Phishing Simulation for Businesses — Employee Security Awareness Testing
You can spend PLN 50,000 on the most expensive antivirus on the market. But if one employee clicks a single fake link, those systems are bypassed. Our phishing simulation builds resilience in people, not just machines.
How a phishing simulation works
01. Campaign preparation
We agree the scope: number of recipients, the message scenario (e.g. a fake invoice, a password reset, a parcel notice) and the schedule. The campaign starts only after written authorisation.
02. Delivery
Test messages reach the selected mailboxes. Technically, the campaign looks like a real phishing attack — with no risk to your systems.
03. Response measurement
We measure who opened the message, who clicked the link, and who submitted data in the test form. No real data leaves your infrastructure.
04. Report and training
After the campaign you receive an aggregated results report, and the people who clicked automatically get a short e-learning module.
Plans
Starter — up to 25 people
One campaign per month and an aggregated results report.
from PLN 800 net / month
Growth — up to 100 people
Monthly campaign, report, and automatic e-learning for the people who clicked.
from PLN 1,800 net / month
Enterprise — over 100 people
Cross-department benchmarking and a board-level report.
individual pricing
Before and after
- Before: nobody knows how many employees would click a fake link. After: a concrete percentage from a test campaign and a month-over-month trend.
- Before: annual training nobody remembers. After: a short e-learning delivered exactly at the moment of the mistake.
- Before: the board hears "we are secure". After: the board sees a measurable resilience indicator for the team.
What this service does not include
- We do not send real attacks and we do not install malicious software — this is a controlled, authorised test.
- It does not replace full cyber security training — the post-click e-learning takes a few minutes and covers phishing only.
- It does not include a technical assessment of your systems — infrastructure vulnerabilities are covered by our other services.
- We do not guarantee that nobody will ever click — we measure and steadily reduce the risk, but it cannot be eliminated entirely.
Frequently asked questions
Is a phishing simulation legal?
Yes, provided it is commissioned by the entity authorised to manage the infrastructure — with us, always under a contract and a written authorisation of scope. Internal communication about the campaign stays on your side; if in doubt (e.g. GDPR), consult your own adviser.
What happens when an employee clicks the link?
They land on a safe training page and complete a short e-learning. The result goes into the aggregated report. The campaign is not about punishing anyone — it teaches people to recognise an attack.
How often should campaigns be repeated?
We recommend a monthly cycle. A single campaign shows a snapshot; only a series shows the trend and the team’s real progress.
Ask about a phishing simulation
We match the plan and scope after a short briefing. Tell us how many people the campaign should cover — we will come back with a proposed schedule.
Marcin Białczyk, operator at CHORS.NET — read about my approach.