Skip to main content

Phishing simulations

A repeatable send with measurement and training afterwards. What gets evaluated is the reporting rate, not the click rate.

Phishing-Simulation und ihre Auswertung Eine Kampagne an fuenfhundert Postfaecher, aufgeteilt in gemeldet, ignoriert und geklickt. Ausgewertet wird ohne Namen. CAMPAIGN 500 MAILS REPORTED 46 % IGNORED 36 % CLICKED 18 % EVALUATION STAYS ANONYMOUS PHISHING SIMULATION · ANONYMISED
Trusted by
What this is

The number that counts is the reporting rate

A simulation usually measures how many people clicked. That number falls with every round, and it says little, because a well-made mail catches attentive people too.

The number that holds up is a different one: how many reported the mail, and how quickly. A click can be caught as long as someone reports it and someone else acts on the report. So we evaluate the reporting rate and the reporting time, and check along the way whether the report actually arrives anywhere.

How it runs

How a campaign works

Four steps per round, usually three to four rounds a year.

1

Goals and limits

Which areas, what difficulty, which pretexts are ruled out. The works council sits at this table, and the undertaking not to evaluate on individuals is written into the engagement.

2

The send

Templates that fit your organisation: invoices from real suppliers, internal announcements, messages from tools you actually use. Generic templates catch nobody any more.

3

Measurement

Opened, clicked, data entered, reported. Plus the time to the first report and the question of what happened in the organisation afterwards.

4

Training

Whoever clicked gets a short explanation of that exact mail straight away. For everyone there is a write-up showing what the mail could have been recognised by.

Where the line is

When a simulation is enough and when it is not

The simulation is the repeatable mass send with a rate and a learning effect. It reaches many people at low cost and works as a recurring measure that can also be evidenced to a regulator.

Targeted attacks on individuals, phone calls and the route through reception belong in a different format. Anyone who wants to know whether a particular person can be reached with a pretext cut for them needs social engineering.

Common questions

Common questions about phishing simulations

No. We evaluate on groups, not on individuals, and that undertaking is written into the engagement. The person concerned gets feedback straight away, because that is where the learning is.

Three to four rounds a year with rising difficulty. Less often has no effect; more often makes everyone treat every mail as a test.

That is exactly what we check along the way. A simulation in which reports land in a mailbox nobody reads shows that immediately, and that finding is usually worth more than the click rate.

Credentials

Certifications and memberships.

Certifications held in the team
Memberships
eco – Verband der Internetwirtschaft
networker NRW
Next step

Talk to us.

A first conversation usually takes 30 minutes. We look at where you stand and tell you frankly whether we are the right partner.

Telephone
0231 39814905
Mon–Fri · 9am–5pm CET
Email
info@yekta-it.de
PGP key available
Location
Dortmund
Ruhrallee 9 · 44139