When is it worth taking the test?
Problems we help solve
Phishing often looks like an ordinary message with an invoice, document, login link or request from a superior. The test checks whether employees recognise the risk and know where to report suspicious messages.
- Employees receive more and more fake invoices and login links.
- The company doesn't know if the team can report suspicious messages.
- After the training, there is no practical verification of behaviour.
- Accounting, sales or customer service departments are particularly vulnerable.
- The organisation wants to improve procedures without waiting for a real incident.
Fit
Who is this service for?
Companies after training
We check whether the knowledge has translated into real user behaviour.
Companies after the incident
We help determine which scenarios require additional education and procedures.
High-risk teams
We test departments working with payments, documents and customer data.
Companies before the audit
We provide a report and recommendations showing a practical approach to user awareness.
Service scope
What does a phishing test involve?
Scenario
We select the content of the test to suit the company's profile and risk.
- false invoices or documents,
- login links,
- messages from a supplier or manager.
Implementation
We conduct a controlled campaign without disturbing the company's work.
- selected group of recipients,
- secure test site,
- measurement of clicks and reports.
Report
We show the results in a form useful for further actions.
- user reactions,
- reporting time,
- areas requiring improvement.
Post-test activities
We help turn the result into better procedures and communication.
- training recommendations,
- rules for reporting messages,
- email protection fixes.
Outcomes
What will you receive?
- a practical picture of the team's reaction to suspicious messages,
- report with campaign results and recommendations,
- identification of groups requiring additional support,
- material for improving phishing reporting procedures,
- proposals for technical changes in email protection.
We treat the test as a tool to improve security, not as a hunt for employee errors.
Delivery approach
How is the service delivered?
- Purpose. We establish a group, a scenario and communication rules.
- Preparation. We create a message, a test page and a measurement method.
- Campaign. We send the simulation on the agreed date.
- Measurement. We analyse clicks, entries and news reports.
- Report. We provide the results and conclusions for the company.
- Improvement. We recommend training, procedures and email settings.
Delivery standards
How do we conduct tests?
- We establish the rules of the test with decision-makers before starting.
- We do not collect actual passwords or sensitive data.
- We adjust the difficulty of the scenario to the maturity of the organisation.
- We present the results in a way that supports improvement, not to find fault.
- We combine the test with technical and educational recommendations.
Cost
What determines the price?
The price depends on the number of users, the number of scenarios, the scope of reporting, the need for post-test training and the level of adaptation of the campaign to the industry and company processes.
FAQ
Frequently asked questions
Is the test safe for employees?
Yes. We do not collect real passwords, and the scenario is intended to check behaviour and procedures.
Should employees know about the test?
It depends on the goal. You can announce an awareness program without specifying a campaign date.
Will we get a list of people who clicked?
We determine the scope of reporting in advance. We recommend an approach focused on improving the process, not stigmatising people.
Can the test be combined with training?
Yes. This is often the best model because the test result shows which topics need to be clarified.
Will the test help improve email security?
Yes. The results also often indicate the need for changes to filters, MFA, DMARC and the reporting procedure.