A familiar request.
A supplier document, password reset or executive instruction arrives in the channel employees use all day.
PlankSec HARM helps security teams see, test and reduce the human attack surface across email, WhatsApp, SMS, QR, voice, deepfake, ClickFix, USB and social engineering.
Multi-channel human risk intelligence. Platform currently in active development.
Your people can be reached through many paths. The channel changes; the target is still human trust.
A supplier document, password reset or executive instruction arrives in the channel employees use all day.
An attacker changes the channel and uses urgency, familiarity and a public relationship to make the request feel real.
Vishing removes the pause people get with email. Verification habits are tested while a caller controls the pace.
Synthetic voice or video can amplify executive impersonation and exploit established trust.
USB drops and blended social engineering test curiosity, process and physical handling behavior.
Attack surface management protects the technology attackers can reach. HARM focuses on the people attackers can reach.
Traditional attack surface
Human attack surface
Signals become useful when security teams can see the people, channels and outcomes behind them.
Map the role, relationships, public signals and channels that make a person reachable.
Choose an approved channel and scenario that reflects the pressure the role may face.
Capture security-relevant outcomes without turning human risk into productivity surveillance.
Connect channel outcomes with role criticality, history, training and exposure.
Target training, verify the improvement and keep the analyst in control of every action.
Finance Director
High-value financial rolePayment authority and supplier access
Public phone number exposedFound on a professional profile
Executive relationship identifiedFrequently associated with CFO
Vendor payment responsibilityHigh-impact operational trust
Verification pressure and executive impersonation
No message or call is sent from this website preview.
Email phishingReported
ProtectedWhatsApp impersonationIgnored
ProtectedQR simulationScanned
MediumVishingSensitive information disclosed
HighClickFixNo execution
ProtectedTrainingIncomplete
ActionCallback verification trainingTarget the seven users who disclosed information
Follow-up vishing simulationVerify improvement after training
Manager insightShare the Finance pattern without exposing private content
Scout assists analysts with campaign setup, scenario selection, result summaries and recommended follow-up work. It prepares the work; the user reviews and approves it.

Scout AIOnline inside HARM
A phishing simulator reports campaign activity.
HARM explains human attack exposure.
Useful for one campaign report, but shallow when leadership needs to understand where human risk is forming.
HARM includes everything a traditional simulator reports, then connects each result to the person, role, channel, pattern and next action needed to reduce real human risk.
Move beyond isolated email tests with controlled, approved scenarios that model how attackers combine reconnaissance, impersonation, channels and operational pressure.
Email phishing and spear-phishing scenarios that test credential, attachment, payment and account-access decisions.
Email / available in preview
The interface follows one operating model across campaigns, people, profiles and integrations.
HARM is designed around configured simulations, exposure and security-relevant outcomes. It is not positioned as productivity monitoring or silent access to private employee content.
Limit views and actions to the teams responsible for human-risk operations.
Collect the signals needed for security decisions, not unrelated personal activity.
Keep campaign ownership, approvals and operational actions reviewable.
Align simulation records and reporting windows with organizational policy.
Protect lead and platform data with controlled access and encrypted transport.
Give leaders useful patterns without exposing unnecessary private content.
See where your people are exposed. Test how attackers can reach them. Measure what happens. Reduce the risk before it becomes an incident.
We will focus the conversation on your channels, teams and human-risk goals.