CHORS.NET
Subscription service — authorised testing

Phishing Simulation for Businesses — Employee Security Awareness Testing

You can spend PLN 50,000 on the most expensive antivirus on the market. But if one employee clicks a single fake link, those systems are bypassed. Our phishing simulation builds resilience in people, not just machines.

How a phishing simulation works

01. Campaign preparation

We agree the scope: number of recipients, the message scenario (e.g. a fake invoice, a password reset, a parcel notice) and the schedule. The campaign starts only after written authorisation.

02. Delivery

Test messages reach the selected mailboxes. Technically, the campaign looks like a real phishing attack — with no risk to your systems.

03. Response measurement

We measure who opened the message, who clicked the link, and who submitted data in the test form. No real data leaves your infrastructure.

04. Report and training

After the campaign you receive an aggregated results report, and the people who clicked automatically get a short e-learning module.

Plans

Starter — up to 25 people

One campaign per month and an aggregated results report.

from PLN 800 net / month

Growth — up to 100 people

Monthly campaign, report, and automatic e-learning for the people who clicked.

from PLN 1,800 net / month

Enterprise — over 100 people

Cross-department benchmarking and a board-level report.

individual pricing

Before and after

- Before: nobody knows how many employees would click a fake link. After: a concrete percentage from a test campaign and a month-over-month trend.

- Before: annual training nobody remembers. After: a short e-learning delivered exactly at the moment of the mistake.

- Before: the board hears "we are secure". After: the board sees a measurable resilience indicator for the team.

What this service does not include

- We do not send real attacks and we do not install malicious software — this is a controlled, authorised test.

- It does not replace full cyber security training — the post-click e-learning takes a few minutes and covers phishing only.

- It does not include a technical assessment of your systems — infrastructure vulnerabilities are covered by our other services.

- We do not guarantee that nobody will ever click — we measure and steadily reduce the risk, but it cannot be eliminated entirely.

Frequently asked questions

Is a phishing simulation legal?

Yes, provided it is commissioned by the entity authorised to manage the infrastructure — with us, always under a contract and a written authorisation of scope. Internal communication about the campaign stays on your side; if in doubt (e.g. GDPR), consult your own adviser.

What happens when an employee clicks the link?

They land on a safe training page and complete a short e-learning. The result goes into the aggregated report. The campaign is not about punishing anyone — it teaches people to recognise an attack.

How often should campaigns be repeated?

We recommend a monthly cycle. A single campaign shows a snapshot; only a series shows the trend and the team’s real progress.

Ask about a phishing simulation

We match the plan and scope after a short briefing. Tell us how many people the campaign should cover — we will come back with a proposed schedule.

Marcin Białczyk, operator at CHORS.NET — read about my approach.