The one messagenobodyquestions.
A phishing simulation does not show who is careless. It shows which techniques work in your organisation and where a short explanation achieves more than another policy.
Why many simulations do more harm than good
Four mistakes that burn a good idea.
Everyone gets the same mail on the same day
Within ten minutes the whole building knows, and from then on the simulation only measures how fast news travels down the corridor.
The test mail is too obvious
Sending only clumsy fakes confirms a false sense of safety. Attackers do not send clumsy fakes.
Whoever clicks gets reported
As soon as results carry names to managers, fear replaces attention. After that incidents are no longer reported, they are hidden.
Nothing happens after the click
A simulation without an explanation afterwards is a statistic. Learning happens the moment someone understands what the giveaway was.
How a simulation runs at Conbool
Prepare, stagger, explain.
1. Choose audience and technique
You decide which departments take part and which techniques the messages should be modelled on.
2. Send staggered over time
Messages go out spread across days so the simulation does not announce itself.
3. Explain immediately
Anyone who reacted receives a short unit on that exact technique straight away, with no report to anyone else.
What makes the simulation work
Six points that decide the outcome.
Realistic templates
Messages follow techniques that are actually in circulation, not obvious test mails.
Spread over time
Staggered rather than bundled sending, so the result reflects everyday work and not corridor gossip.
Explanation instead of reporting
A reaction is followed by a short unit, not by a notification to management.
Group level evaluation
Results per department and period, with no ranking of individual employees.
Your mailbox has reached its storage limit
it-service@mailbox-administration.net
That was a simulation
The sender domain does not belong to your company. For genuine notices of this kind, a look at the address behind the display name is what helps.
Anyone who did not react gets nothing. There is no ranking and no report to management.
First the message, then the explanation.
The simulation does not end with a click but with a short explanation. Learning happens exactly when someone understands what the giveaway would have been.
Templates modelled on techniques in real use
Sending spread across days
Explanation straight away, with no report to anyone
Evaluation at group level only
Simulation versus briefing alone
What each approach delivers.
With simulation | Briefing only | |
|---|---|---|
| Everyday behaviour becomes visible | yes | no |
| Training hits the actual weakness | yes | no |
| Development measurable over time | yes | no |
| Evidence beyond an attendance list | yes | no |
| Works council agreement required | yes | usually not |
The last row is deliberately not a judgement. A simulation evaluates behaviour and is therefore subject to codetermination, a plain briefing usually is not.
Frequently asked questions
Is a phishing simulation even permitted?
What happens to someone who clicks?
How is success measured?
How often should we simulate?
Can whole departments be excluded?
How is this different from phishing protection?
Related solutions
NIS2 im Überblick
Richtlinie, Umsetzungsgesetz und BSIG: wer betroffen ist und was gilt.
Security Awareness Training
Schulung, die sich gegenüber einer Prüfung belegen lässt.
NIS2-Schulungspflicht
Was Paragraf 30 und Paragraf 38 BSIG konkret verlangen.
Phishing-Schutz
Die technische Abwehr, bevor eine Nachricht den Menschen erreicht.
NIS-2 E-Mail-Sicherheit
Alle E-Mail-Anforderungen nach Paragraf 30 BSIG im Überblick.
Plan the first round together
We define audience, techniques and evaluation with you and go through the result afterwards.