Firewalls don’t stop an employee from clicking a convincing fake invoice email. That’s why PalmSol runs ongoing phishing simulations and security awareness training for clients using BullPhish ID — and manages the whole program, not just the software license.
BullPhish ID is a phishing simulation and security awareness training platform from Kaseya’s ID Agent line. It lets us send realistic, simulated phishing emails to your staff, then measure who clicked, who reported it, and who needs follow-up training — all backed by a built-in learning management system with short video courses on phishing, password security, data protection, and compliance topics, available in multiple languages with quizzes that confirm the material actually landed.
Licensing the software is the easy part. What actually reduces risk is how the program is run:
Phishing and other social engineering tactics remain one of the most common ways attackers get their first foothold into a business — and a single click can bypass firewalls, email filtering, and endpoint protection in a way no technical control can fully prevent on its own. Documented, ongoing security awareness training is also increasingly expected by cyber insurance underwriters and shows up directly in HIPAA, PCI DSS, and SOC 2-aligned compliance programs — auditors and insurers want to see that training happened, who completed it, and what the results were, not just that a policy exists on paper.
Security awareness training is one of the standing pieces of our 24/7 security operations stack, alongside SOC/NOC monitoring, managed detection and response, and patch management — because most breaches start with a click, not a firewall failure. We design and schedule your BullPhish ID campaigns, review the reporting, and fold the results into the quarterly reviews every client gets through our vCIO program, so phishing risk stays a standing agenda item instead of a once-a-year checkbox.
Will simulated phishing emails disrupt our team or feel like a “gotcha”?
No. The goal is measurable improvement, not embarrassment. Employees who click get short, specific follow-up training rather than a public callout, and reporting is used to guide the program, not to punish individuals.
How often do you run campaigns?
On a recurring cadence rather than a single annual test — consistent, lower-key repetition is what actually builds the habit of pausing before someone clicks.
Let’s talk about setting up a simulation campaign for your business.
Get a Free IT Assessment