Spear Phishing
How does your organisation respond to a targeted phishing email?
Using an agreed, credible scenario, we test how employees and processes handle a targeted phishing attempt. The outcome helps you improve recognition, reporting and follow-up.
From context to response
Three questions we answer
- Does the scenario reach the agreed target group?
- Which interactions and reports follow?
- Where could employees and administrators receive better support?
When is this relevant?
A recognisable work situation makes the assessment relevant.
Targeted phishing relates to people, roles and everyday work. We choose a scenario that fits your organisation and the question you want to answer.
- You want to know how a specific target group responds to a credible scenario.
- You want to practise and improve the reporting of suspicious messages.
- You have changed awareness activities or email security.
- You want to learn how IT administrators and employees respond to a phishing attempt together.
The assessment
What do we assess?
Your environment and assessment question determine the content. We agree in advance which elements we will examine.
01
Targeted preparation
We update the public, professional information needed about the agreed target group. We use that information to design an appropriate scenario, with the extent of the assessment defined in advance.
02
Scenario and execution
We agree the message, target group, testing period and permitted interactions. We then carry out the simulation according to those arrangements.
03
Responses and reports
We record the agreed interactions and map the available reports. The meaning of the results depends on reach, the target group and the chosen scenario.
04
Technical and organisational follow-up
Your administrators can review logs from the email environment and security products. Alongside reports to IT, this helps explain what was blocked, recognised or followed up.
Defining the scope together
A scope that fits your question.
Before testing, we document the objective, target group and measurements. Preparation also includes arrangements for information use, communication and evaluation.
What do we agree in advance?
- Target group, scenario, sending time and testing period.
- Which interactions are measured and how results are reported.
- Use and retention period of assessment data.
- Contacts, internal reports and available administration logs.
Customer logs are needed to understand detection by Exchange, Microsoft 365 or other security products. A limited scenario does not, on its own, provide a full assessment of the email environment's security.
The result
Insight you can act on.
01
Results in context
An overview of the scenario, reach and agreed measurements, with an explanation of the limitations.
02
Insight into reporting behaviour
Available information about recognition, internal reports and follow-up by the teams involved.
03
Practical improvements
Points to act on for awareness, reporting procedures and, where examined, technical security measures.
Our approach
From the initial question to follow-up.
01
Choosing the objective and target group
We determine what you want to learn and which scenario fits.
02
Preparation and coordination
We develop the scenario and document the measurements and execution.
03
Simulation and recording
We carry out the agreed test and collect the available evidence.
04
Evaluating together
We discuss the outcome and practical improvements for people, processes and technology.
Frequently asked questions
What you need to know in advance.
Is clicking the only result you measure?
No. Depending on the arrangements, we also examine reach, other permitted interactions, employee reports and follow-up by administrators. That combination makes the outcome easier to interpret.
Can you see what our email security blocks?
This is not fully visible from outside. Your administrator can supply logs and alerts from Exchange or other security products so we can compare them with the test activities.
How do you use public information?
We limit preparation to information needed for the agreed target group and scenario. The data, its use and its retention period are defined in advance.
Are employees assessed individually?
We agree the objective and reporting level in advance. We focus the evaluation on improving resilience and recognising patterns in behaviour and processes.
Discuss your situation
Make a phishing test relevant to your organisation.
Discuss your target group and assessment question. Together, we determine the scenario and which results you want to interpret.