Cybersecurity › Social Engineering
Social Engineering & Awareness

No burglar breaks in
if someone lets him in.

We test how your team responds to phishing, fake payment instructions, and phone calls under real-world conditions. Afterward, you’ll know exactly where you stand, rather than just guessing.

Real-World Scenarios · Analysis by Department

The Problem

Technology can be secured.
Trust cannot.

Professional attackers can bypass any firewall by making a phone call, sending a credible email, or posing as a technician. No software can protect against this.

62 %

The security incidents investigated all have a human element: errors, misuse of access, or deception.

Verizon Data Breach Investigations Report 2025

Theory doesn't protect you

A training session once a year imparts knowledge. However, anyone who has never experienced a real simulation will still fail to recognize a targeted attack on their own company.

No Improvement Without Measurement

How many people click, how many report it, which department is most affected: Without simulation, this remains unknown until a real attack provides the answer.

The call to
on Friday afternoon

Fake payment orders issued in the name of management arrive precisely when no one is available to question them. They don’t need a loophole in the system—just one in the process.

Simulations

Real-world methods,
controlled conditions.

Each scenario is tailored to your company: your industry, your internal processes, and current attacker tactics.

Phishing

Widespread email campaigns targeting login credentials.

Deliberate Deception

Personalized messages on behalf of management or a supplier.

Calls

Fake IT support or a technician who asks for access over the phone.

Text Messages and QR Codes

Text messages on cell phones and stickers with codes that lead to fake login pages.

Planning
  • Tailor Scenarios to Your Business
  • Define Target Audiences and Exceptions
  • Develop a pretext and a plan of action
Implementation
  • Campaign with no advance notice
  • Track Clicks and Keypresses
  • Measuring Reporting Behavior and Response Time
Analysis
  • Executive Summary
  • Recommendations Organized by Urgency
  • Key Metrics on Click and Registration Behavior
How to Recognize Them

Three characteristics—
—that are almost always present.

A typical phishing message, like the ones sent out every day. The key parts are highlighted.

From: it-support@ihr-unternehmen-helpdesk.com
To: m.wagner@ihr-unternehmen.at
Subject: Urgent: Your password will expire in 24 hours
Immediate Action Required: Verify Your Account

Dear Ms. Wagner,

Our system has detected that your business account will be suspended in 24 hours unless you verify your login credentials immediately.

Please verify your account using the following link:
your-company-portal.helpdesk-login.net/verify

Sincerely,
IT Support

Characteristic 1

The sender seems familiar

The address includes your company name but ends with a different domain. Many programs display only the display name, not the actual address.

Characteristic 2

Apparently, it's urgent

Time pressure is the most effective tool. When people act under pressure, they don't double-check their work. That is exactly the intention.

Characteristic 3

The link goes somewhere else

The beginning of the address looks familiar, but the end is what matters. That's where the real domain is, and it belongs to the attacker.

No one clicks out of stupidity.
It's because it looked plausible.

That's why we evaluate by department, not by individual. The goal is to improve, not to pin the blame on anyone.

Report and Training

First comes clarity—
—then improvement.

The simulation shows where the risk lies. The training addresses it. The documentation provides evidence of both to auditors.

Analysis and Report

Executive summary, detailed section on the campaign, click-through rates by department, and recommendations categorized into three levels of urgency.

Report

Discussion of the Results

We present the figures in our own words: where the risks lie, which groups are affected, and what this means. Without using technical jargon.

Presentation

Training for the affected groups

The training is based on actual results. Participants see how their own department performed and learn the key characteristics and the appropriate course of action.

Workshop

Certificate of Participation and Proof of Attendance

All participants will receive a confirmation. The date, participants, content, and results will be documented in accordance with NIS2 and can be used as proof of compliance.

NIS2 Certification

Second Simulation

Upon request, we'll run another analysis after the training session. You'll see in black and white how the click-through rate and sign-up rate have changed.

optional
Why ITanic

A simulation is only as good
as its credibility.

Everyone can spot a cookie-cutter script. What matters is a scenario that your people believe is real.

Without prior notice

The campaign is being conducted without prior announcement. This is the only way to obtain actual figures rather than estimates from a pre-selected group.

Your Company, Your Scenarios

The company name, industry, typical internal processes, and current procedures are all incorporated. It feels authentic because it’s built from the ground up.

Measurable before and after training

Click-through rate, response rate, and affected groups are documented. You can see what has improved, not just whether it has.

NIS2 Compliance and Data Protection

Complete documentation for the authorities; no evaluation of personal data without consultation with the Human Resources department; in compliance with Austrian labor law.

Frequently Asked Questions

What companies need to clarify beforehand.

Are employees informed in advance?

No, that would render the results useless. Management and the relevant contacts in Human Resources and IT will be involved from the outset, but the workforce will not.

Can individuals or departments be excluded?

Yes. We'll determine the scope and exceptions together in advance—for example, particularly sensitive roles or individuals on parental leave.

What happens if someone actually clicks on it?

The user is immediately redirected to a neutral page that explains what just happened and how the message could have been identified. No actual login credentials are stored. The goal is to educate, not to catch people.

Who sees the results?

The analysis is conducted at the department level, not as a list of individual people. We will determine in advance, together, who will receive the report.

Does the training meet the NIS2 requirements?

Yes. NIS2 requires affected companies to conduct regular awareness training and to document it. We provide simulations, training, and comprehensive documentation in a format that can be used as evidence of NIS2 compliance.

How many times should you repeat that?

At least once a year, but preferably two to three times. Attackers are constantly changing their methods, and the effectiveness of training noticeably declines after a few months.

Training lowers the rate. It doesn't bring it down to zero.

If someone does click on it, someone has to notice the resulting access.

View Detection & Response

Do you know how many people would click on
?

A simulation will show where the real risks lie in just a few weeks—without theory or estimates.

Free and with no obligationNIS2 documentation includedCoordinated with the HR department