Phishing simulations: train your team before a real attacker does

91% of cyberattacks start with a phishing email. Your systems can be flawless; it only takes one employee clicking the wrong link. Simulations measure exactly that and help change behavior, not just deliver a talk.

Firewalls don't protect against human error

You can have the best security software on the market and still be vulnerable if your employees don't recognize a malicious email, a fake SMS, or a call from someone impersonating IT support. Social engineering doesn't attack systems — it attacks people. And the only way to know if your team is ready is to test them under controlled conditions.

Types of simulations we run

  • Standard phishing: fraudulent emails with malicious URLs or attachments
  • Spear phishing: personalized emails for specific profiles (CISO, finance, HR)
  • Vishing: phone calls impersonating IT support, a bank or a supplier
  • Smishing: fraudulent SMS mimicking banking or delivery alerts
  • Multi-channel campaigns: combining email + phone call + SMS
  • Internal phishing: simulating an attacker already inside the organization

How we design and run the campaign

  1. Objective definition: We agree what we want to measure: click rate, credential submission, attachment downloads, response to calls.
  2. Scenario design: We create realistic emails, capture pages and call scripts tailored to your sector and industry.
  3. Campaign execution: We launch the campaign under the agreed conditions, with full discretion so results aren't skewed.
  4. Results analysis: We measure click rates, credential submissions, employee reports and the security team's reaction time.
  5. Training and feedback: We share the results with the team, explain the warning signs they should have caught, and give improvement recommendations.

Deliverables

  • Results report: click rates, performance by department, comparison against sector benchmarks
  • Analysis of the most effective emails/SMS/calls (to understand what fools your team)
  • Personalized awareness module based on the results
  • Technical recommendations: SPF, DKIM, DMARC, email filters, periodic training

Who should run phishing simulations?

  • Any company with employees who receive corporate email
  • Organizations with an awareness requirement under NIS2 or ISO 27001
  • Companies with high-risk profiles: finance, HR, executive leadership
  • Teams that have suffered phishing-related incidents
  • Companies that want to measure improvement after a security training program

Frequently asked questions

Will employees know it's a simulation?

Not during the campaign. The learning effect is much greater when the employee discovers, after clicking, that it was a test. It's handled with care: employees aren't publicly identified or penalized, only trained.

Do you need access to our email server?

We need our sending infrastructure to be whitelisted so emails reach inboxes correctly. It's a simple technical process we manage together with you.

What happens to the data on who clicked?

Data is handled with strict confidentiality. The report can be presented anonymized by department if you prefer, without identifying individual employees.

How often should these simulations be run?

The recommended minimum is 2-3 campaigns per year. Awareness fades over time if it isn't reinforced. Ideally it's complemented with short, periodic training modules.