---
title: "AVAREANGE | Cybersecurity, made simple"
url: "https://avareange.avacloude.ru/en/future/"
---

# Cybersecurity,made simple.

AVAREANGE runs realistic phishing tests, coaches people the moment they slip, and turns every result into a score built on 102 behaviors tracked by the AVADB risk model.

[Request a demo](mailto:help@avareange.ru?subject=AVAREANGE%20demo%20request)[Spot the red flags yourself](https://avareange.avacloude.ru/en/future/#xray)

Simulations

Email phishing

Risk scoring

AVADB · 102 behaviors

Deployment

SaaS · On-Premise

Product language

English, end to end

01 / Lure

## Every lure borrows a real reason to click.

Attackers rarely invent a reason to click. They borrow yours: payday, an overdue invoice, a file a coworker might plausibly share. The only way to know how your people react is to test them regularly, with lures that feel just as routine.

*   Credential harvesting
*   Weaponized attachments
*   Display-name spoofing
*   Lookalike domains

02 / Reflex

## A wrong click in training builds the right reflex.

Click a simulated lure and the lesson starts right there: a one-page debrief points out what gave the message away. A follow-up course on that exact trick is added to the person’s training automatically.

*   Instant debrief
*   Rule-based enrollment
*   SCORM 1.2 & 2004

03 / Risk

## Risk is scored on behavior, habit by habit.

The AVADB risk model scores the habits that matter, from how people sign in to what they do with a suspicious message, so you can see which departments carry the most risk and whether last quarter’s training made a dent.

102

behaviors

10

security categories

7

impact types

4

priority tiers

[Explore the AVADB risk model](https://avareange.avacloude.ru/en/future/#model)

*   Credential phishing
*   Business email compromise
*   Payroll diversion
*   CEO fraud
*   Lookalike domains
*   Malicious attachments
*   QR codes in PDFs
*   Invoice fraud
*   Fake voicemail alerts
*   Shared-file lures

Try it / Phishing X-ray

## Put the lureunder the X-ray.

Five real-world tricks, rebuilt with fictional names: a payroll email, a fake voicemail notice with a QR code, a card-fraud text, a WhatsApp help-desk scam, and a refund scam in a Telegram group. Sweep the lens across the screen and pause on whatever looks wrong. Each red flag you catch goes into your report.Tap whatever looks wrong. Each red flag you catch goes into your report.

### URGENT: New bank account for Friday's payroll

**Marcus Bell** External <marcus.bell.kestrel@inboxmail.example\>

To: Dana Whitfield

Today, 7:52 AM

Hi Dana,

I switched banks last week. Could you update the bank account my salary is paid into before Friday's payroll run? The details are on the attached form.

It really has to be in place for this Friday. My old account is already closed.

I'm traveling for client meetings all week and can't get into the HR portal from my phone, so email is easiest.

Thanks so much!

— Marcus BellSenior Data AnalystKestrel Analytics

Bank\_Details\_Form.pdf84 KB

Training example · every person, company, number, and domain is made up

Payroll diversion

10% of email scams targeting businesses, Q2 2026[APWG](https://docs.apwg.org/reports/apwg_trends_report_q2_2026.pdf "Anti-Phishing Working Group (APWG), Phishing Activity Trends Report, 2nd Quarter 2026 (August 28, 2026)")

BEC losses reported to the FBI

US$3.05 billion in 2025[FBI IC3](https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf "FBI Internet Crime Complaint Center (IC3), 2025 IC3 Annual Report (April 2026)")

Keyboard users: the Tab key moves the lens from one suspicious detail to the next and adds each one to the report.

X-ray report

**0**/ 6 signs

1.  01
    
    Not found yet
    
2.  02
    
    Not found yet
    
3.  03
    
    Not found yet
    
4.  04
    
    Not found yet
    
5.  05
    
    Not found yet
    
6.  06
    
    Not found yet
    

Platform / The loop

## Simulate, coach,score, repeat.

Every campaign feeds the next one. Who clicked decides what they learn, and what they learn moves their AVADB risk score: one cycle that runs all year, not a test you pass once for the auditors.

1.  01/ 04
    
    Simulate
    
    ### Phishing that looks like it belongs in your inbox.
    
    Lures carry a link or an attachment and go out from domains you control, via your mail server. Draft them in the template editor and spread delivery over the week so one desk can’t warn the next.
    
    *   Email links
    *   Attachments
    *   Custom domains
    *   Template editor
    *   Staggered sends
    
    Campaign · Travel policy acknowledgmentScheduled
    
    Lure type
    
    LinkAttachment
    
    Template · built in the editor
    
    **From:** Corporate Travel <travel-desk@policy-hub.example>
    
    **Subject:** Action required: acknowledge the new travel policy
    
    Send window
    
2.  02/ 04
    
    Coach
    
    ### The debrief lands the moment someone clicks.
    
    Whoever takes the bait sees a page that walks through each red flag they missed. An event rule then enrolls them in a matching course, either from the AVAREANGE library or a SCORM 1.2 or 2004 package you already own.
    
    *   Instant debrief
    *   Event rules
    *   Course library
    *   Bring your own SCORM
    
    Whenclicks a link in a simulationThenenroll in “Spotting lookalike links”
    
    **Spotting lookalike links**Micro-course · SCORM 1.2
    
    Red-flag walkthroughAVAREANGE libraryYour SCORM packages
    
3.  03/ 04
    
    Score
    
    ### A risk score for every person, team, and company.
    
    The AVADB risk model turns each person’s recent actions into a risk profile, then rolls the profiles up by department. Watch the trend, export the reports, and show leadership what moved after training.
    
    *   AVADB risk model
    *   Risk profiles
    *   Department roll-ups
    *   Report export
    
    AVADB risk profile · Accounts PayableDemo data
    
    **Department risk score**31 of 34 people assessed
    
    Highest-risk categories
    
    **71.5** Threat detection and prevention
    
    **58.0** Data security and handling
    
    **33.5** Security awareness, policy, and help-seeking
    
4.  04/ 04
    
    Connect
    
    ### Plugs into the stack you already run.
    
    Simulations leave through your SMTP relay, courses arrive as SCORM packages, and the Outlook add-in sits where your people read mail. Two-factor authentication (2FA) protects sign-in to the platform. On-Premise and Enterprise add AD/LDAP user sync and Syslog events for your SIEM.
    
    *   SMTP relay
    *   SCORM
    *   Outlook add-in
    *   2FA
    
    Admin · ConnectionsLive
    
    Outbound mail
    
    **SMTP host:** relay.kestrel-analytics.example
    
    **Sender domain:** policy-hub.example
    
    Every deployment
    
    SCORM 1.2 / 2004Outlook add-in2FAReport export
    
    On-Premise and Enterprise
    
    AD / LDAP syncSyslog → SIEM
    

AVADB / Risk model

## Every risk hasa behavior behind it.

The AVADB risk model breaks human risk down into 102 concrete behaviors, from signing in with a passkey to escorting visitors. Each dot on the map is one of them; the nearer the core, the higher its priority.

102

behaviors

10

security categories

7

impact types

4

priority tiers

*   Tier 1 · top priority
*   Tier 2
*   Tier 3
*   Tier 4

Data security and handling: 40 behaviors

03 / 10

### Data security and handling

**40** behaviors

Behaviors in this category by priority tier: Tier 1 · top priority: 9, Tier 2: 14, Tier 3: 8, Tier 4: 9

*   Tier 1 · top priority: Signing in with MFA
*   Tier 1 · top priority: Using a strong password or passphrase
*   Tier 1 · top priority: Keeping passwords confidential
*   Tier 1 · top priority: Downloading content only from official sites
*   Tier 1 · top priority: Locking the device when away

Show 35 more of 40

*   Tier 1 · top priority: Keeping one-time passwords (OTPs) confidential
*   Tier 1 · top priority: Using a password that hasn’t been breached
*   Tier 1 · top priority: Protecting devices from loss or theft
*   Tier 1 · top priority: Using a device that hasn’t been compromised
*   Tier 2: Using a unique password for every account
*   Tier 2: Checking links before clicking
*   Tier 2: Shutting down the device when away for long periods
*   Tier 2: Wiping data before a device is retired
*   Tier 2: Destroying confidential documents
*   Tier 2: Keeping a clean desk
*   Tier 2: Sending data only to approved recipients
*   Tier 2: Returning or disposing of devices securely
*   Tier 2: Working only on approved devices
*   Tier 2: Changing information only with approval
*   Tier 2: Using elevated privileges only when needed
*   Tier 2: Sharing credentials only with approval
*   Tier 2: Handing a device only to approved people
*   Tier 2: Sharing data only through approved channels
*   Tier 3: Using only approved browser extensions
*   Tier 3: Using full-disk encryption
*   Tier 3: Using a privacy screen
*   Tier 3: Setting a SIM card PIN
*   Tier 3: Moving confidential information only to approved locations
*   Tier 3: Checking the recipient before sending
*   Tier 3: Signing out of accounts on shared devices
*   Tier 3: Photographing or filming confidential information only with approval
*   Tier 4: Signing in with SSO
*   Tier 4: Reporting access to systems you don’t need
*   Tier 4: Preventing public leaks of confidential information
*   Tier 4: Classifying information by sensitivity
*   Tier 4: Backing up data
*   Tier 4: Reviewing account security settings
*   Tier 4: Asking for personal information to be removed online
*   Tier 4: Using work information only for work
*   Tier 4: Storing documents according to their classification

Impact types

*   System compromise
*   Data compromise
*   Physical asset compromise
*   Identity theft and fraud
*   Account compromise
*   Business disruption
*   Financial loss

Counts come from the AVADB catalog. Because a behavior can belong to several categories, the category totals add up to more than 102. Mappings to NIST CSF and MITRE ATT&CK are there to support your analysis; they are not a compliance guarantee.

Evidence / Breach and fraud data

## Most breachesinvolve a person.

Breach investigations, cost studies, and complaints to the FBI point the same way: attackers keep going through people, and they are adding text messages, phone calls, and AI-generated impersonation to the email playbook. Each figure names its publisher, the population counted, and the period covered.

*   62%
    
    ### of breaches involved a person’s action, such as clicking a lure or making an honest mistake
    
    *   Began with phishing**16%**
    *   Began with pretexting**6%**
    
    More than 22,000 confirmed breaches in 145 countries, November 2024 to October 2025. A year earlier the share was 60%; Verizon calls the rise slight and not worth reading into, given its error margins. The phishing and pretexting bars count only breaches with a known initial access vector, excluding errors and misuse. Pretexting means a made-up story, often told by phone, such as a caller posing as the help desk.
    
    [Verizon DBIR1](https://avareange.avacloude.ru/en/future/#source-G-DBIR26)
    
*   US$4.99M
    
    ### global average cost of a data breach
    
    Research by Ponemon Institute for IBM: breaches at 602 organizations worldwide, March 2025 to February 2026. It is the cost of the whole breach, not of phishing alone.
    
    [IBM2](https://avareange.avacloude.ru/en/future/#source-G-IBM26)
    
*   US$3.05B
    
    ### lost to business email compromise (BEC), as reported to the FBI for 2025
    
    24,768 BEC complaints to the FBI’s Internet Crime Complaint Center, mostly from the United States: about US$123,000 per complaint, by our calculation. Reported losses, not recovered ones.
    
    [FBI IC33](https://avareange.avacloude.ru/en/future/#source-G-IC3-25)
    
*   1 in 4
    
    ### malicious breaches involved AI, mostly deepfake impersonation and AI-generated malware
    
    *   AI-enabled breach, average cost**US$6M**
    *   Any breach, global average**US$4.99M**
    
    Up 56% from the previous year, IBM reports. Same study: 602 organizations, March 2025 to February 2026.
    
    [IBM2](https://avareange.avacloude.ru/en/future/#source-G-IBM26)
    
*   4×
    
    ### the phishing report rate among people trained in the last 30 days
    
    About 21% of simulated phishing emails reported, compared with a 5% baseline. Verizon saw a far smaller effect on clicks. Simulation data from more than 7,000 organizations; the 2026 edition does not update this figure.
    
    [Verizon DBIR 20254](https://avareange.avacloude.ru/en/future/#source-G-DBIR25)
    
*   ~40%
    
    ### higher median click rate on simulated phone-based lures than on email lures (our calculation)
    
    *   Phone-based lures, median**about 2%**
    *   Email lures, median**1.4%**
    
    Phishing simulations run by Verizon’s data contributors: about 2% versus 1.4%. Phone-based means texts, voice calls, and emails that ask for a callback. That sample is small, 35 campaigns, so read it as a direction rather than a benchmark.
    
    [Verizon DBIR1](https://avareange.avacloude.ru/en/future/#source-G-DBIR26)
    

### Attack volume and attempts

These count phishing sites, fraud attempts, and shares of observed incidents, not victims or losses.

*   **1,069,681**phishing sites reported to APWG, April–June 2026Up 10.1% from the first quarter. APWG counts unique phishing sites, not the people who reached them.
    
    [APWG5](https://avareange.avacloude.ru/en/future/#source-G-APWG26Q2)
    
*   **+40%**text-message phishing, first to second quarter of 2026Crane Authentication data, published in APWG’s quarterly trends report.
    
    [APWG5](https://avareange.avacloude.ru/en/future/#source-G-APWG26Q2)
    
*   **US$61,732**average amount requested in a wire-transfer BEC attempt, Q2 2026Up 45% from US$42,663 the quarter before. Fortra data, published by APWG.
    
    [APWG5](https://avareange.avacloude.ru/en/future/#source-G-APWG26Q2)
    
*   **~60%**of intrusions ENISA observed in the EU started with phishingENISA gives the share as about 60%, July 2024 to June 2025, ahead of exploited vulnerabilities at 21.3%. EU scope, incidents selected mostly from open sources.
    
    [ENISA6](https://avareange.avacloude.ru/en/future/#source-G-ENISA25)
    

Amounts are in US dollars, as the publishers reported them. Click and report rates come from phishing simulations, not real attacks. The numbered links lead to the sources below.

### Sources

1.  1[Verizon, 2026 Data Breach Investigations Report](https://www.verizon.com/business/resources/T161/reports/2026-dbir-data-breach-investigations-report.pdf). May 19, 2026. More than 22,000 confirmed data breaches at organizations in 145 countries, in incidents from November 1, 2024, to October 31, 2025. Click rates come from phishing-simulation data, where the phone-based sample is small.
2.  2[IBM, research by Ponemon Institute, Cost of a Data Breach Report 2026 (press release)](https://newsroom.ibm.com/2026-07-29-ibm-study-one-in-four-malicious-breaches-are-ai-enabled,-costing-companies-6-million-on-average). July 29, 2026. Breaches at 602 organizations worldwide, March 2025 to February 2026. Costs are for a whole breach, not for phishing alone.
3.  3[FBI Internet Crime Complaint Center (IC3), 2025 IC3 Annual Report](https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf). April 2026. 1,008,597 complaints filed with IC3 in calendar year 2025, mostly from the United States. Reported losses, not recovered ones, and not a global total.
4.  4[Verizon, 2025 Data Breach Investigations Report](https://www.verizon.com/business/resources/reports/2025-dbir-data-breach-investigations-report.pdf). April 2025. Phishing-simulation data from more than 7,000 organizations. “Recent training” means within the previous 30 days.
5.  5[Anti-Phishing Working Group (APWG), Phishing Activity Trends Report, 2nd Quarter 2026](https://docs.apwg.org/reports/apwg_trends_report_q2_2026.pdf). August 28, 2026. Phishing sites reported to APWG worldwide, April to June 2026, with member data from Crane Authentication (text-message phishing), Fortra (email-based scams), and ZeroFox (social media).
6.  6[European Union Agency for Cybersecurity (ENISA), ENISA Threat Landscape 2025](https://www.enisa.europa.eu/sites/default/files/2026-01/ENISA%20Threat%20Landscape%202025_v1.2.pdf). October 2025 (references updated January 2026). 4,875 incidents selected by ENISA, mostly from open sources, July 1, 2024, to June 30, 2025. The link opens file version 1.2.

Deployment / Cloud or on-prem

## Our cloud,or your own servers.

Start on our SaaS with nothing to install, or run AVAREANGE inside your own network when the data has to stay in-house. Either way it sends from your domains and takes your SCORM courses; On-Premise and Enterprise add directory sync and SIEM export.

SaaS**Hosted by AVAREANGE**

Launch the first campaign without provisioning a single server.

On-Premise**Inside your own network**

The whole platform runs on infrastructure you control.

*   Every deployment
*   On-Premise and Enterprise

*   **SMTP**Your domains
*   **SCORM**1.2 / 2004
*   **2FA**Sign-in
*   **Outlook**Add-in
*   **Departments**Hierarchy and tags
*   **Reports**Export

*   AD / LDAP sync
*   Syslog to SIEM
*   Self-hosted

What’s included depends on your plan and how you deploy.

Pricing / Open price list

## Prices up front.No guessing games.

Choose a plan, how you want to deploy, and how many people you have. The list price updates as you go, and the quote email opens pre-filled. Enterprise deals start at US$27,500 a year.

Plans

Your configurationPro

Deployment

Employees: **up to 1,000**

Each additional block of 1,000 employees adds US$1,000 a year. Prefer to run it yourself? Switch to On-Premise.

Works out to US$6.90 per employee a year at 1,000 employees.

List price: 6,900 US dollars per year

*   Unlimited simulations
*   Email simulations with English-language templates
*   SCORM course import

Get this quote

Your email opens with this plan, deployment, headcount, and list price filled in.

Pricing request email address

help@avareange.ru

[Request a quote by email](mailto:help@avareange.ru?subject=AVAREANGE%20pricing%20request%3A%20Pro%20SaaS%2C%201%2C000%20employees&body=Plan%3A%20Pro%0ADeployment%3A%20SaaS%0AEmployees%3A%20up%20to%201%2C000%0AList%20price%3A%20US%246%2C900%20per%20year%0AList%20prices%20in%20US%20dollars%2C%20excluding%20taxes%2C%20as%20of%20September%2026%2C%202026.%0A%0ACompany%3A%0ACountry%3A%0AYour%20name%20and%20role%3A)

Your email will include: Pro · up to 1,000 employees · SaaS · US$6,900 per year

List prices in US dollars (US$), excluding taxes, as of September 26, 2026. Sales tax, VAT, or withholding tax may apply depending on where you’re based.

Get started

## Make your peopleyour strongest link.

Tell us which attacks worry you most. We’ll walk you through them in AVAREANGE: the simulation, the debrief an employee sees right after a click, and how each result moves the AVADB risk score.

Email address for demo requests

help@avareange.ru

[Send an email](mailto:help@avareange.ru?subject=AVAREANGE%20demo%20request)
