APOLLOSEC

Phishing simulation

Campaigns that mirror the lures in use right now, measured on what matters: who clicks, who enters credentials, and how quickly someone reports it.

Measure the response, not just the click

Phishing is consistently the most common type of attack reported by UK organisations in the governmen’s annual Cyber Security Breaches Survey. It is cheap for attackers, and it only has to work once.

Generic training teaches people to spot generic phishing. We build campaigns around the themes and techniques being used against organisations like yours, including multi-stage lures and attacks that capture session tokens to get past MFA, so the results reflect your real exposure.

What a campaign measures

  • Delivery

    Whether lures reach inboxes past your email filtering, and which controls stopped the rest.

  • Clicks

    Who engages with the lure, by department and role.

  • Credential entry

    Who enters credentials on a lookalike sign-in page, including MFA codes.

  • Payloads

    Optionally, whether an attachment or download would have run on your devices.

  • Reporting

    How many people report the email, how quickly, and what your team does next.

  • Trends

    How results change from one campaign to the next.

How the engagement runs

  1. Plan

    We agree themes, targets, frequency, and what people see if they click: a short learning page, or nothing, so the test stays covert.

  2. Build

    We register lookalike domains, build landing pages and write lures based on current campaigns.

  3. Launch

    Emails go out in waves so people do not warn each other, and the campaign runs for an agreed period.

  4. Report

    Results by department and role, the time from first click to first report, and recommendations.

What you get

  • Campaign results by department, role and lure.
  • Time to first report, and how your team handled it.
  • Recommendations for email controls, reporting and training.

When to commission it

  • Before and after awareness training, to measure its effect.
  • When moving to a new email platform or changing filtering.
  • On a regular cycle, such as quarterly, to build habits and track trends.
  • When rolling out phishing-resistant MFA, to show why it matters.

Questions we get asked

How often should we run phishing simulations?

Quarterly is a common rhythm: often enough to build habits and show trends, without people becoming suspicious of every email. Vary the themes so you measure judgement, not memory of the last test.

Should our email filter let the campaign through?

We can test both ways. Without allow-listing, you learn whether filtering stops the lure. With allow-listing, you measure people on their own. Many clients do one of each.

What happens when someone clicks?

Your choice. They can see a short page explaining the warning signs they missed, or nothing at all if you want the campaign to stay covert while you measure reporting.

Can you test whether attackers could get past our MFA?

Yes. Adversary-in-the-middle phishing, which captures session tokens to get past most MFA, is now common. We can include it to show whether conditional access and phishing-resistant MFA would stop it.

Measure how your people respond to a real lure.

Talk to us