Home/Services/Phishing Simulation Services
security service

Phishing Simulation Services

Phishing simulation services that measure how your staff really react. Spear-phishing, vishing and awareness training, fixed price with a full report.

Manual, expert-ledEvidence-based findingsFree remediation retest

Phishing simulation services show you what your people actually do when a convincing lure lands in their inbox, not what a policy document says they should do. We run controlled, consent-backed campaigns across Europe that mirror the way real attackers work, then turn the results into training that changes behavior.

What phishing simulation services actually cover

Most breaches we help clean up did not start with a clever exploit. They started with one employee clicking a link and typing a password into a page that looked like the company portal. A phishing simulation puts that exact moment under a microscope, safely, so you learn where the risk sits before a criminal does. We build the campaign around your real environment: your brand, your suppliers, the tools your staff use every day.

Coverage is broader than a single fake email blast. We combine email lures with optional voice and SMS pretexts, credential-capture pages that record submission rates without ever storing the actual passwords, and a debrief that ranks departments and roles by risk. The aim is a defensible measurement of human risk, not a gotcha exercise that leaves staff resentful.

Targeted spear-phishing using pretexts built from public OSINT about your company
Credential-harvesting landing pages that count submissions but never keep the password
MFA-fatigue and consent-phishing scenarios against Microsoft 365 and Google Workspace
Optional vishing and smishing to test phone and text-based social engineering
Per-department click, report and credential-submission metrics you can track over time
Just-in-time awareness training triggered the moment someone clicks

How we run a phishing campaign

A simulation is only useful if it is realistic and controlled at the same time. Our phishing simulation and awareness services follow a repeatable process so the numbers you get are honest and comparable from one round to the next.

Scoping and authorization

We start with a short call to agree the target population, the pretexts that are fair game, and the off-limits topics. Some subjects, like bogus redundancy notices or fake medical alerts, cause real distress and we steer clients away from them. A named sponsor inside your business signs off the rules of engagement, and we work under NDA throughout.

Pretext design and OSINT

Attackers research before they send. So do we. We gather public information about your organization: supplier names, the format of your email addresses, recent press, job titles on LinkedIn. From that we craft lures that feel native. A finance team might see an invoice query from a genuine-looking vendor. IT might get a fake ticket from the helpdesk platform they actually use.

Infrastructure and delivery

We stand up dedicated sending infrastructure on GoPhish-style tooling with freshly registered look-alike domains, valid TLS certificates and warmed sender reputation, so the mail behaves like a real campaign rather than something your gateway trivially bins. Where you want to test detection, we can also send from domains your filters have never seen. Every message is tagged so we can trace exactly who received, opened, clicked and submitted.

Tracking, live response and debrief

During the window we watch the metrics in real time. If a genuine incident looks like it is brewing, we tell your security contact at once so nobody wastes an afternoon chasing our test. Afterward you get the full picture: open rates, click rates, credential-submission rates, the median time to click, and, just as important, how many people reported the mail to your abuse mailbox.

48h
from launch to first live metrics
0
real passwords ever stored on capture pages
Free
re-run to prove awareness training worked

The social-engineering techniques we test

Real intrusions rarely rely on one trick. We model the techniques that map to MITRE ATT&CK Initial Access T1566, so the exercise reflects what your staff will genuinely face.

Spear-phishing and pretexting

Broad, generic phishing catches the careless. Targeted spear-phishing catches almost everyone the first time, because it references real people, real projects and real deadlines. We test both, so you can see the gap between baseline awareness and resistance to a tailored attack.

Credential harvesting and MFA fatigue

Stealing a password is only step one now that most companies run multi-factor authentication. We test the follow-through: consent-phishing that tricks a user into approving a malicious OAuth app, and MFA-fatigue pushes that bombard someone with prompts until they tap approve to make it stop. These are the exact paths behind several large European incidents in recent years.

Vishing and smishing

Not every attack arrives by email. A phone call from the “IT helpdesk” asking someone to read out a code, or a text message about a stuck parcel, can be more effective than any inbox lure. Where scope allows, we add scripted voice and SMS pretexts so you understand exposure across every channel your people use.

Get a fixed quote

Want this tested on your own systems?

Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.

Get a fixed quote

What you get

The report is written for two audiences at once. Leadership gets a clear read on human risk and how it trends. Your security and HR teams get the operational detail they need to act.

Metrics that mean something

We report the numbers that predict real-world compromise: click rate, credential-submission rate, and the report rate that tells you how many people did the right thing. We break these down by department and seniority, because the pattern in a finance team differs from the pattern in engineering, and your training budget should follow the risk.

Awareness training that lands in the moment

People remember a lesson best right after they make the mistake. Anyone who clicks is shown a short, non-shaming teachable page that explains the specific cues they missed. We can pair this with role-based training modules and a recommended cadence, so the simulation becomes a program rather than a one-off scare.

A retest to prove it worked

A single campaign is a snapshot. Improvement is a trend. Every engagement includes a follow-up round after your training, at no extra cost, so you can show the board that click rates fell and reporting rose.

Where phishing simulation fits your compliance

Security-awareness testing is written into most frameworks a European business has to satisfy, and our reporting is built to slot straight into an audit.

ISO 27001, PCI DSS and beyond

ISO 27001:2022 control A.6.3 requires information-security awareness, education and training, and auditors increasingly want evidence that the training is measured, not just delivered. PCI DSS 4.0 requirement 12.6 mandates a formal security-awareness program with periodic testing. A documented phishing simulation gives you that evidence in a form an assessor recognizes.

GDPR, NIS2 and DORA

Under the GDPR, article 32 expects appropriate organizational measures to protect personal data, and staff susceptibility to phishing is squarely an organizational risk. For operators in scope of NIS2, human-risk testing supports the required cyber-hygiene and training measures. Financial entities under DORA can fold awareness metrics into their ICT risk-management reporting. We map findings to the framework you name so the report earns its keep at audit time.

Why a live simulation beats a checkbox

Plenty of platforms will spray a template at your staff and hand you a percentage. That is better than nothing, but it rarely reflects a real attacker, and staff learn to spot the same tired template within a month. Our value is the human craft in the pretext and the analysis behind the numbers. A tailored campaign designed by an offensive engineer who has actually broken into companies produces results you can trust, and advice you can act on. The dashboard tells you what happened. We tell you why, and what to change.

When to run a simulation, and how often

A single test tells you where you stand today. A program tells you whether your people are getting harder to fool, which is the number that actually protects you.

Baseline, then repeat

We recommend an initial baseline campaign to establish honest starting figures, followed by quarterly rounds with fresh pretexts. Attackers rotate their lures constantly, and staff quickly learn to spot a template they have seen before, so repeating the same email teaches nothing. Rotating themes keeps the exercise honest and the training relevant.

Tie it to real events

The best moments to run a simulation are after onboarding a group of new hires, following a policy change, or in the run-up to an audit that expects awareness evidence. A campaign timed to a merger or a major product launch also reflects when attackers are most likely to strike, because those are the moments your staff are busiest and least suspicious.

Report the trend to leadership

Boards respond to direction of travel, not a single percentage. We present click and report rates as a trend across rounds, so you can show that investment in awareness is paying off and pinpoint the teams that still need attention. That trend line is often what unlocks continued budget for security training.

Pricing

Pricing scales with headcount and how many channels you want to test. A single email campaign against a small team costs far less than a multi-vector program across a large European workforce with vishing and bespoke pretexts.

Engagement What’s included Timeline Price
Baseline campaign Single email pretext to up to 100 staff, click and report metrics, teachable landing page, summary report 1–2 weeks from €1,500
Standard program Two to three tailored pretexts, credential-capture tracking, per-department breakdown, awareness training modules, exec + technical report 2–4 weeks €2,500–€5,000
Multi-vector Email plus vishing or smishing, MFA-fatigue and consent-phishing scenarios against your identity provider, deep debrief 3–5 weeks €5,000–€12,000
Ongoing awareness Quarterly simulations with trend reporting and refreshed pretexts, run as a managed program across the year quarterly from €4,000/yr
Custom / large estate Thousands of users, multiple languages and countries, blended with a wider red-team objective on scoping custom

Every engagement is fixed-price, quoted after a free 20-minute scoping call, and a follow-up retest is included. Get a fixed quote

FAQ

How much do phishing simulation services cost?
Campaigns start from €1,500 and the price scales with your headcount and the number of channels you want to test. You get a fixed quote after a free scoping call, so there are no hourly surprises.
Will you store our employees’ passwords?
No. Our credential-harvesting pages record that a submission happened and time it, but the actual password is discarded on the spot and never written to disk. You get the metric without ever holding the secret.
How do you keep the exercise fair to staff?
We agree off-limits themes up front and avoid distressing pretexts like fake redundancies. Anyone who clicks sees a short, non-shaming lesson rather than a public naming, because we are testing the system, not punishing people.
Does this satisfy ISO 27001 or PCI DSS awareness requirements?
Yes. The report is written to evidence ISO 27001:2022 A.6.3 awareness training and PCI DSS 4.0 requirement 12.6, and we map results to NIS2, DORA or GDPR when you need them. Tell us your framework and we align the deliverables.
Can you test phone and text attacks as well as email?
Yes. We add scripted vishing calls and smishing texts where scope allows, so you see susceptibility across every channel rather than just the inbox. These vectors often catch people that email filters would have stopped.
What do we get after the campaign?
An executive summary showing human risk and trend, a technical breakdown of click, submission and report rates by department, teachable content for the people who clicked, and a prioritized set of next steps. A free follow-up round proves the training worked.
How long does a phishing simulation take?
A baseline email campaign runs over one to two weeks including the reporting window, while a multi-vector program with vishing and tailored pretexts takes three to five weeks. Live metrics start flowing within 48 hours of launch.
Are you one of the phishing simulation companies that also trains our staff?
Yes. We pair the test with just-in-time teachable pages and role-based training modules, and we can run the whole thing as an ongoing quarterly program so awareness keeps improving rather than fading.

Related services

Who needs this

Any European business whose staff handle email, money or customer data and wants a defensible measure of human risk. It suits companies preparing for ISO 27001 or PCI DSS, security leads building an awareness program, and anyone who has already had a near-miss and wants to know how exposed they really are.

why safetybis

Security you can prove

The same standard on every engagement, big or small.

Evidence, not opinions

Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".

Humans over scanners

Certified engineers find the logic flaws and chained attacks automated tools walk straight past.

Fixed price, free retest

You know the cost up front, and verifying the fix is part of the deal — not a second invoice.

500+
assessments delivered
<30min
incident first response
12k+
infections removed
98%
fixed within one retest
$ safetybis quote --service "Phishing Simulation Services"

Ready to lock this down?

Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.

get in touch

Tell us what you're running

Scoping is free. We reply within one business day, and under 30 minutes for active incidents.