October 1, 2026
Building PhishCamp: A Modern Phishing Simulation & Security Awareness Platform
Most organizations run phishing simulations the same way they did a decade ago: send a generic templated email, record who clicked, repeat…

By Joseph Olanrewaju
2 min read
Most organizations run phishing simulations the same way they did a decade ago: send a generic templated email, record who clicked, repeat quarterly. The result is a vanity metric, not actual behavior change. Over the past several months, I led the evolution of PhishCamp, an organization's internal phishing simulation and security-awareness platform, from a general-purpose open-source phishing toolkit into a purpose-built system that tests employees across email, SMS, and voice and closes the loop automatically by teaching people exactly what they missed.
The problem
Traditional phishing simulations stop at detection. An employee clicks a bad link, gets flagged, and -if an admin has time-eventually gets assigned some generic "security awareness" training weeks later, long after the moment has passed. There's no connection between what specific red flag fooled someone and what they're taught afterward. At the same time, real attackers don't just send email anymore-they call, they text, they impersonate IT helpdesks over the phone. A platform that only simulates email phishing is testing half the threat model.
What I built
- Multi-vector simulations: email (phishing), SMS (smishing), and voice (vishing), including a live, AI-driven vishing mode where a language model conducts a real-time adaptive phone conversation with the target rather than playing a fixed script, so the simulation reacts the way a real social-engineering call would.
- Indicator-based auto-remediation: the piece I'm proudest of. Every shing template is tagged with the specific red flags it relies on: spoofed sender, urgency language, a lookalike domain, a suspicious attachment, and so on. The moment someone fails a simulation, the system automatically matches those tags against a library of micro-courses and enrolls the employee in the one that teaches exactly what they missed, with no admin having to manually pick a course days later. It turns "you failed" into "here's the 90 seconds of training that would have caught this," while it's still fresh.
- Enterprise SSO-single sign-on for admin access, role-based permissions, and a full audit trail of administrative actions for compliance and incident review.
- Risk analytics: a weighted risk-scoring engine with configurable multipliers for higher-risk departments or roles, historical trend snapshots, and executive-level reporting with exportable audit reports.
- Operational automation: HR-driven employee roster sync, scheduled and recurring campaigns, and SLA-based escalation over email and Slack when assigned training goes overdue.
- Secure, containerized deployment - migrated the platform to a container-based deployment with secrets pulled from a cloud secret manager at runtime instead of living in config files, and hardened several other credential-handling paths along the way.
- A full UI/UX overhaul: a consistent design system, light and dark themes, accessible focus states, and a working mobile-responsive layout, replacing an admin interface that hadn't meaningfully changed in years.
Why it matters
Security awareness only works if the feedback loop is immediate and specific. By connecting what fooled someone directly to what they're taught next, and by testing the full range of channels attackers actually use rather than just email, PhishCamp is a much closer simulation of real-world social engineering than the quarterly email-click test most companies still run.
If you'd like to talk through any part of the architecture or the auto-remediation design in more depth, I'm happy to walk through it.