Security awareness training, built in Jakarta

Phishing simulationthat changes behaviour.

Send realistic phishing over email, voice, SMS and WhatsApp. Catch the click, teach on the spot, and watch your reporting rate climb. Then export the evidence your regulator asks for.

Hosted in Southeast Asia. English and Bahasa Indonesia as standard.

CampaignRunning

Q3 Credential Harvest, All Staff

Click rateReport rate1,840 recipients, last 8 campaigns
Opened63.4%
Clicked6.9%
Reported51.3%
Mapped controls
  • OJK POJK 11/202211
  • Bank Indonesia PBI 2/20248
  • ISO/IEC 27001:20227
  • NIST CSF 2.06
  • UU PDP3
Auto-assigned12 min ago

Recognizing Phishing Emails

Triggered by a credential submit

Rina W., FinanceDue in 7d

Illustrative interface. Sample data.

Regulatory readiness

Your auditors already have a control language. Claro reports in it, so the awareness section of your next examination is mostly written before you start.

OJK POJK 11/2022
Board-ready reporting on awareness activity, incident readiness and staff competency, on whatever schedule you set.
Bank Indonesia PBI 2/2024
Cyber resilience and security programme records for banks supervised under the KKS regime.
ISO/IEC 27001:2022
A.6.3 awareness and training evidence, exported with dates, cohorts and outcomes attached.
NIST CSF 2.0
Govern, Identify, Protect, Detect, Respond and Recover outcomes evidenced from live campaign data.
UU PDP
Training records for personal data handling, retention settings and per-user erasure logs.

Claro generates the evidence and the control mapping. Certification and regulatory findings stay with your auditor and your supervisory authority.

Human risk intelligence

Human risk scoring your board can read

Attendance is easy to hit and tells you nothing. Two numbers predict whether a real attack lands: how many people click, and how many people report it. Claro moves both.

Click rate
24.1%6.9%
Report rate
6.2%51.3%
Median time to report
42 min6 min
Click rateReport rate

Sample tenant data over six campaign cycles. Yours will look different.

Most improvedBranch Operations went from elevated to low in two quarters. No extra classroom sessions.

See how the scoring works
The programme, end to end

How your security awareness programme runs

Most tools stop when someone finishes a module. Claro keeps going. It provokes a real decision, records what people actually did, and coaches them at the moment of the mistake. What comes out the other end is a score you can defend and a report you can file.

  1. 01Simulate

    Every channel your staff actually use

    Email is where most programmes stop. Attackers moved on years ago. Claro runs voice, SMS and WhatsApp simulations from the same console, using lures written for Indonesia rather than translated from somewhere else.

    • Four channels live: email, voice, SMS, WhatsApp
    • AI-written spear phishing and double-barrel sequences
    • 71 email templates, including Indonesian lures written locally
    • BPJS Kesehatan, membership data checkGovernmentID
    • J&T Express, customs charge confirmationLogisticsID
    • Finance, urgent CFO wire requestFinanceEN
    71 email templates in the global libraryAI personalisation on
  2. 02Observe

    Behaviour, timestamped

    You get more than a click count. Every delivery, open, click, credential submit and report lands on a per-person timeline. When somebody reports the email straight from Outlook or Gmail, that counts too.

    • Per-recipient event timeline
    • One-click reporting from Outlook and Gmail
    • Breakdowns by department, device and browser
    Event streamRecipient 0412
    1. Email delivered09:12:04
    2. Opened09:14:37
    3. Link clicked09:15:02
    4. Credentials submitted09:15:48
    5. Awareness page shown09:15:49
    6. Training assigned09:16:03

    One second between the password going in and the lesson coming up.

  3. 03Teach

    Coaching at the moment it lands

    Nobody learns from a reminder three weeks later. The second someone submits a password, Claro shows them what they missed, in their own language, and books the matching module before they close the tab.

    • Just-in-time awareness page per attack type
    • Rules assign training by trigger, department or schedule
    • Runs your existing SCORM and xAPI content alongside ours
    Awareness page

    This was a simulation

    You entered your password on a page that was not ours. Here is what gave it away.

    • The sender domain was not the bank's real domain
    • The link went to a lookalike address
    • The message pushed for action within the hour
    Assignment rule

    On credential submit, assign the matching module and set a 7 day due date.

    Assigned module

    Recognizing Phishing Emails

    6 min, pass mark 80%

  4. 04Measure

    A risk score you can defend line by line

    One number per person, plus the factors behind it. Show a department head exactly why their team scores the way it does and what has moved since last quarter. No arguing with the methodology in front of the board.

    • Scoring per user, team and department
    • Every factor visible, nothing hidden in a black box
    • Reporting rate treated as a headline metric
    Average risk score
    3114
    vs previous quarter
    • Low62%
    • Moderate24%
    • Elevated10%
    • Critical4%
    Largest movements
    • Repeat clicks, Operations+18
    • Time to report, all staff-12
    • Credential submits, Finance-9
  5. 05Prove

    The audit pack, already written

    Pick a framework and a period. Claro builds the report from live data, in English or Bahasa Indonesia, and emails it to your risk committee every quarter. Nobody touches a spreadsheet.

    • Five report types across five frameworks
    • Scheduled generation and delivery
    • Full evidence bundle with CSV exports
    Evidence packQ3 2026, generated
    • OJK supervisory reportPDF, Bahasa Indonesia
    • ISO 27001 control mappingPDF, English
    • Campaign and training recordsCSV, 4 files
    Mapped controls35

    Every control links back to the campaigns, modules and reports behind it.

Built here

Made in Jakarta for Indonesian compliance

Claro was built by an Indonesian team for organisations that answer to OJK and BSSN, run bilingual workforces, and get asked hard questions about where their data sits.

Bahasa Indonesia is not a plugin
Training modules, awareness pages, the learner interface and every generated report ship in both languages. The phishing library carries Indonesian lures written locally, not translated ones.
Your data stays in the region
Claro is a managed service hosted in Southeast Asia, with a separate encryption key for every tenant and deletion on request.
Lures your staff have already seen
Account re-verification, customs charges, delivery fees, government notices, e-wallet prizes. Modelled on what is circulating here, not on American gift-card scams.
From the template library
J&T Express Indonesiajnt-customs@mail.example.id

J&T Express: Status bea cukai paket Anda

Paket Anda tertahan di bea cukai. Konfirmasi pembayaran dalam 1 x 24 jam agar pengiriman dapat dilanjutkan.

Konfirmasi pembayaran
How it runs
Managed and hosted
Nothing for your team to run or patch. Fixes and features ship continuously.
A key per tenant
Personal data is encrypted at rest. Destroy the key and it becomes unreadable for good.
Regional residency
Hosted in Southeast Asia so employee records never leave the region.

Questions buyers ask

  • A safe, controlled phishing email sent by your own security team to your own staff. Nobody gets punished. The point is to find out who is exposed and coach them at the moment they slip, before a real attacker gets there first.

Show your board a number that moved

Thirty minutes to scope it. A pilot on one department. An evidence pack you can take into your next audit.

What happens next
  1. A 30 minute call on your channels, languages and reporting obligations.
  2. A pilot on one department, with a baseline and a follow-up campaign.
  3. The evidence pack from that pilot, in the framework you report on.