The Cyber Empowerment Hub

The Cyber Empowerment Hub Ltd

The Ethical Phishing Simulation Pledge

A public standard for how we run phishing-awareness training. It protects the people we train, respects the brands criminals impersonate, and puts brands in control of their own identity, on their terms, at all times.

See our commitments How brands take part

Why this exists

Phishing is one of the most common ways criminals defraud people and organisations, and they succeed by impersonating brands the public already trusts. The most effective defence is practice: safe, controlled simulations that teach people to spot the fakes before a real one reaches them.

Here is the bind. Criminals copy a real email down to the last detail, the same layout, the same wording, the same logo, and change nothing but the link before sending it out in the brand's name. The people trying to defend against this cannot answer in kind. There is no clean way for a legitimate trainer to reference the brands the public actually trusts, so awareness training falls back on generic templates that look nothing like a real attack. People are practised against a threat that bears no resemblance to the one they will meet, and they find out the difference only when a real one lands. The realistic material is wide open to the criminals and closed to the good guys.

Done well, this protects everyone: the people being trained, the businesses employing them, and the brands whose names criminals abuse. Done badly, it can deceive people who never agreed to take part, mishandle personal data, or damage the very brands it borrows.

This pledge sets a clear, public line between the two. We hold ourselves to it without exception, and we built it so that any brand can rely on it: deciding for themselves whether we may reference their identity in training, and staying in control of that decision at every point. It gives a brand a single, simple choice instead of a private negotiation, and it gives everyone else a plain answer to why they should trust us with a name that isn't ours.

Our commitments

The promises we hold ourselves to, without exception, every time.

  1. 01

    Consent first, always

    We only ever send simulated phishing to people whose organisation has enrolled them in a training programme, or who have personally and verifiably agreed to be tested. We never target members of the public, and we never target anyone who has not consented, directly or through their employer.

  2. 02

    Education, never exploitation

    Every simulation exists to teach. Our landing pages are educational only. We never build or operate credential-harvesting pages, never capture passwords, card details or other sensitive information, and never retain data that a real attacker would seek to steal.

  3. 03

    Always reveal the lesson

    Anyone who interacts with a simulation is promptly and clearly told that it was a training exercise, not a real message, and is given guidance on how to recognise the real thing.

  4. 04

    Closed environments only

    Simulation materials are used exclusively within controlled training programmes for consenting participants. We do not publish working phishing templates, distribute them to the public, or make convincing brand-impersonation kits available to anyone who could misuse them.

  5. 05

    Respect for brands and their marks

    Where a training scenario refers to a real brand, we do so only as set out under how brands take part. We never imply that a brand sponsors, endorses or is affiliated with our simulations or our business. All trademarks and logos remain the property of their owners. We never use government, Crown or official insignia (for example HMRC, NHS, DVLA, GOV.UK, police) without the relevant authority's explicit permission.

  6. 06

    Honour opt-outs and takedowns, fast

    Any brand owner may ask us to stop using their identity, or to change how we use it. We act on any such request within 5 working days, without argument, and confirm when it is done. Contact: takedown@cyberempowermenthub.co.uk.

  7. 07

    Protect personal data

    We handle all personal data in line with UK GDPR and the Data Protection Act 2018: lawful basis, data minimisation, security, retention limits and participants' rights. We collect only what the training genuinely requires.

  8. 08

    Verify who we sell to

    Before providing our service, we take steps proportionate to the customer to confirm their identity and legitimate purpose. For organisations this means confirming the business is genuine and that the buyer acts for it. For individuals, who present greater risk, we apply enhanced checks and require a binding commitment that simulations will only ever be sent to people who have consented. We refuse service where misuse is suspected.

  9. 09

    No help for real attackers

    We will not provide materials, tooling or advice to anyone we believe intends to use them to deceive, defraud or gain unauthorised access. We treat our own product as something that must never become an instrument of real fraud.

  10. 10

    Accountability

    We publish who we are and how to reach us, and we respond to complaints. If we ever breach this pledge, any brand may withdraw their participation immediately, and we accept that the breach may be made public.

How brands take part

Support the training that protects your customers, on your terms.

If your organisation's name is impersonated by real phishing attacks, controlled training that teaches the public to recognise those fakes protects your customers and your reputation. This pledge lets you support that training on your terms, with control you can exercise at any time.

You give up nothing by taking part. Today, no legitimate use of your identity exists without your permission. This pledge does not weaken any of your existing rights: anyone who misuses your brand remains just as liable to you as they are now. What it adds is a single, controlled lane through which we can help protect the public using your brand's name, plus a clear way to tell that apart from the criminals who impersonate you regardless.

Default

Opt out

Your brand is not referenced at all. We maintain and respect a do-not-use list.

By request

Opt in

We may reference your brand in simulations, bound to the Code of Conduct above, plus any additional conditions you set.

  • Use is conditional, never open. Reference is only ever made under the Code of Conduct above. If we breach it, we lose the right to use your identity and you may say so publicly.

  • Control and conditions. You may set your own conditions (which assets, which contexts, which markets) and we will honour them.

  • The right to withdraw, at any time, with changes actioned within 5 working days.

  • No implied endorsement. Participation is permission for controlled training use only. It never means you endorse, sponsor or are affiliated with us.

  • A single point of contact for questions, conditions, complaints or withdrawal: brands@cyberempowermenthub.co.uk.

To register your brand's choice, contact brands@cyberempowermenthub.co.uk.

Governance

A pledge is only as trustworthy as its enforcement.

We maintain the register of participating brands and the do-not-use list, publish this Code of Conduct and keep it current, and receive and act on complaints. If we ever breach this pledge, any brand may withdraw their participation immediately, and we accept that the breach may be made public.

Supported by

This pledge has been developed to align with published UK cyber-security and fraud-prevention guidance, and we are seeking the support and input of leading UK cyber-security and anti-fraud organisations. Endorsing organisations will be listed here.

Take part

Brands

Register your participation choice: opt in with your own conditions, or confirm you'd rather stay on the do-not-use list.

Register your choice

Everyone else

Questions about this pledge, or think a brand's identity is being misused outside it? Tell us.

Get in touch