We approach your employees the way real attackers do: by email, on the phone, with prepared storage devices and at the door.
The mail got past the filter and gateway.
The mailbox loaded it.
Someone opened the link.
Credentials were typed into the login form.
The attempt went to IT. This rate should rise.
Every stage is recorded technically and evaluated by department or site, not by person.
Texts, domains and senders that match your language and your tool stack.
Calls posing as support, a service provider or the boss. With a record of what was given away.
Prepared sticks are placed and tracked technically.
Electrician, cleaner, utility company, job applicant, delivery service. Roles that hardly anyone questions in everyday life.
Evaluation per vector: phishing, vishing, baiting, physical access on site
Risk rating and prioritisation of the findings
Immediate measures such as a report button in the mail client, plus longer-term steps
Evidence for audits and management reviews, for example ISO 27001, NIS2 or TISAX
We deliver the test and the technical evidence. Legal advice, certification and reports to authorities are not part of it.
Objectives, vectors, time frame and boundaries. HR and the works council are at the table.
Scenarios, domains and senders are tailored to your organisation, tracking and landing pages are set up.
The campaign runs and events are recorded. One contact person on your side knows about it and can stop it at any time.
Rates per stage and area, findings, recommendations, comparison with the last round.
A session with management and, if you wish, with the teams that were tested.
Once a year an in-depth test with several vectors, with smaller phishing simulations in between. The reporting rate over several rounds shows whether your measures are working. A single campaign remains a snapshot.
A phone call gathers information, an email tailored to that information then makes use of it, and at the same time someone wearing a hi-vis vest is standing at the door. This combination reveals the transitions between people, technology and the building. For example, whether the same employee who trusts the technician on the phone will later also unlock the server room for him.
Texts, domains and hooks are modelled on real campaigns, not on demo spam.
Click, entry, reporting and forwarding rates, anonymised and still meaningful to evaluate.
We work on structures, not against people. Nobody is singled out in public.
Reports that can be used in audits, management reviews and for regulatory purposes.
The link leads to a page that we operate ourselves. It only counts what happened and does not pass anything on to anyone.
The test looks for gaps in processes, not for someone to blame. The results go to management in aggregated form. Anyone who falls for it during the test learns in an environment with no data loss and no extortion.
Then what you are missing is the number, not the problem. Only the click rate, the entry rate and the reporting rate show whether you need better filters, a training course or a clearer process for urgent requests.
Voice phishing, in other words an attack carried out over the telephone. It is harder to contradict a friendly voice than an email, and cloned voices generated with AI tools lower the barrier even further.
No. That is the point where a campaign tips over. You get rates per department or site, and with them the information on where you need to start.
Then the test has served its purpose, and the gap has been found before somebody else exploits it. In most cases the processes do not fit everyday working life. That is exactly what we then continue working on together with you.
Anyone who reports gets brief feedback from IT that reporting was the right call. That is the cheapest lever there is: reporting has to pay off, otherwise people stop doing it.
In a free initial call we clarify vectors, scope and boundaries. After that you receive a written offer.