Audit and testing
Phishing simulation
What is the point of a phishing simulation?
In a phishing simulation you send harmless test emails, announced to the workforce but without naming the moment. It shows you how your business actually reacts.
The most important number is not how many people clicked. The most important number is how many reported the message, and how quickly. A click is human. A report within minutes gives you the chance to contain the damage.
A simulation is a means of learning. It is not suited to exposing individual employees. Anyone who fears consequences reports a genuine incident late or not at all, and that is exactly what worsens your position.
Mind the legal frame. An evaluation that traces back to individuals is a form of monitoring behaviour. Evaluate in aggregate and involve any staff representation beforehand.
All terms in the knowledge base
Note: This entry reflects the state of knowledge to the best of our understanding and serves as general orientation. It is not legal advice. What counts is always the version currently in force at the responsible body, for example dsb.gv.at, nis.gv.at or enisa.europa.eu.
From the term to practice
Where does your business actually stand?
The IT Check reviews your IT across 8 audit areas with more than 100 individual checks and delivers documented findings with a prioritised action plan. From 1,299 € excl. VAT. The first call takes 20 minutes and carries no charge.