As organisations across the Middle East face increasingly sophisticated cyber threats, the human element continues to remain one of the most difficult risks to measure and manage. Traditional security awareness programmes and periodic training often struggle to reflect how employees actually behave when confronted with real world cyber threats.
Addressing this gap, SimuPhish, a UAE- incubated cybersecurity firm, has developed Human Risk Management + (HRM+), an experiential platform designed to help organisations assess, understand and condition human behaviour against evolving cyber threats.
The platform brings together AI-powered automation & analytics, multi-vector risk assessments and multilingual capabilities to create real life and measurable experiences for employees. Rather than relying solely on conventional awareness training, SimuPhish enables organisations to assess how people respond to different attack scenarios and use those insights to strengthen their overall human risk posture.
Moving from awareness to behaviour: where human risk actually changes.
One of the key challenges facing organisations today is the gap between knowing what to do and doing it under pressure. Employees may understand cybersecurity best practices in a classroom or online course, but real-world attacks are designed to exploit human emotion, urgency, trust and distraction.
SimuPhish takes an experiential approach by exposing employees to realistic risk scenarios across multiple communication channels and measuring their responses. These experiences can help organisations identify vulnerable behaviours, understand risk patterns, improve user instincts and reinforce safer responses over time.
Shubh Arya, CEO and Co-Founder of SimuPhish, said: “Cybersecurity awareness cannot stop at telling people what not to do. Human behaviour needs to be experienced, measured and conditioned. We created SimuPhish because organisations needed a way to understand how their people actually respond to cyber risk and not simply whether they completed a training module. Our goal with HRM+ is to make human risk measurable, actionable and continuously improvable”.
One platform. Multiple attack vectors. Multiple languages.
SimuPhish’s HRM+ platform is designed to reflect the way modern attacks reach employees. Its multi-vector capabilities extend beyond traditional email-based scenarios to include channels such as voice, messaging and other social engineering attack vectors, enabling organisations to evaluate human responses across different threat environments.
The platform’s multilingual capabilities, supporting 75+ languages, are particularly relevant to organisations operating across diverse workforce ethnicities and geographies. This allows organisations to deliver relevant experiences in languages employees are more comfortable using, helping make risk assessments more realistic and inclusive.
AI-powered automation further enables organisations to streamline the creation, management and delivery of risk assessment programmes, helping security and HR teams scale human risk initiatives without creating significant operational overhead.
From a UAE market gap to international expansion
SimuPhish was founded after its founders, Shubh Arya and Hritik Jain, identified a clear gap in the cybersecurity market while working in the UAE. They recognised that organisations needed to move beyond conventional security awareness approaches and gain greater visibility into how human behavior contributes to cyber risk.
What began as a solution focused on addressing this regional need has since expanded beyond the UAE, with SimuPhish now extending its presence into the UK, Europe and Africa.
Hritik Jain, CTO and Co-Founder of SimuPhish, said: “Technology has evolved rapidly, and so have the techniques used by attackers. Human risk platforms need to evolve at the same pace. We built SimuPhish to combine automation, AI, multiple attack vectors and multilingual capabilities into a platform that can replicate the complexity of today’s threat landscape. The objective is not simply to test employees, it is to generate meaningful behavioural intelligence that organisations can act on”.
Supporting compliance and sector-specific requirements
Human risk is also becoming increasingly important as organisations work to meet cybersecurity and data protection requirements across the region. SimuPhish is designed to support organisations in aligning their human risk and security awareness initiatives with applicable regional cybersecurity and compliance frameworks, helping organisations incorporate measurable human-risk activities into their broader security programmes.
The platform is designed to support a broad range of sectors, including banking and financial services, retail, government, technology, healthcare and other highly regulated industries, where employees routinely interact with sensitive information and critical systems.
As cyber threats increasingly target people rather than just infrastructure, SimuPhish believes organisations need to treat human behavior as an integral part of their cybersecurity strategy.
“The future of cybersecurity is not only about protecting systems; it is about preparing people”, added Shubh. “When organisations understand behaviour, they can start changing behaviour. That is the foundation of Human Risk Management +.”
With its UAE roots and expanding international footprint, SimuPhish aims to help organisations across the region and beyond to build a more resilient human layer of defence—one measurable experience at a time.
Image Credit: SimuPhish
Source: Tahawul Tech

