Lacop Studio OG · Wels, Austria · FN 659759i Directive (EU) 2019/1937 · Directive (EU) 2019/882 office@lacopstudio.com
Lacop SystemsCompliance systems
Phishing simulation and awareness

Find out how your staff respond, without turning it into a witch hunt.

We send realistic phishing to your own people, measure what happens, and follow it the same week with training that takes minutes rather than an afternoon. Results are reported as numbers for the organisation, not as a list of names.

Why now

Training moved from good practice to an obligation.

NIS2

Directive (EU) 2022/2555 requires essential and important entities to have basic cyber hygiene practices and cybersecurity training as part of their risk management measures, and requires management bodies to follow training themselves. Management can be held responsible for failures.

Financial entities under DORA

Regulation (EU) 2022/2554 requires ICT security awareness programmes and digital operational resilience training for staff and, at a proportionate level, for management.

GDPR

Article 32 requires measures appropriate to the risk, and Article 39 makes awareness raising and training of staff an explicit task where a data protection officer is appointed.

ISO 27001

Annex A control 6.3 of the 2022 revision requires personnel to receive information security awareness, education and training relevant to their role, and to be updated regularly. It names awareness and training, not simulation.

Tested for effectiveness

For the digital infrastructure and managed service entities covered by Implementing Regulation (EU) 2024/2690, the awareness programme must, where appropriate, be tested for effectiveness. A simulation is the usual way to produce that evidence.

Your customers' questionnaires

Whether or not a directive applies to you, a large customer's supplier assessment will ask when you last ran awareness training and what the result was. An answer with a number wins that question.

What we will not tell you. No EU instrument names phishing simulation as a legal requirement. Not NIS2, not DORA, not the GDPR, not ISO 27001. The duties above are duties to train and to manage risk. Simulation is the most reliable way we know to measure whether the training worked, and that is how we sell it. We will also tell you honestly whether NIS2 is actually in force where you are, because several member states are late transposing it.
Run lawfully

Simulating an attack on your own staff is a personnel measure. We treat it as one.

In Germany and Austria a campaign that records how individual employees behaved is a monitoring measure and typically needs the works council on board before it starts. Done badly, a simulation costs you more goodwill than the attack it was meant to prevent.

Aggregated by default

You receive rates by department, site and campaign. Individual results are not reported to management and are deleted after the campaign.

Works council material

We prepare the description of purpose, data, retention and reporting that a works agreement needs, and we sit in the meeting if it helps.

Announced in principle

Staff are told that simulations happen, not when. That keeps the exercise honest and keeps trust intact.

No shaming

Someone who clicks lands on a short page that explains the three signals they missed. That is the whole intervention.

Reporting is the metric

We measure how many people report the mail, not only how many click. A workforce that reports fast is the outcome worth paying for.

Data protection built in

Processing agreement, EU hosting, minimal retention, and a record of processing you can show your data protection officer.

The programme

A quarter at a time

01

Baseline

One campaign against the whole organisation, built from templates that match your industry and your suppliers. You get a click rate, a report rate and the time to first report.

02

Training that follows

Short modules in the languages your staff speak, sent within days while the memory is fresh. Ten minutes, on a phone, no login to remember.

03

Measure again

A different campaign the next quarter. You see whether the number moved, by department. That trend line is what an auditor and a customer both want.

Start with one honest baseline.

We will show you the templates, the reporting, and the works council pack before you commit to anything.

Talk about a campaign Check the duty in your country