# PhishSkill > PhishSkill is a security awareness and human risk management platform for organizations. It runs automated email and WhatsApp phishing simulations, delivers behavior-triggered training, measures workforce resilience over time, and produces compliance-grade reporting for SOC 2, ISO 27001, HIPAA, and PCI DSS programs. PhishSkill is designed for security teams, CISOs, IT leaders, and GRC practitioners who need to measure and reduce the human layer of cyber risk. The platform combines phishing simulation, awareness training, and reporting infrastructure in one product, with content covering email and WhatsApp attack vectors. ## Product - [Home](https://www.phishskill.com/): platform overview, who PhishSkill is for, and what it produces - [How It Works](https://www.phishskill.com/how-it-works): the full lifecycle from baseline simulation through training delivery to executive reporting - [Platform Features](https://www.phishskill.com/features): phishing simulations, behavioral scoring, risk-based training, and reporting capabilities - [Phishing Simulation](https://www.phishskill.com/phishing-simulation): how PhishSkill runs simulated phishing campaigns and measures employee response - [Security Awareness Training](https://www.phishskill.com/security-awareness-training): the awareness-training delivery model — video lessons, quizzes, and behavior-triggered assignment - [WhatsApp Phishing Awareness](https://www.phishskill.com/whatsapp-phishing-awareness): training employees to recognize phishing on WhatsApp in addition to email - [AI-Powered Phishing Awareness Training](https://www.phishskill.com/ai-phishing-awareness-training): training employees against AI-generated phishing attacks - [Pricing](https://www.phishskill.com/pricing): plans and trial information - [Compliance](https://www.phishskill.com/compliance): how PhishSkill supports SOC 2, ISO 27001, HIPAA, and PCI DSS programs - [Security](https://www.phishskill.com/security): enterprise-grade security, data controls, and platform compliance posture - [About PhishSkill](https://www.phishskill.com/about): company background, mission, and team ## Learning Hub Short definitional guides on core security-awareness topics: - [What Is Phishing](https://www.phishskill.com/learn/what-is-phishing): definition, attack mechanics, and defensive principles - [What Is Phishing Simulation](https://www.phishskill.com/learn/what-is-phishing-simulation): how organizations test employees with controlled phishing exercises - [What Is Phishing Awareness Training](https://www.phishskill.com/learn/what-is-phishing-awareness-training): training programs that teach employees to recognize and report phishing - [What Is Security Awareness Training](https://www.phishskill.com/learn/what-is-security-awareness-training): broader security awareness program scope and outcomes - [What Is Smishing](https://www.phishskill.com/learn/what-is-smishing): SMS-based phishing and how it differs from email phishing - [What Is Spear Phishing](https://www.phishskill.com/learn/what-is-spear-phishing): targeted phishing attacks and the high-value-target threat model - [What Is Social Engineering](https://www.phishskill.com/learn/what-is-social-engineering): the human-layer attack surface that phishing is one expression of - [What Is Human Risk Management](https://www.phishskill.com/learn/what-is-human-risk-management): measuring and reducing cyber risk driven by employee behavior - [Business Email Compromise Explained](https://www.phishskill.com/learn/business-email-compromise-explained): BEC mechanics, financial impact, and defense strategy - [Security Awareness Policy Template](https://www.phishskill.com/learn/security-awareness-policy-template): a starting structure for an organization's awareness policy - [Security Awareness Compliance](https://www.phishskill.com/learn/security-awareness-compliance): how awareness programs meet regulatory and audit requirements - [Phishing Email Examples](https://www.phishskill.com/learn/phishing-email-examples): real-world phishing patterns with annotated indicators - [Phishing Statistics](https://www.phishskill.com/learn/phishing-statistics): current data points on attack volume, click rates, and reporting performance - [Phishing Resilience Score](https://www.phishskill.com/learn/phishing-resilience-score): a metric for quantifying workforce phishing resilience - [Phishing Simulation Frequency](https://www.phishskill.com/learn/phishing-simulation-frequency): how often to run phishing simulations - [How to Run a Phishing Simulation](https://www.phishskill.com/learn/how-to-run-phishing-simulation): the operational steps for executing a phishing exercise - [Glossary](https://www.phishskill.com/learn/glossary): terminology used across security awareness and phishing simulation ## Blog In-depth practitioner guides, threat intelligence, and benchmarks. The full archive lives at [the blog index](https://www.phishskill.com/blog) and a complete machine-readable list is in [the blog sitemap](https://www.phishskill.com/sitemap-blog.xml). Common topic clusters: - Building and operating awareness programs (program design, simulation cadence, training delivery, reporting culture) - Industry benchmarks (click rates, reporting rates, completion rates, BEC success rates, credential harvesting rates) - Threat anatomy (spear phishing, CEO fraud, BEC, MFA bypass, AI-generated phishing, ransomware delivery) - Industry- and region-specific guides (healthcare, financial services, legal, GCC/UAE sectors) - Compliance and policy (PCI DSS, HIPAA, ISO/SOC alignment, written security awareness policies) ## Feeds and indices - [Sitemap index](https://www.phishskill.com/sitemap.xml) - [Blog sitemap](https://www.phishskill.com/sitemap-blog.xml) - [Learning Hub sitemap](https://www.phishskill.com/sitemap-learn.xml) - [Static pages sitemap](https://www.phishskill.com/sitemap-static.xml) - [Blog RSS feed](https://www.phishskill.com/rss.xml)