More than 90% of successful cyberattacks begin with human error. A phishing campaign will safely test how employees respond to fraudulent emails, links, attachments, or fake login pages. You’ll discover not only the number of clicks but also the actual risk to your organization and the effectiveness of your security processes.
A one-time phishing campaign
Suitable for organizations that want to conduct a one-time assessment of their employees’ current level of security awareness.
Together, we’ll choose a suitable scenario. We’ll then prepare and send out test emails and evaluate the responses. Once the campaign is over, you’ll receive a report with the results and recommendations.
This service will conduct a one-time audit of your organization. After mutual agreement and establishing a specific scenario, we will send out emails containing clues indicating that they are phishing attempts. We will let the campaign run for a period of time and then evaluate it in a final report.
Suitable for: an initial phishing test, assessing a specific risk, or a follow-up assessment after training
Ongoing Campaigns and Education
Regular campaigns and follow-up training help improve employee behavior over the long term. We conduct four campaigns with different scenarios throughout the year. After the initial testing, we begin training employees and continue to test them. We report on the results of each campaign on an ongoing basis and monitor the development of employees’ resilience.
The service includes access to a training platform where, after clicking or entering their information, employees can be redirected to a brief explanation and verification questions.
Suitable for: long-term education, regular testing, and tracking progress
Targeted black-box phishing
We simulate a real-world attacker who has no prior knowledge of the organization’s internal environment. We use publicly available information to develop customized scenarios targeting specific employees, roles, or departments.
The campaign may combine email phishing with other methods, such as smishing or vishing.
Suitable for: realistic testing of security processes
We create phishing campaigns on our own platform. It is designed to make creating a campaign simple and to guide users through the entire process step by step.
Currently, there are over 15 pre-designed phishing scenarios available for you to choose from. We can further customize each scenario to suit the environment and needs of a specific organization.
Campaign preparation consists of five steps:
We recommend doing this on an ongoing basis throughout the year. That’s one of the reasons why we offer the Porybný service, which includes four campaigns a year.
We’ll take care of everything; all you need to do is agree on the topic and, if necessary, the person whose email address will be used to send out the campaign.
Essentially all of them, ranging from traditional email phishing and SMS smishing to voice vishing, right through to the less common form of WiPhishing, which creates a fake access point.
Almost everywhere – healthcare, finance, retail and software development.
© Sec4good, s.r.o., registered in the commercial register at the municipal court in Prague, section C, insert 378876.