KS-CYBER_

Phishing simulations

Phishing simulations that end in training, not a list of culprits

A controlled phishing campaign built on realistic scenarios. We measure opens, clicks, credentials entered and reports to the SOC — and the people who fell for it are assigned training immediately, not next quarter.

How a campaign runs

Stage 1

Scenario

We match the pretext to the company's reality: an invoice, a courier, HR, a note from the board.

Stage 2

Delivery

The campaign is sent from our own infrastructure, with SPF/DKIM/DMARC authentication and controlled send rate.

Stage 3

Measurement

Who opened, who clicked, who entered credentials, who reported the incident — broken down by department.

Stage 4

Remediation

Anyone who clicks lands on a teaching page and is assigned the matching training module.

What we measure and why it matters

  • Click rate — the basic measure of exposure, comparable between campaigns.
  • Credentials entered — the most dangerous behaviour; passwords are never stored in a form useful to anyone.
  • Reports to the SOC — a measure of maturity. A company where people report finds out about an attack in minutes; one where nobody reports finds out from a report weeks later.
  • Breakdown by department — shows where to direct training instead of training everyone identically.

Not only email — the USB Drop simulation

A dropped drive is still a working vector, because it bypasses the entire layer of mail filtering. In a USB Drop campaign we leave drives in agreed locations carrying a file that looks like an ordinary document — a spreadsheet, a contract, a payroll list. We measure how many people plugged it in and opened it, anonymously or with attribution, depending on what we agree before the start.

The file does nothing beyond reporting that it was opened — no executable code, no access to the workstation.

Lines we do not cross

  • No traps on people's dignity — no scenarios involving bonuses, redundancies or medical results.
  • Aggregate results — the report is for planning training, not for disciplining individuals.
  • Notice in the policy — employees know the company runs simulations; they only do not know when.
  • Short retention — individual data is deleted once the remediation cycle closes.

More on GDPR compliance for simulations →

How to read the results so they mean something

A click percentage on its own says little. Only four indicators read together show whether the organisation defends itself or merely looks safe.

IndicatorWhat it really measuresWhat to watch for
OpensCampaign reach and whether the message got through the filters Inflated by security scanners that open mail automatically
ClicksBasic exposure — how many employees fell for the pretext Only comparable between campaigns of similar scenario difficulty
Credentials enteredThe most dangerous behaviour — real credential compromise Always at most as high as clicks — but it decides the scale of the incident
Reports to the SOCOrganisational maturity — whether anyone reacts at all The most important indicator, and the one most often ignored
Counter-intuitive, but true. A company where 15% clicked but 40% reported the incident defends itself better than one where 5% clicked and nobody reported. In the first, the security team learns about the attack within minutes. In the second — from the logs, weeks later.

How often to run simulations

Too rare

Once a year

It builds no reflex. People remember the training for a few weeks, then return to old habits — and staff turnover means part of the team has never been tested at all.

Optimal

Every quarter

A quarterly cycle sustains alertness and produces data comparable over time. Rare enough not to tire the team, frequent enough to catch new joiners.

Too often

Every month

It breeds fatigue and cynicism. People start reporting everything indiscriminately or ignoring the subject, and the programme loses credibility inside the organisation.

What separates a good simulation from a bad one

  • A realistic pretext — based on what actually lands in inboxes: an invoice, a courier, a request from HR. Not a Nigerian prince.
  • Fitted to the company — one scenario for finance, another for sales. A single message for everyone measures chance, not exposure.
  • Learning on the spot — whoever clicks immediately sees how the attack could have been spotted. The moment of the click is the only moment with full attention.
  • A measurable cycle — a result comparable with the previous campaign, otherwise nobody knows whether the programme changes anything.

The most common first-campaign mistakes

  • Punishment instead of teaching — a public list of who clicked kills reporting for years. People stop admitting mistakes.
  • Too hard a scenario to open with — a 60% click rate in the first campaign gives you no knowledge, only a panicking board.
  • No notice in the policy — employees find out the company tests them only after the fact. That is both a legal and a reputational problem.
  • A campaign without remediation — measurement alone changes nothing. A test with no training after it is a wasted budget.

The questions we get most often

Is phishing simulation lawful towards employees?

Yes. The basis is the controller's legitimate interest (Art. 6(1)(f) GDPR) — protecting the company's systems and data. It requires notice in the security policy that simulations are run, and results analysed in aggregate. We cover the detail in a separate article.

Do employees have to know a simulation is coming?

They have to know the company runs such tests — they do not have to know when or in what form. The standard is a clause in the security policy or work rules plus an announcement when the programme starts.

What happens to a password if somebody types it in?

We record only the fact that credentials were submitted — which is what the training assignment needs. We do not build a collection of employee passwords, because it is unnecessary for the educational purpose and would be a serious risk in itself.

How long does preparing and running a campaign take?

A campaign on a ready-made scenario launches within minutes from the platform. A campaign prepared for a specific organisation — with its own pretext and domain — usually needs a few days for agreement and delivery configuration.

Can this be done without involving the client's IT team?

In the basic version, yes — delivery comes from our infrastructure. For larger organisations it is still worth allow-listing our addresses, so that the test measures people's alertness rather than the effectiveness of the spam filter.

See your first report

Simulations are part of the platform — you can run one during the trial.