04 / PHISHING SIMULATIONS

When the scam looks
convincing.

A phishing simulation shows how employees react to a controlled email that resembles a scam. The results provide a practical starting point for training and better routines.

Request a quote
SUITABLE FOR

For businesses that want to assess security awareness and make training relevant to situations their employees actually face.

01 / SCOPE AND DELIVERABLES

From insight to action.

Read the service description (Norwegian) PDF ↗
01

An agreed scenario

The audience, timing and email design are agreed before sending. The scenario is tailored to the purpose of the test.

02

A controlled campaign

A simulated phishing email is sent to agreed employees as part of the planned security test.

03

Response measurement

The service description covers who did not respond, opened the email or attempted to provide requested information, within the agreed and available measurements.

04

A basis for improvement

Results can help prioritise training topics and review reporting routines. Follow-up and further campaigns are agreed as needed.

The aim is learning. Individual data, access to results, retention and any applicable employment-law requirements are clarified before starting. Real passwords or payment details must not be included in the test report.

HOW WE GET STARTED

01

Agree the ground rules

Clarify the purpose, audience, privacy, employee information and handling of results.

02

Run the simulation

The agreed email is sent and responses are measured according to the test setup.

03

Learn from the results

Use the findings to give relevant guidance and improve routines for recognising and reporting suspicious activity.

02 / REGULATIONS AND DOCUMENTATION

Supporting your security work.

See requirements and scope

Our assessment of how the service can support your work. Applicable requirements depend on your organisation and how the service is used.

Requirements for organisations in scope

Norwegian Digital Security Act

Test results can inform relevant training for providers of essential services.

NSM guidance
Risk-appropriate requirements

GDPR / privacy

Measuring employee responses involves processing personal data. Purpose, lawful basis, information and data minimisation need to be assessed.

GDPR, including Article 32
Preparing for Norwegian implementation

NIS2

Simulations can support preparation around security awareness and evaluation of measures. This is a contribution to security work, not a certification.

EFTA: Norwegian/EEA status

Useful to know before we start.

Do opens and clicks tell the whole story?

No. Email filters and security systems can affect measurements, and a single campaign is a snapshot. Results need to be interpreted alongside the scenario, measurement method and organisational routines.

Is this the same as a real attack?

It is an agreed simulation. The purpose is to understand responses and learn from them, with defined limits on what data is recorded and who can see the results.

Can we run several campaigns?

Yes, scope and frequency can be agreed. Repetition can help track progress, particularly when scenarios and measurements are comparable.

NEXT STEP / A NO-OBLIGATION CONVERSATION

Plan a phishing simulation

How many employees would be involved, and what would you like to learn from a simulation?

We agree needs, scope and pricing before starting.
An enquiry carries no obligation to purchase.

How can we help?

Choose a service and tell us a little about your needs.

I would like

Opens your email app with a draft to Eddie. Review it and send it yourself. This form does not store your details.