// 03 · PHISHING SIMULATIONS
Phishing simulations
A phishing simulation is a controlled phishing attack on your own employees. Its purpose is to measure behavior and train the response, not to trap anyone. We prepare a scenario that fits your industry and your systems, send it in batches, and track how many people clicked, how many entered credentials, and how many reported the message to the help desk. We report in aggregate and follow up with training.
// 01
How we prepare and launch a campaign
First we agree on the rules: who approves the campaign, who knows about it (typically the managing director, IT, and HR), and which scenarios are acceptable. Payroll, layoffs, health data, and anything that humiliates a person are off-limits for us. A simulation is meant to teach people something, not to breed distrust between management and employees. For companies in the higher obligations regime under Act No. 264/2025 Coll., on Cybersecurity (the Czech Cybersecurity Act), a campaign also helps with a specific duty: Section 10(3)(d) of Decree No. 409/2025 Coll. requires regular training and verification of employees’ security awareness. The Decree doesn’t prescribe the form of verification; a simulation with follow-up training is one option.
Then we build the scenario. We register a domain similar to yours or the domain of a fictitious supplier, set up SPF, DKIM, and DMARC so the message gets delivered at all, and prepare a landing page that mimics the login screen of an application people use every day. Entered passwords are never stored. From the form we take only a flag that a submission happened.
We send in batches of a few dozen addresses over two to three days, not to everyone at once. Word of a mass send spreads across an open-plan office in five minutes, and all you measure is how fast people talk across the desk. In parallel we measure the opposite direction: how long after the first delivered message the first report reaches the help desk.
// 02
Which scenarios we use
We scale difficulty across three levels. The easiest scenario is a generic message with mistakes in the Czech text and a foreign domain, which shows the baseline. The middle level targets a specific system: a Microsoft 365 password expiry, a shared document, a new invoice in the ERP, that is, a pretext close to what business email compromise (BEC) and CEO fraud look like. The hardest is spear phishing aimed at a handful of people, built on a real project or supplier whose name we picked up from public sources. Our glossary breaks down what a believable pretext is made of and where those pieces come from.
Beyond a link in an email, we try techniques that bypass link checking entirely: a QR code in a PDF attachment, a request to approve an OAuth application in your company tenant, and login through a device code. What they have in common is that there is nothing to check in the message body, because the fraudulent step happens on the phone or on the login screen of the provider itself. A detailed breakdown of which techniques are currently getting past filters is on the blog.
On request we add vishing, a phone call from “IT support” that follows up on the delivered email. Scenarios inside the building, such as a dropped USB drive or a QR poster, are described separately, because they touch physical space and need additional approval from you.
// 03
What we measure and how we report the results
We measure five numbers: delivered, opened, clicked, credentials entered, and reported to the help desk. The last one matters most, together with the time to the first report. A click is human and happens everywhere, but a company where the first person reports a suspicious message within ten minutes can stop a campaign before it gets going.
The report goes to management in aggregate: numbers per company and per department, never a list of names of who clicked. We need the names only for the duration of the campaign, to target the follow-up training, and we delete them from the platform once the training has gone out. Get this framework approved internally in advance; it is the difference between a training tool and an HR problem.
The value is in repetition. The first campaign gives a baseline, the second, after training, shows the shift, and the third checks if the shift held. That is why we spread campaigns over the year roughly four months apart, and in each report we compare only with a campaign of the same difficulty. Comparing targeted spear phishing with a generic message makes no sense.
// 04
How we classify findings
| Severity | CVSS | Handling |
|---|---|---|
| Critical | 9.0 – 10.0 | Immediate escalation |
| High | 7.0 – 8.9 | Summary within 24 hours |
| Medium | 4.0 – 6.9 | Included in the final report |
| Low | 0.1 – 3.9 | Remediation recommendation |
// 05
Frequently asked questions
// INCLUDED WITH EVERY ENGAGEMENT
Free one-time data leak check
With every service we add a one-time leak check: we tell you whether your company email addresses and passwords sit in public leaks or on the dark web as of the day of the check. It is a snapshot of one day. If you want to know about a leak whenever one appears, you move to continuous monitoring.
How continuous leak monitoring works// NEXT STEP
We build the campaign around the way your people work.
We decide together who the campaign goes to and which scenarios fit your operations; management then gets the numbers in aggregate, with no lists of names. Fill in your email address and we’ll get back to you to talk it through.