Phishing is one of the most common ways to gain access to an organisation. You can set up your firewall, antivirus and endpoint protection as well as you like, but if a single employee clicks on a phishing email and enters their credentials, an attacker bypasses all of it. People remain the weakest link in your security.
Phishing has also become a great deal more sophisticated. The messages about a Nigerian prince have been replaced by targeted attacks that bypass MFA, by CEO fraud and by spoofed login pages that are indistinguishable from the real thing. Attackers play on haste and authority to deceive an employee. The result can be a ransomware infection, fraud through Business Email Compromise or a data breach.
A phishing simulation (also known as a phishing test or security awareness test) tests how resilient your employees are to phishing. To do this, we send realistic phishing emails. Our ethical hackers recreate real attack scenarios, from a simple click test to a scenario in which MFA is bypassed. This shows you how your organisation responds to phishing and where an awareness training is needed.
For a cybercriminal, an employee is often the easiest target. A single click on a phishing email is enough for a compromised account, a ransomware infection or financial fraud. Spam filters and antivirus by no means catch all phishing. A targeted spear phishing email usually slips through effortlessly.
A phishing simulation is sensible in the following situations:
A phishing simulation is not a one-off exercise. Attack techniques change, so it is sensible to repeat the simulation with some regularity to keep employees alert.
We work with four types of phishing simulation. Each type tests a different attack vector and goes a step further than the previous one. Together they recreate the chain that a real phishing attack goes through.
The click test is the simplest form. Employees receive a phishing email with a link or a button. We measure how many employees open the email and how many click on the link.
Anyone who clicks arrives on a landing page that explains that this was a test and how the email could be recognised. This way, the employee takes something away immediately.
The click & login simulation goes a step further and tests whether employees also enter their credentials on a spoofed portal. Anyone who clicks on the link arrives on a fake login page, for example of Microsoft 365, a VPN or an HR portal. In addition to the figures from type 1, we measure:
This is the most common form of phishing: stealing credentials via a fake page.
The click & login & download simulation tests the scenario in which an employee downloads and opens a file. This is how attackers spread ransomware and malware via phishing. In addition to the figures from types 1 and 2, we measure how many employees download the file and how many actually run it.
For this we use safe test files that cause no damage but can be detected, for example via a macro, an HTA file or an executable with a harmless payload. This shows you whether your endpoint protection blocks these files and whether employees ignore the warnings.
The MFA test recreates an attack in which an attacker tries to bypass MFA through social engineering. After all, MFA is no guarantee against phishing. Attackers use MFA fatigue, prompt bombing or adversary-in-the-middle (AiTM). In addition to the figures from types 1 and 2, we measure how many employees approve the MFA prompt and how they respond to a suspicious prompt.
To do this, we show a fake MFA prompt after credentials have been entered, or we trigger a real MFA prompt via, for example, Microsoft Authenticator or Duo. This shows us whether employees approve the prompt, despite the suspicious situation.
More about our approach and expertise on our about us page.
Would you like to know how resilient your employees are to phishing? Then get in touch with us without obligation via our contact page. We are happy to tell you more about our company and our approach, and would love to hear more about your organisation and the scope of the simulation.
Every phishing simulation is different, so we draw up a bespoke proposal for each assignment. A simulation can start within 3 weeks. Depending on the scope, the work takes 1 to 3 days. We deliver the report within a week of the campaign.
We test how resilient your employees are to phishing with a realistic campaign, including MFA bypass via Evilginx where it fits the scope. Request a bespoke proposal.
Get in touchOr email us directly at [email protected]
A phishing simulation tests how alert your employees are to phishing. We look at a number of things:
A pentest examines the technical vulnerabilities in your systems. A phishing simulation examines the human layer, often the weakest link in your security.
Yes. We work with standard scenarios and with scenarios that we tailor entirely to your organisation.
Standard scenarios we often use:
For a bespoke scenario, we adjust the sender name and email address, use your own house style in the email and landing page, and register a dedicated domain for the website and email. A bespoke scenario is more realistic, because it is tailored to your organisation.
We handle privacy carefully. We never store the password itself. We only record statistics about the password, such as its length and strength. We do record usernames and email addresses, because this lets us measure how many employees clicked on the link. After the report is delivered, we remove all data, in line with the GDPR.
This means we can show you how many employees use a weak password, without us ever knowing those passwords ourselves.
You receive a report with the campaign statistics and a technical analysis.
Under the statistics you will find:
The technical analysis describes the configuration of your SPF, DKIM and DMARC, the effectiveness of your phishing filter and the security of the mail client. We provide concrete recommendations alongside this, such as setting up a warning banner for external email.
On request, we discuss the results with your management or follow up with an awareness training. We present all figures with charts, so you can see straight away where improvement is needed.