Hacking people, not systems

We approach your employees the way real attackers do: by email, on the phone, with prepared storage devices and at the door.

  • Results without real names
  • Scope agreed with HR and works council
  • Report usable for audits

What makes a campaign measurable

A diagram, not measured values. The rates come from your campaign.
  1. Delivered

    The mail got past the filter and gateway.

  2. Opened

    The mailbox loaded it.

  3. Clicked

    Someone opened the link.

  4. Entered

    Credentials were typed into the login form.

  5. Reported

    The attempt went to IT. This rate should rise.

Every stage is recorded technically and evaluated by department or site, not by person.

Four ways into the same organisation

Email

Spear Phishing

Texts, domains and senders that match your language and your tool stack.

Phone

Vishing

Calls posing as support, a service provider or the boss. With a record of what was given away.

Storage devices

USB drops and baiting

Prepared sticks are placed and tracked technically.

On site

Personas at the door

Electrician, cleaner, utility company, job applicant, delivery service. Roles that hardly anyone questions in everyday life.

What the report contains

  • Evaluation per vector: phishing, vishing, baiting, physical access on site

  • Risk rating and prioritisation of the findings

  • Immediate measures such as a report button in the mail client, plus longer-term steps

  • Evidence for audits and management reviews, for example ISO 27001, NIS2 or TISAX

We deliver the test and the technical evidence. Legal advice, certification and reports to authorities are not part of it.

How a campaign runs

  1. 1

    Scoping

    Objectives, vectors, time frame and boundaries. HR and the works council are at the table.

  2. 2

    Pretext and set-up

    Scenarios, domains and senders are tailored to your organisation, tracking and landing pages are set up.

  3. 3

    Execution

    The campaign runs and events are recorded. One contact person on your side knows about it and can stop it at any time.

  4. 4

    Evaluation

    Rates per stage and area, findings, recommendations, comparison with the last round.

  5. 5

    Debriefing

    A session with management and, if you wish, with the teams that were tested.

How often

Once a year an in-depth test with several vectors, with smaller phishing simulations in between. The reporting rate over several rounds shows whether your measures are working. A single campaign remains a snapshot.

The full chain

A phone call gathers information, an email tailored to that information then makes use of it, and at the same time someone wearing a hi-vis vest is standing at the door. This combination reveals the transitions between people, technology and the building. For example, whether the same employee who trusts the technician on the phone will later also unlock the server room for him.

Why this is tested

Realistic attacks

Texts, domains and hooks are modelled on real campaigns, not on demo spam.

Measurable awareness

Click, entry, reporting and forwarding rates, anonymised and still meaningful to evaluate.

Focus on culture

We work on structures, not against people. Nobody is singled out in public.

Evidence for audits

Reports that can be used in audits, management reviews and for regulatory purposes.

What a simulation email looks like

Example
SubjectAction required: an update to your VPN access rights
MessageGood day, we have registered unusual login attempts on your company account. Please confirm your access using the following link in order to avoid your account being locked.
Confirm access now

The link leads to a page that we operate ourselves. It only counts what happened and does not pass anything on to anyone.

Frequently asked questions

Does this harm the working atmosphere?

The test looks for gaps in processes, not for someone to blame. The results go to management in aggregated form. Anyone who falls for it during the test learns in an environment with no data loss and no extortion.

Our people click on everything anyway.

Then what you are missing is the number, not the problem. Only the click rate, the entry rate and the reporting rate show whether you need better filters, a training course or a clearer process for urgent requests.

What exactly is vishing?

Voice phishing, in other words an attack carried out over the telephone. It is harder to contradict a friendly voice than an email, and cloned voices generated with AI tools lower the barrier even further.

Do we get the click figures of individual employees?

No. That is the point where a campaign tips over. You get rates per department or site, and with them the information on where you need to start.

What if the result is bad?

Then the test has served its purpose, and the gap has been found before somebody else exploits it. In most cases the processes do not fit everyday working life. That is exactly what we then continue working on together with you.

How do you handle reported attempts?

Anyone who reports gets brief feedback from IT that reporting was the right call. That is the cheapest lever there is: reporting has to pay off, otherwise people stop doing it.

How far would someone get in your company?

In a free initial call we clarify vectors, scope and boundaries. After that you receive a written offer.