Hero

WE ARE

HACKIFY

What is a phishing simulation

Icon of a phishing simulation

Phishing is one of the most common ways to gain access to an organisation. You can set up your firewall, antivirus and endpoint protection as well as you like, but if a single employee clicks on a phishing email and enters their credentials, an attacker bypasses all of it. People remain the weakest link in your security.

Phishing has also become a great deal more sophisticated. The messages about a Nigerian prince have been replaced by targeted attacks that bypass MFA, by CEO fraud and by spoofed login pages that are indistinguishable from the real thing. Attackers play on haste and authority to deceive an employee. The result can be a ransomware infection, fraud through Business Email Compromise or a data breach.

A phishing simulation (also known as a phishing test or security awareness test) tests how resilient your employees are to phishing. To do this, we send realistic phishing emails. Our ethical hackers recreate real attack scenarios, from a simple click test to a scenario in which MFA is bypassed. This shows you how your organisation responds to phishing and where an awareness training is needed.


Why and when is a phishing simulation important?

For a cybercriminal, an employee is often the easiest target. A single click on a phishing email is enough for a compromised account, a ransomware infection or financial fraud. Spam filters and antivirus by no means catch all phishing. A targeted spear phishing email usually slips through effortlessly.

A phishing simulation is sensible in the following situations:

  • you want to know whether an earlier awareness training has actually had an effect
  • you need to meet the awareness requirements of ISO 27001, NIS2 or SOC 2
  • you want to measure how alert your employees are every quarter or every six months
  • you have had a phishing or ransomware incident and want to check whether alertness has improved
  • you want to test departments that are especially in the spotlight, such as finance, HR and the board, separately

A phishing simulation is not a one-off exercise. Attack techniques change, so it is sensible to repeat the simulation with some regularity to keep employees alert.


What forms of phishing simulations are there?

We work with four types of phishing simulation. Each type tests a different attack vector and goes a step further than the previous one. Together they recreate the chain that a real phishing attack goes through.

Type 1: Click test (basic phishing awareness)

The click test is the simplest form. Employees receive a phishing email with a link or a button. We measure how many employees open the email and how many click on the link.

Anyone who clicks arrives on a landing page that explains that this was a test and how the email could be recognised. This way, the employee takes something away immediately.

Type 2: Click & login (credential harvesting test)

The click & login simulation goes a step further and tests whether employees also enter their credentials on a spoofed portal. Anyone who clicks on the link arrives on a fake login page, for example of Microsoft 365, a VPN or an HR portal. In addition to the figures from type 1, we measure:

  • how many employees enter their credentials
  • the strength of the passwords entered, based on length and complexity (we never keep the password itself)
  • whether employees attempt to log in multiple times

This is the most common form of phishing: stealing credentials via a fake page.

Type 3: Click & login & download (malware execution test)

The click & login & download simulation tests the scenario in which an employee downloads and opens a file. This is how attackers spread ransomware and malware via phishing. In addition to the figures from types 1 and 2, we measure how many employees download the file and how many actually run it.

For this we use safe test files that cause no damage but can be detected, for example via a macro, an HTA file or an executable with a harmless payload. This shows you whether your endpoint protection blocks these files and whether employees ignore the warnings.

Type 4: MFA test (multi-factor authentication bypass)

The MFA test recreates an attack in which an attacker tries to bypass MFA through social engineering. After all, MFA is no guarantee against phishing. Attackers use MFA fatigue, prompt bombing or adversary-in-the-middle (AiTM). In addition to the figures from types 1 and 2, we measure how many employees approve the MFA prompt and how they respond to a suspicious prompt.

To do this, we show a fake MFA prompt after credentials have been entered, or we trigger a real MFA prompt via, for example, Microsoft Authenticator or Duo. This shows us whether employees approve the prompt, despite the suspicious situation.


Why choose Hackify?

  • Proven expertise - Ethical hackers with at least 5 years of experience, 3 certificates and relevant expertise per test component (not the industry minimum of 1 year and 1 certificate)
    • Track record - Responsible disclosures at Philips, Zoom, Oracle, the Dutch Police and many others
    • Hacking competition winners - Prizes at Hack010, PVIB CTF, Hackerhotel and HackTheHague
  • Phishing expertise - Specialist knowledge of modern phishing techniques, MFA bypass and Evilginx tools
  • Direct contact - No account managers, speak directly with the pentesters who carry out your simulation
  • Flexibility - Phishing simulations can often be scheduled within 2-3 weeks

More about our approach and expertise on our about us page.


Schedule your phishing simulation

Would you like to know how resilient your employees are to phishing? Then get in touch with us without obligation via our contact page. We are happy to tell you more about our company and our approach, and would love to hear more about your organisation and the scope of the simulation.

Every phishing simulation is different, so we draw up a bespoke proposal for each assignment. A simulation can start within 3 weeks. Depending on the scope, the work takes 1 to 3 days. We deliver the report within a week of the campaign.

Ready for a phishing simulation?

We test how resilient your employees are to phishing with a realistic campaign, including MFA bypass via Evilginx where it fits the scope. Request a bespoke proposal.

Get in touch

Or email us directly at [email protected]

Frequently asked questions about phishing simulations

What is the difference between a phishing simulation and a pentest?

A phishing simulation tests how alert your employees are to phishing. We look at a number of things:

  • Do employees recognise a phishing email as such?
  • Do they click on a suspicious link?
  • Do they enter their credentials on a spoofed portal?
  • Do they approve an MFA prompt in a suspicious situation?

A pentest examines the technical vulnerabilities in your systems. A phishing simulation examines the human layer, often the weakest link in your security.

What does a phishing simulation cost?

The price of a phishing simulation depends on the scope, the number of employees and other aspects such as customisation and specific requirements. After an intake meeting, we draw up a suitable proposal that fits your situation.

Can you create bespoke phishing scenarios?

Yes. We work with standard scenarios and with scenarios that we tailor entirely to your organisation.

Standard scenarios we often use:

  • a notice that a password has expired
  • a request to carry out a printer update
  • choosing a Christmas gift
  • a shared file that needs to be viewed
  • additional verification for a parcel delivery

For a bespoke scenario, we adjust the sender name and email address, use your own house style in the email and landing page, and register a dedicated domain for the website and email. A bespoke scenario is more realistic, because it is tailored to your organisation.

What happens to the passwords that are entered?

We handle privacy carefully. We never store the password itself. We only record statistics about the password, such as its length and strength. We do record usernames and email addresses, because this lets us measure how many employees clicked on the link. After the report is delivered, we remove all data, in line with the GDPR.

This means we can show you how many employees use a weak password, without us ever knowing those passwords ourselves.

What is included in the phishing simulation report?

You receive a report with the campaign statistics and a technical analysis.

Under the statistics you will find:

  • the number of emails sent and how many employees opened the email
  • how many employees clicked on the link
  • how many employees entered their credentials
  • an analysis of the strength of the passwords used
  • for type 3, how many employees downloaded and ran the file
  • for type 4, how many employees approved the MFA prompt

The technical analysis describes the configuration of your SPF, DKIM and DMARC, the effectiveness of your phishing filter and the security of the mail client. We provide concrete recommendations alongside this, such as setting up a warning banner for external email.

On request, we discuss the results with your management or follow up with an awareness training. We present all figures with charts, so you can see straight away where improvement is needed.

How long does a phishing simulation take?

The lead time depends on the scope. We allow roughly a week for the intake meeting and preparation. The campaign itself lasts 1 to 3 days, and we deliver the report within a week of the campaign. If you would like a training session afterwards, we schedule it directly after the results. During the intake meeting, we set out the planning together.