Phishing simulation
Campaigns that mirror the lures in use right now, measured on what matters: who clicks, who enters credentials, and how quickly someone reports it.
Measure the response, not just the click
Phishing is consistently the most common type of attack reported by UK organisations in the governmen’s annual Cyber Security Breaches Survey. It is cheap for attackers, and it only has to work once.
Generic training teaches people to spot generic phishing. We build campaigns around the themes and techniques being used against organisations like yours, including multi-stage lures and attacks that capture session tokens to get past MFA, so the results reflect your real exposure.
What a campaign measures
Delivery
Whether lures reach inboxes past your email filtering, and which controls stopped the rest.
Clicks
Who engages with the lure, by department and role.
Credential entry
Who enters credentials on a lookalike sign-in page, including MFA codes.
Payloads
Optionally, whether an attachment or download would have run on your devices.
Reporting
How many people report the email, how quickly, and what your team does next.
Trends
How results change from one campaign to the next.
How the engagement runs
Plan
We agree themes, targets, frequency, and what people see if they click: a short learning page, or nothing, so the test stays covert.
Build
We register lookalike domains, build landing pages and write lures based on current campaigns.
Launch
Emails go out in waves so people do not warn each other, and the campaign runs for an agreed period.
Report
Results by department and role, the time from first click to first report, and recommendations.
What you get
- Campaign results by department, role and lure.
- Time to first report, and how your team handled it.
- Recommendations for email controls, reporting and training.
When to commission it
- Before and after awareness training, to measure its effect.
- When moving to a new email platform or changing filtering.
- On a regular cycle, such as quarterly, to build habits and track trends.
- When rolling out phishing-resistant MFA, to show why it matters.
Questions we get asked
How often should we run phishing simulations?
Should our email filter let the campaign through?
What happens when someone clicks?
Can you test whether attackers could get past our MFA?
Related
Social engineering
Social engineering assessments that test how your people and processes respond to phishing, phone pretexting, impersonation and physical intrusion.
Read more →Physical intrusion
Physical penetration testing: tailgating, badge cloning, reception pretexts and access to server rooms. Could someone walk in and leave with your data?
Read more →Tabletop exercises
Realistic cyber incident tabletop exercises for leadership and technical teams. Rehearse your incident response plan before you need it.
Read more →SavountCyber Breach Survey Insight: The Need to Know for UK Businesses and Charities
Key findings from the UK Cyber Security Breaches Survey 2024: what breaches cost, why phishing leads, and where boards stand on cyber risk.
Read the article →