Find out how your staff respond, without turning it into a witch hunt.
We send realistic phishing to your own people, measure what happens, and follow it the same week with training that takes minutes rather than an afternoon. Results are reported as numbers for the organisation, not as a list of names.
Training moved from good practice to an obligation.
NIS2
Directive (EU) 2022/2555 requires essential and important entities to have basic cyber hygiene practices and cybersecurity training as part of their risk management measures, and requires management bodies to follow training themselves. Management can be held responsible for failures.
Financial entities under DORA
Regulation (EU) 2022/2554 requires ICT security awareness programmes and digital operational resilience training for staff and, at a proportionate level, for management.
GDPR
Article 32 requires measures appropriate to the risk, and Article 39 makes awareness raising and training of staff an explicit task where a data protection officer is appointed.
ISO 27001
Annex A control 6.3 of the 2022 revision requires personnel to receive information security awareness, education and training relevant to their role, and to be updated regularly. It names awareness and training, not simulation.
Tested for effectiveness
For the digital infrastructure and managed service entities covered by Implementing Regulation (EU) 2024/2690, the awareness programme must, where appropriate, be tested for effectiveness. A simulation is the usual way to produce that evidence.
Your customers' questionnaires
Whether or not a directive applies to you, a large customer's supplier assessment will ask when you last ran awareness training and what the result was. An answer with a number wins that question.
Simulating an attack on your own staff is a personnel measure. We treat it as one.
In Germany and Austria a campaign that records how individual employees behaved is a monitoring measure and typically needs the works council on board before it starts. Done badly, a simulation costs you more goodwill than the attack it was meant to prevent.
Aggregated by default
You receive rates by department, site and campaign. Individual results are not reported to management and are deleted after the campaign.
Works council material
We prepare the description of purpose, data, retention and reporting that a works agreement needs, and we sit in the meeting if it helps.
Announced in principle
Staff are told that simulations happen, not when. That keeps the exercise honest and keeps trust intact.
No shaming
Someone who clicks lands on a short page that explains the three signals they missed. That is the whole intervention.
Reporting is the metric
We measure how many people report the mail, not only how many click. A workforce that reports fast is the outcome worth paying for.
Data protection built in
Processing agreement, EU hosting, minimal retention, and a record of processing you can show your data protection officer.
A quarter at a time
Baseline
One campaign against the whole organisation, built from templates that match your industry and your suppliers. You get a click rate, a report rate and the time to first report.
Training that follows
Short modules in the languages your staff speak, sent within days while the memory is fresh. Ten minutes, on a phone, no login to remember.
Measure again
A different campaign the next quarter. You see whether the number moved, by department. That trend line is what an auditor and a customer both want.
Start with one honest baseline.
We will show you the templates, the reporting, and the works council pack before you commit to anything.