← All services

Phishing Simulation and Awareness

Technical controls protect your systems. But attackers often skip the system entirely and convince an employee instead. Phishing simulation is the only realistic way to measure how resistant that human layer really is.

The goal is measurement, not blame

The commonly misunderstood part: this is not about producing a list of "who clicked". It is about seeing which department struggles with which scenario, and directing training there. Naming individuals leads staff to hide from the next test — which makes the test useless.

How we run it

1. Written approval
Written approval from management. The staff-notification policy and the data-protection framework are agreed. Testing does not start without this.

2. Scenario design
A scenario matching your real workflows: an invoice notice for accounts, a CV application for HR, a meeting invitation for management. Targeted, not random.

3. Delivery and measurement
A personalised email is sent. Three things are measured: open rate, link click rate and submission rate (credentials entered).

4. Instant training
Anyone who clicks is redirected to a short training page. Educational, not accusatory.

5. Report
Department breakdown instead of individual names. Which scenario worked, which department is at risk, where training should focus.

Legal framework

Phishing simulation is legal — as long as it is run with written management approval and a transparent framework. Points to observe:

  • Written approval from management (who authorized what, when)
  • The staff-notification policy covering this type of testing
  • Immediate destruction of any data collected (e.g. entered credentials) at test end
  • Results never used as a disciplinary tool

What is delivered

  • Department-level risk report (no individual names)
  • Which scenario worked and at what rate
  • Sample phishing email and the warning signs to watch for
  • Awareness content for staff
  • Improvement recommendations for the next round

Free initial assessment

Send us the scope; within 24 hours you receive the tests required, the timeline and a price range in writing.

Get a Quote