Closed

Phishing Simulation and User Awareness Platform for Enterprise Environment

Tender ID: 618937


Tender Details

Tender #:
RFI-03980  
Status:
Closed
Publish Date:
6 July 2026
Closing Date:
17 July 2026
Closing Time:
11:59 PM (Australia/ACT)

Tender Description

⁠⁠⁠Key problem/s

National Library of Australia is seeking a phishing simulation solution to strengthen our cyber security awareness program. While we currently have a phishing simulation solution in operation, several gaps limit its effectiveness in preparing staff for real-world phishing threats.

1. Lack of Realistic Phishing Simulations

Current solution relies on generic or predictable phishing emails, which do not adequately reflect modern, sophisticated attack techniques. We need the capability to deliver highly targeted, context-aware phishing campaigns that simulate real-world attack scenarios (e.g., spear phishing, business email compromise, credential harvesting etc.)

2. Limited Flexibility in Campaign Design

Existing tools do not offer sufficient flexibility in crafting and managing campaigns e.g., limited phishing templates, no capability to distribute

We require:

  • Access to a comprehensive library of phishing templates
  • Ability to easily customise templates to align with our organisational context.
  • Support for multiple phishing payload variations within a single campaign.
  • Capability to distribute different phishing email variants across user groups or individuals, rather than sending the same payload to all staff on the same day.  
  • Support for varying difficulty levels and attack types to better simulate real-world adversary tactics.
  • Ability to select specific user or users of a branch in campaign design.

3. Predictable Campaign Execution

The current solution does not randomise phishing simulation payloads across the user base, reducing the effectiveness of campaigns and potentially creating artificial user behaviour.

We require:

  • Randomised and staggered phishing delivery across users and time periods.
  • Ability to simulate “always-on” threat conditions rather than point-in-time testing.

4. Limited Visibility into User Risk

We lack detailed insight into how individuals and groups respond to phishing attempts.

The solution should provide:

  • Granular visibility at individual, team, and enterprise levels
  • Tracking of user actions (click, credential submission, email reply, reporting, etc.)
  • Clear identification of high-risk users and behavioural trends over time

5. Inability to Effectively Manage Repeat Offenders

Repeat offenders present a higher organisational risk but are not currently systematically addressed.

We require:

  • Identification and flagging of repeat offenders.
  • Ability to target high-risk users with more frequent or advanced simulations.
  • Risk scoring to prioritise remediation efforts. 

6. Need for Continuous Improvement and Metrics

There is currently no strong feedback loop to measure program effectiveness.

We require:

  • Metrics such as phish-prone percentage, reporting rates, and resilience scores.
  • Benchmarking and trend analysis over time
  • Support for continuous improvement of the cyber awareness program

The users and their needs

1. Executive and Operational Visibility

We require:

  • Intuitive dashboards for quick assessment of organisational risk posture
  • Executive-level reporting with trends and key metrics
  • Ability to export data for governance, audit, and reporting purposes. 

2. Reporting Capability

The solution should include:

  • A “Phish Alert” button integrated into enterprise email clients so that employees can report phishing email.
  • Capability to capture, analyse, and triage reported emails
  • feedback loop to reinforce correct reporting behaviour.

3. Usability and Administrative Efficiency

We require:

  • A user-friendly administration interface
  • Streamlined campaign creation, reporting, and user management.
  • Minimal administrative overhead for ongoing operations


Similar Tenders

Active opportunities matching this tender's categories and regions.