PHISHING SIMULATION AND SECURITY AWARENESS TRAINING PLATFORM

IOM
PHISHING SIMULATION AND SECURITY AWARENESS TRAINING PLATFORM Request for proposal

Reference: 30000030029
Beneficiary countries or territories: Switzerland
Registration level: Basic
Published on: 24-Jul-2026
Deadline on: 06-Aug-2026 18:00 0.00
Description
The International Organization for Migration (IOM) invites qualified vendors to submit proposals for the provision, implementation, support and continuous improvement of a cloud-based phishing simulation and security awareness training platform for approximately 20,000 users. The proposed solution shall enable IOM to plan, execute and measure phishing simulation campaigns, deliver risk-based and role-based training, monitor user behaviour, and report on awareness and resilience indicators across the Organization. The purpose of this RFP is to identify the proposal that offers the best value for money to IOM, taking into consideration technical quality, functional coverage, security and privacy posture, implementation approach, service support, scalability, sustainability, and total cost of ownership. 1. BACKGROUND AND OBJECTIVE IOM seeks to strengthen organizational resilience against phishing, social engineering and user-targeted cyber threats through a scalable, measurable and accessible platform that supports global awareness campaigns, targeted simulations, automated training assignments and audit-ready reporting. The solution shall support approximately 20,000 target users and shall be delivered as a cloud-based service. Vendors shall clearly describe how the proposed solution will support a geographically distributed workforce, multiple user populations, different risk profiles and future scalability. 2. SCOPE OF SERVICES The selected vendor shall provide a complete phishing simulation and security awareness training solution, including platform licensing, configuration, onboarding, integration support, administrator training, user communication support, reporting, maintenance, technical support and optimization services. 2.1 PHISHING SIMULATION AND TESTING Vendors shall demonstrate that the proposed platform supports the following phishing simulation and testing requirements: • Targeted and enterprise-wide phishing campaigns: Ability to launch phishing simulations for selected user groups, departments, offices or the full organization, depending on campaign objectives and risk priorities. • User segmentation: Ability to segment recipients by user attributes such as department, office, role, region, risk profile or other defined criteria to enable targeted and relevant simulations. • Flexible campaign delivery: Ability to schedule campaigns for a specific date and time, launch them immediately, or stagger delivery over a defined period to simulate realistic phishing activity and reduce operational disruption. 2.2 SIMULATION CONTENT • Threat-informed simulation templates: The platform shall provide pre-built phishing templates aligned with current threat trends, common attack techniques and realistic scenarios relevant to a global organization. • Custom template creation: The platform shall allow authorized administrators to create, edit and manage custom phishing templates tailored to IOM-specific processes, communications and risk scenarios. • Advanced use-case scenario support: The platform shall support simulation scenarios beyond standard phishing emails, including targeted, contextual or high-risk use cases that reflect evolving social engineering techniques. • User-level campaign suppression: The platform shall allow administrators to exclude specific users from campaigns, including users on medical leave, separated personnel, or other cases where participation is not appropriate.

Email address: mtomas@iom.int
First name: Maria Helena
Surname: TOMAS