What is it?
Part of KeenSec AI Studio. It turns a simulation interaction into a short, interactive learning page built on the cues the employee just saw.
Most simulations end with "You failed" and a long course weeks later. AI Studio turns the moment after the click into a short, interactive lesson built on the exact cues the employee just missed.
Show people what fooled them, right when it happens, and let them practise the safer habit.
[CUE 01] Display name claims @vendor-corp.com, but it was sent from @v-billing-auth.net.
[CUE 02] Urgency: threatens a 4:00 PM shipment hold.
[HABIT] Verify bank details through a known contact, not links in the email.
[NOTICE] "ACCESS BLOCKED: You failed an IT security test."
[ASSIGNMENT] A long, mandatory slide course.
[OUTCOME] People dread simulations and hide genuine mistakes.
Try it
AI Studio marks each trick in the lure and pairs it with a simple habit for next time.
Interactive sample. Scenarios and data are illustrative.Dear Accounts Team,
Our banking partner has transitioned following a corporate entity restructuring. Effective today, all outstanding balances for Purchase Order PO-98441 must be processed to our updated remittance routing number.
Failure to confirm updated disbursement instructions by 4:00 PM EST will place automated vendor shipment dispatches on administrative hold.
The attacker registered apex-logistix-portal.com (substituting 'x' for 'cs'), creating visual similarity to the authentic domain apex-logistics.com to bypass quick human inspection.
Check the domain spelling carefully. Attackers often add words like -portal, -secure, or -support to domain names when authentic domains are already taken.
If you received this supplier banking change today, what is the single strongest defensive step?
Checking through a known contact, not the email itself, is the strongest defence against a fake bank change.
Why it works
The moment after a click builds either habits or resentment.
Treats the simulation as a trap.
"You failed." No explanation of what fooled them.
A long slide deck on unrelated topics.
People stop reporting suspicious emails for fear of being caught out.
Treats the simulation as a chance to learn.
"This was a training exercise." People relax, so they can learn.
Clues marked on the exact email, SMS or QR code they saw.
Practises the safer action without derailing the workday.
The learning loop
One connected loop that respects people's time.
An employee clicks a simulated email, scans a QR code or enters test credentials.
AI Studio picks out the pretext, the cues and why this role was targeted.
The employee explores the clues on the lure itself, in a short and supportive lesson.
The result feeds Human Risk Analytics, and a comparable follow-up test checks the habit later.
Learning formats
Each lesson fits the attack type and the employee's role.
Step-by-step notes on the simulated email, SMS or QR code.
Explains why an attacker would aim this lure at their role.
Highlights lookalike characters and mismatched reply-to addresses.
A single decision that reinforces the right action.
Company-approved steps for checking a request through a known contact.
Clear lessons in the learner's own language.
At a glance
Part of KeenSec AI Studio. It turns a simulation interaction into a short, interactive learning page built on the cues the employee just saw.
The attack pretext and cues, the channel, the employee's role, and what they did: opened, clicked or entered test credentials.
It builds the clue-by-clue breakdown, the explanations and the habit check. A person reviews before anything is sent.
Habit-check results feed Human Risk Analytics and help schedule comparable follow-up tests.
Let’s connect the dots
Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.
Book a demo