Scope and rules
Goal, group, timing, and what is in-scope and out-of-scope.
Related: Phishing tests and Security awareness training.
Controlled phishing simulations for teams. We measure clicks, reporting, response time, and follow-up - not just a number.
Blind spot: optimizing for a low click rate alone can reduce reporting. Reporting and follow-up is the real win.
High level only, no abuse instructions.
Measure clicks, reporting, and time to report, per scenario and target group.
Mobile-focused scenarios, measuring escalation and reporting behavior.
Test verification steps and how people handle phone-based requests.
Where does a report land, who owns follow-up, how fast does the loop close.
Results in plain English, plus concrete improvements for people, process, and settings.
Training topics based on what actually went wrong in your test results.
Blind spot: if you only chase a lower click rate, you can train people to stay quiet. Reporting and follow-up is the goal.
Goal, group, timing, and what is in-scope and out-of-scope.
Realistic, safe scenarios aligned to your environment.
Controlled execution, monitoring, and measurement.
Clear results and practical changes you can implement.
Answers to the questions we get most.
No. We do not collect credentials. The goal is behavior and reporting, not tricking people into handing over secrets.
Yes. Scope and rules are agreed upfront. No malware, no harmful attachments, no panic content.
No. Results are used to improve habits and process. We focus on what to change, not who to shame.
Usually a short intake, then scenario setup, then the run. Timing depends on scope and number of groups.
Yes. We can measure if reports land in the right place, and whether follow-up happens.
A sensible start is quarterly, plus after major changes like new joiners, new tooling, or new processes.
Training is built on the results of the simulations. Short sessions, practical steps, focused on reporting and follow-up.
Contact: [email protected] | +31 6 2797 8381.