Terranova Security's most visible phishing asset is the annual Gone Phishing Tournament - a free, industry-wide benchmark co-sponsored with Microsoft. The 2023 edition, per Terranova's own press release distributed on PRWeb, deployed more than 1.37 million simulated phishing emails to participants at nearly 300 organisations between October 9-27, 2023. Results showed a 10.4% click-through rate (up 3.4 points year-on-year) and a 6.5% password-submission rate among those who clicked, with education the highest-risk sector (16.8% click-through) and finance the lowest (6.2%). A separate Technology Record article confirms Microsoft co-sponsors the event and that participants can "benchmark their performance against peers" by industry, region and size.
Day-to-day, Fortra's own release notes describe "immediate remediation" that automatically assigns follow-up courses to users who fail a simulation - genuine in-product automation, still referenced as recently as June 2026, distinct from the once-a-year tournament. A separate orchestration tool, Campaign Manager, existed earlier in the platform but was "fully decommissioned" in May 2026 (version 1.126), per Fortra's own release notes - a reminder that feature sets in this category shift, and worth confirming directly before relying on any specific tool name. Terranova also announced a partnership with Elevate Security, per a PRNewswire release, adding risk scoring that identifies users behind "4% of users causing 80% of phishing incidents" for more targeted enrolment.
On risk scoring specifically, we found two named tools: Cyber Hero Score, announced via a Newswire press release as a rating built from role, access, knowledge, breach proximity and behavioural data, and the Security Awareness Index (SAI) that appears in Terranova's current product documentation and release notes. Both are genuinely sophisticated profiling tools - neither, in the materials we could access, is described as mapped to a named compliance framework's specific controls.
Cyber Aware's Auto Phish generates a full year of varied phishing campaigns from a single setup conversation, and its gap assessments map directly to Essential 8 and SMB1001 controls from the first report.