We test how your team responds to phishing, fake payment instructions, and phone calls under real-world conditions. Afterward, you’ll know exactly where you stand, rather than just guessing.
Real-World Scenarios · Analysis by Department
Professional attackers can bypass any firewall by making a phone call, sending a credible email, or posing as a technician. No software can protect against this.
The security incidents investigated all have a human element: errors, misuse of access, or deception.
Verizon Data Breach Investigations Report 2025
A training session once a year imparts knowledge. However, anyone who has never experienced a real simulation will still fail to recognize a targeted attack on their own company.
How many people click, how many report it, which department is most affected: Without simulation, this remains unknown until a real attack provides the answer.
Fake payment orders issued in the name of management arrive precisely when no one is available to question them. They don’t need a loophole in the system—just one in the process.
Each scenario is tailored to your company: your industry, your internal processes, and current attacker tactics.
Widespread email campaigns targeting login credentials.
Personalized messages on behalf of management or a supplier.
Fake IT support or a technician who asks for access over the phone.
Text messages on cell phones and stickers with codes that lead to fake login pages.
A typical phishing message, like the ones sent out every day. The key parts are highlighted.
Dear Ms. Wagner,
Our system has detected that your business account will be suspended in 24 hours unless you verify your login credentials immediately.
Please verify your account using the following link:
your-company-portal.helpdesk-login.net/verify
Sincerely,
IT Support
The address includes your company name but ends with a different domain. Many programs display only the display name, not the actual address.
Time pressure is the most effective tool. When people act under pressure, they don't double-check their work. That is exactly the intention.
The beginning of the address looks familiar, but the end is what matters. That's where the real domain is, and it belongs to the attacker.
No one clicks out of stupidity.
It's because it looked plausible.
That's why we evaluate by department, not by individual. The goal is to improve, not to pin the blame on anyone.
The simulation shows where the risk lies. The training addresses it. The documentation provides evidence of both to auditors.
Executive summary, detailed section on the campaign, click-through rates by department, and recommendations categorized into three levels of urgency.
We present the figures in our own words: where the risks lie, which groups are affected, and what this means. Without using technical jargon.
The training is based on actual results. Participants see how their own department performed and learn the key characteristics and the appropriate course of action.
All participants will receive a confirmation. The date, participants, content, and results will be documented in accordance with NIS2 and can be used as proof of compliance.
Upon request, we'll run another analysis after the training session. You'll see in black and white how the click-through rate and sign-up rate have changed.
Everyone can spot a cookie-cutter script. What matters is a scenario that your people believe is real.
The campaign is being conducted without prior announcement. This is the only way to obtain actual figures rather than estimates from a pre-selected group.
The company name, industry, typical internal processes, and current procedures are all incorporated. It feels authentic because it’s built from the ground up.
Click-through rate, response rate, and affected groups are documented. You can see what has improved, not just whether it has.
Complete documentation for the authorities; no evaluation of personal data without consultation with the Human Resources department; in compliance with Austrian labor law.
No, that would render the results useless. Management and the relevant contacts in Human Resources and IT will be involved from the outset, but the workforce will not.
Yes. We'll determine the scope and exceptions together in advance—for example, particularly sensitive roles or individuals on parental leave.
The user is immediately redirected to a neutral page that explains what just happened and how the message could have been identified. No actual login credentials are stored. The goal is to educate, not to catch people.
The analysis is conducted at the department level, not as a list of individual people. We will determine in advance, together, who will receive the report.
Yes. NIS2 requires affected companies to conduct regular awareness training and to document it. We provide simulations, training, and comprehensive documentation in a format that can be used as evidence of NIS2 compliance.
At least once a year, but preferably two to three times. Attackers are constantly changing their methods, and the effectiveness of training noticeably declines after a few months.
If someone does click on it, someone has to notice the resulting access.
A simulation will show where the real risks lie in just a few weeks—without theory or estimates.
We use cookies to operate this website and analyze its usage. You decide which categories to allow. You can adjust your settings at any time.