voice and executive likeness ●YesSynthetic voice cloning, face-swap video and synthetic personas ○No claim
Process testingDid a procedure hold, not did a person click ●YesProcess hold rate against a named consequential action ○No claimMeasurement is per-user risk scoring ○No claim ●YesHelp desk mode tests password reset and MFA re-enrollment procedures ◐PartialPublishes process boundaries for wire transfers, bank-detail changes and credential resets, so the procedure is taught. Measurement is still per-user click and report behaviour rather than whether the procedure held ○No claimTriage Center handles phishing reports; no procedure testing documented ○No claim
Human risk managementPer-person risk scoring and behaviour change tracked over time ◐PartialWe focus on process invocation rather than only the user. Per-person risk scoring is not our primary output ●YesPer-employee risk scores updating in real time, with just-in-time remediation ●YesPer-employee vulnerability score out of 100, plus risk by department ●YesHuman risk management is a named product line ●YesPositions itself as human risk management; per-user adaptive difficulty and cadence ◐PartialRisk scores by team and role claimed; no named per-person score or methodology published ◐VariesIncreasingly added, but historically completion tracking
Instantly create awareness trainingGenerated from policies, a prompt, or simulation results ●YesOSES™ Behave generates from your policies, a prompt, an article, or simulation results, and the team deploys it themselves in minutes ●YesPrompt-based and policy-fed content generation ◐PartialAuto-assigns from a fixed library rather than generating ●YesContent builder drawing on simulation results ◐PartialPolicy to training documented; result-driven generation not ●YesGenerates courses from a topic or uploaded policy document, with SCORM and xAPI export ○No claimFixed catalogue
Generic training libraryStock compliance catalogue you can simply assign ○By designNo stock compliance catalogue, deliberately. The library is entirely generative, and a security team can build and deploy its own content in minutes, because security is unique to every organization ●Yes1,000+ resources, named framework tracks, 39 languages ◐PartialCourse library documented; no compliance catalogue or count ◐PartialHundreds of videos documented; no named frameworks or languages ●Yes300+ modules, regulatory tracks, 40+ languages ◐PartialA library is referenced, with Spanish and Japanese launches; no module or language count published ●YesThe category's core strength
Original threat researchFirst-party findings, not curation of other outlets ●YesFirst-party findings from live engagements, published in our 2026 benchmark ◐PartialResearch hub curated from external sources; no first-party telemetry found ○No claimBlog is buyer-guide content, not research ●YesNamed threat actor briefs from own telemetry ●YesAnnual trends report drawn from its own simulation volume, the largest published sample in this set ○No claimBlog statistics are attributed to third-party sources ◐Varies
Enterprise scaleLarge seat counts, directory provisioning, procurement evidence ●YesSOC 2; deployed at enterprise scale, with Entra ID integration, full API and CLI ●YesSOC 2; SCIM across Entra ID, Okta, Ping ◐PartialPublic trust center documents GDPR, SOC 2 Type II in progress, and security policies available under NDA. No completed SOC 2, ISO 27001, SCIM or named customers found ●YesNamed enterprise customers; SOC 2, ISO 27001, 27701 and 42001 ●YesMillions of users, 129+ countries; SSO and SCIM; multi-tenancy; SOC 2 ●YesSOC 2 Type I and II, US Department of War IL5 authorization, NASA SEWP V availability; SCIM on the top tier. No ISO 27001 found ●YesThe category's core strength
Transparent pricingRates published on the vendor's own site ●YesTiers and flat platform rates on the pricing page, priced by scope rather than seat count ◐PartialQuote only on site; one tier listed on a cloud marketplace ○NoCorrected 20 September. No pricing page exists and no rates appear anywhere on the site. An earlier version of this scorecard credited published per-seat rates, which we could not substantiate on re-check ○NoDemo request only ○NoPer-employee, quote on request ◐PartialPer-seat monthly rates for three tiers appear in page metadata rather than visible page copy; no pricing page ◐Varies
Teaches users to spot deepfakesRead this row in reverse. We treat perceptual detection training as a decaying control ○No, argues againstWe teach process invocation and out-of-band verification, a control that does not decay ●Yes, leads with itPublishes an artifact curriculum covering blink symmetry, hairline smearing, lighting direction, lip-sync delay, prosody and timbre, with procedural controls framed as the complement ◐PartialTeaches visual and audio tells, then states that the most effective defense is verification that works regardless of how convincing the fake appears ◐MixedPages are titled around recognizing deepfakes, but the stated mechanism is rehearsal at increasing difficulty to build a verification reflex that holds under social pressure, which is procedural rather than perceptual ●YesPublishes a spot-the-deepfake chart covering lighting, artifacting, audio quality, lip-sync, facial expression, blinking and skin texture. Pairs it with explicit process boundaries for high-risk workflows, which is the stronger half of that guidance ●YesTeaches tells including unnatural blinking and audio artifacts, alongside verification protocols, presenting the two as complementary ●YesSpot-the-fake modules are the category norm

Compiled from each vendor's public website in September 2026. We are one of the seven columns, so read our column with that in mind, and verify any row that decides your shortlist directly with the vendor. Capability behind a login is real capability, it is simply not something we can check. If you represent a vendor listed here and a cell is wrong or out of date, tell us and we will correct it.

The part that undercuts this article

Now the uncomfortable part, and it applies to every column above including our own. Across our engagements, the platform an organization runs has not predicted how it performs. Run the same voicemail and callback technique across different organizations and the action rate ranges from 0% to 34.5% of the targeted population in each engagement. One population had nobody take the action. Another had roughly one in three. They were buying from the same short list.

The vendor is not the variable that moves the outcome. What correlates is whether a verification procedure exists and holds under pressure: whether the help desk can say no to an executive, whether people were told what to do rather than what to spot. You run this evaluation because you cannot fix a failure you have never observed, not because the tool is the fix.

A control built on perception is a countdown. A control built on procedure is not.

That is the whole argument, and it is worth being precise about it, because the compressed version gets it wrong. We are not against detection. We are against locating detection in human perception.

Where detection training works

The tell is an inspectable artifact that sits still: a sending domain, a header, a link destination. The evidence can be checked after the fact, and teaching someone to check it buys a durable skill.

Where it does not

The tell is perceptual, in synthetic audio or video, and the decision is made live with no inspection window. Every tell taught today is a defect in the current generation of synthesis, engineered out on a release curve the buyer does not control.

Machine verification is a different matter, and we are firmly for it, particularly in the hiring and identity path: document verification, liveness, validation against authoritative sources, synthetic media detection on the interview channel, and a hard gate before provisioning. Our role is to test whether those controls hold, not to sell them or dismiss them.

How to run the evaluation

Bring these five steps to every vendor, including us. They will tell you which platform can run the modern threat, regardless of how the marketing positions it.

01

Give each vendor your Microsoft 365 environment shape, help desk name, and remote support tool. Nothing else. What they do with three facts tells you how much reconnaissance the platform does for them.

02

Have them scope Teams help desk impersonation against 25 people, terminating at an MFA approval or a remote session grant. Name the terminal action before the run, not after.

03

Ask what the report shows when there is no click. A phone call contains nothing to click. If the answer is an empty dashboard, the measurement model is email-shaped.

04

Ask how they handle an inbound callback. Most targets do not answer, so the voicemail and callback path is the dominant route through a population, and the inbound leg is where the most consequential outcomes occur.

05

Ask them to describe the branch logic between stages out loud. A vendor who can only list the channels they support, and not what stage two does differently when stage one succeeds, is describing multi-channel delivery.

  • Use the scorecard to get to three. It is a shortlisting aid, and it rewards documentation quality as much as capability.
  • Use the scenario to get to one. Same population, same terminal action, same report format, run by each finalist.
  • Ask every finalist for a peer benchmark with a stated number of organizations behind it. Including us.

One last thing, because this argument gets flattened

Compressed into a headline, everything above turns into "detection training does not work." That is not the argument, and we would rather be held to the precise version.

Detection-based training is fine for legacy vectors. Email, sender domains, headers, link destinations, lookalike and homoglyph domains, attachment types, the shape of a payment request that does not match a known pattern. For all of those, teaching people what to look at is sound, it is measurable, and it still earns its budget. The evidence sits still. A person can hover, expand the header, compare the domain against the real one, and check again tomorrow. A skill like that does not expire when a model ships.

It is the wrong control for deepfakes. Synthetic voice and video move the tell from something inspectable to something perceptual, and they move the decision into a live conversation where there is no inspection window at all. The target is not examining an artifact, they are talking to someone. Every tell taught today is a defect in the current generation of synthesis, being engineered out on a release curve the buyer does not control, so the training is worth less the day after it is delivered.

So the rule we apply, and the one we would hold any vendor to, is not "detection or process." It is detection where the tell is inspectable, procedure where it is perceptual. Those are different controls for different vectors, and a program that runs both in the right places is stronger than one that picks a side.

The same distinction is why we are firmly in favour of machine verification, which is detection of a different kind and does not decay the same way. Document verification, liveness, validation against authoritative sources and a hard gate before provisioning all belong in the hiring and identity path. Our job is to test whether those controls hold, not to sell them or dismiss them.

Detection where the tell is inspectable. Procedure where it is perceptual.

“Kudos to your entire team. We haven't even seen the report and the whole company is talking about the risks of voice cloning. It's been a huge win for us already.”

CISO, LARGE FINANCIAL ENTERPRISE

Measure your risk.
Train for what you find.
Prove it changed.

Bring your own sequence. We will run it end to end and show you where it terminates.

Contact Us

Frequently asked questions

Score every vendor against one threat rather than a feature grid. Ask whether the platform can run IT help desk impersonation over Microsoft Teams, from reconnaissance to the moment someone grants remote access or approves an MFA prompt, with a live conversation in the middle. That single scenario resolves more than a matrix does, because it forces every vendor to say where their sequence terminates. Use a criteria scorecard second, as a shortlisting aid, not as the decision.

JT

Jason ThatcherFounder and CEO of Breacher.ai and creator of OSES™. Fifteen years in security operations and offensive testing, previously at ZeroFox, Deepwatch, and GuidePoint Security. He builds and runs orchestrated social engineering simulations against enterprise organizations.

Run the Criterion Against Your Own Organization

Tell us the sequence you actually worry about. We will walk a real OSES™ engagement from scenario design through findings, and you decide whether your process would have held.

Contact Us

Latest Posts

  • Deepfake Phishing Capabilities by Vendor: 16 Capabilities.

  • CISO Guide 2027: Understand Your Social Engineering Risk. Then See How You Rank Against Your Peers.

  • Teams Vishing Rose 502% in a Year. Here Is the Simulation That Tests It.

Table Of Contents

About the Author: Jason Thatcher

Jason Thatcher is the Founder of Breacher.ai and comes from a long career of working in the Cybersecurity Industry. His past accomplishments include winning Splunk Solution of the Year in 2022 for Security Operations.

Share this post