Phishing Simulation Services
Phishing simulation services that measure how your staff really react. Spear-phishing, vishing and awareness training, fixed price with a full report.
Phishing simulation services show you what your people actually do when a convincing lure lands in their inbox, not what a policy document says they should do. We run controlled, consent-backed campaigns across Europe that mirror the way real attackers work, then turn the results into training that changes behavior.
What phishing simulation services actually cover
Most breaches we help clean up did not start with a clever exploit. They started with one employee clicking a link and typing a password into a page that looked like the company portal. A phishing simulation puts that exact moment under a microscope, safely, so you learn where the risk sits before a criminal does. We build the campaign around your real environment: your brand, your suppliers, the tools your staff use every day.
Coverage is broader than a single fake email blast. We combine email lures with optional voice and SMS pretexts, credential-capture pages that record submission rates without ever storing the actual passwords, and a debrief that ranks departments and roles by risk. The aim is a defensible measurement of human risk, not a gotcha exercise that leaves staff resentful.
How we run a phishing campaign
A simulation is only useful if it is realistic and controlled at the same time. Our phishing simulation and awareness services follow a repeatable process so the numbers you get are honest and comparable from one round to the next.
Scoping and authorization
We start with a short call to agree the target population, the pretexts that are fair game, and the off-limits topics. Some subjects, like bogus redundancy notices or fake medical alerts, cause real distress and we steer clients away from them. A named sponsor inside your business signs off the rules of engagement, and we work under NDA throughout.
Pretext design and OSINT
Attackers research before they send. So do we. We gather public information about your organization: supplier names, the format of your email addresses, recent press, job titles on LinkedIn. From that we craft lures that feel native. A finance team might see an invoice query from a genuine-looking vendor. IT might get a fake ticket from the helpdesk platform they actually use.
Infrastructure and delivery
We stand up dedicated sending infrastructure on GoPhish-style tooling with freshly registered look-alike domains, valid TLS certificates and warmed sender reputation, so the mail behaves like a real campaign rather than something your gateway trivially bins. Where you want to test detection, we can also send from domains your filters have never seen. Every message is tagged so we can trace exactly who received, opened, clicked and submitted.
Tracking, live response and debrief
During the window we watch the metrics in real time. If a genuine incident looks like it is brewing, we tell your security contact at once so nobody wastes an afternoon chasing our test. Afterward you get the full picture: open rates, click rates, credential-submission rates, the median time to click, and, just as important, how many people reported the mail to your abuse mailbox.
The social-engineering techniques we test
Real intrusions rarely rely on one trick. We model the techniques that map to MITRE ATT&CK Initial Access T1566, so the exercise reflects what your staff will genuinely face.
Spear-phishing and pretexting
Broad, generic phishing catches the careless. Targeted spear-phishing catches almost everyone the first time, because it references real people, real projects and real deadlines. We test both, so you can see the gap between baseline awareness and resistance to a tailored attack.
Credential harvesting and MFA fatigue
Stealing a password is only step one now that most companies run multi-factor authentication. We test the follow-through: consent-phishing that tricks a user into approving a malicious OAuth app, and MFA-fatigue pushes that bombard someone with prompts until they tap approve to make it stop. These are the exact paths behind several large European incidents in recent years.
Vishing and smishing
Not every attack arrives by email. A phone call from the “IT helpdesk” asking someone to read out a code, or a text message about a stuck parcel, can be more effective than any inbox lure. Where scope allows, we add scripted voice and SMS pretexts so you understand exposure across every channel your people use.
Want this tested on your own systems?
Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.
What you get
The report is written for two audiences at once. Leadership gets a clear read on human risk and how it trends. Your security and HR teams get the operational detail they need to act.
Metrics that mean something
We report the numbers that predict real-world compromise: click rate, credential-submission rate, and the report rate that tells you how many people did the right thing. We break these down by department and seniority, because the pattern in a finance team differs from the pattern in engineering, and your training budget should follow the risk.
Awareness training that lands in the moment
People remember a lesson best right after they make the mistake. Anyone who clicks is shown a short, non-shaming teachable page that explains the specific cues they missed. We can pair this with role-based training modules and a recommended cadence, so the simulation becomes a program rather than a one-off scare.
A retest to prove it worked
A single campaign is a snapshot. Improvement is a trend. Every engagement includes a follow-up round after your training, at no extra cost, so you can show the board that click rates fell and reporting rose.
Where phishing simulation fits your compliance
Security-awareness testing is written into most frameworks a European business has to satisfy, and our reporting is built to slot straight into an audit.
ISO 27001, PCI DSS and beyond
ISO 27001:2022 control A.6.3 requires information-security awareness, education and training, and auditors increasingly want evidence that the training is measured, not just delivered. PCI DSS 4.0 requirement 12.6 mandates a formal security-awareness program with periodic testing. A documented phishing simulation gives you that evidence in a form an assessor recognizes.
GDPR, NIS2 and DORA
Under the GDPR, article 32 expects appropriate organizational measures to protect personal data, and staff susceptibility to phishing is squarely an organizational risk. For operators in scope of NIS2, human-risk testing supports the required cyber-hygiene and training measures. Financial entities under DORA can fold awareness metrics into their ICT risk-management reporting. We map findings to the framework you name so the report earns its keep at audit time.
Why a live simulation beats a checkbox
Plenty of platforms will spray a template at your staff and hand you a percentage. That is better than nothing, but it rarely reflects a real attacker, and staff learn to spot the same tired template within a month. Our value is the human craft in the pretext and the analysis behind the numbers. A tailored campaign designed by an offensive engineer who has actually broken into companies produces results you can trust, and advice you can act on. The dashboard tells you what happened. We tell you why, and what to change.
When to run a simulation, and how often
A single test tells you where you stand today. A program tells you whether your people are getting harder to fool, which is the number that actually protects you.
Baseline, then repeat
We recommend an initial baseline campaign to establish honest starting figures, followed by quarterly rounds with fresh pretexts. Attackers rotate their lures constantly, and staff quickly learn to spot a template they have seen before, so repeating the same email teaches nothing. Rotating themes keeps the exercise honest and the training relevant.
Tie it to real events
The best moments to run a simulation are after onboarding a group of new hires, following a policy change, or in the run-up to an audit that expects awareness evidence. A campaign timed to a merger or a major product launch also reflects when attackers are most likely to strike, because those are the moments your staff are busiest and least suspicious.
Report the trend to leadership
Boards respond to direction of travel, not a single percentage. We present click and report rates as a trend across rounds, so you can show that investment in awareness is paying off and pinpoint the teams that still need attention. That trend line is often what unlocks continued budget for security training.
Pricing
Pricing scales with headcount and how many channels you want to test. A single email campaign against a small team costs far less than a multi-vector program across a large European workforce with vishing and bespoke pretexts.
| Engagement | What’s included | Timeline | Price |
|---|---|---|---|
| Baseline campaign | Single email pretext to up to 100 staff, click and report metrics, teachable landing page, summary report | 1–2 weeks | from €1,500 |
| Standard program | Two to three tailored pretexts, credential-capture tracking, per-department breakdown, awareness training modules, exec + technical report | 2–4 weeks | €2,500–€5,000 |
| Multi-vector | Email plus vishing or smishing, MFA-fatigue and consent-phishing scenarios against your identity provider, deep debrief | 3–5 weeks | €5,000–€12,000 |
| Ongoing awareness | Quarterly simulations with trend reporting and refreshed pretexts, run as a managed program across the year | quarterly | from €4,000/yr |
| Custom / large estate | Thousands of users, multiple languages and countries, blended with a wider red-team objective | on scoping | custom |
Every engagement is fixed-price, quoted after a free 20-minute scoping call, and a follow-up retest is included. Get a fixed quote
FAQ
How much do phishing simulation services cost?
Will you store our employees’ passwords?
How do you keep the exercise fair to staff?
Does this satisfy ISO 27001 or PCI DSS awareness requirements?
Can you test phone and text attacks as well as email?
What do we get after the campaign?
How long does a phishing simulation take?
Are you one of the phishing simulation companies that also trains our staff?
Related services
Any European business whose staff handle email, money or customer data and wants a defensible measure of human risk. It suits companies preparing for ISO 27001 or PCI DSS, security leads building an awareness program, and anyone who has already had a near-miss and wants to know how exposed they really are.
Security you can prove
The same standard on every engagement, big or small.
Evidence, not opinions
Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".
Humans over scanners
Certified engineers find the logic flaws and chained attacks automated tools walk straight past.
Fixed price, free retest
You know the cost up front, and verifying the fix is part of the deal — not a second invoice.
Ready to lock this down?
Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.