Not every cyberattack targets systems, networks or software. Many security incidents occur because employees open a phishing email, click on a suspicious link or share data with an unauthorised party.
Phishing Simulations and Security Awareness training help organisations gain insight into how employees deal with digital risks. Through realistic simulations, awareness and targeted guidance, risks can be reduced and a higher level of cyber resilience is created within the organisation.
With Phishing Simulations and Security Awareness, B/Focused supports organisations in recognising risks, improving security awareness and creating a safety culture in which employees actively contribute to protecting company data.
Why our Security Awareness approach works differently
Measurable results & Reports
Security Awareness must be measurable. That’s why results, trends and points for attention are made visible through clear reports and dashboards.
This creates insight into risks, improvements and the effectiveness of previous awareness campaigns.
Risk-based Campaigns
Not every organisation faces the same risks. That’s why campaigns can be tailored to job profiles, departments, business processes and current threats.
This means simulations better match the daily practice of employees.
Continuous Awareness
Cyber resilience does not come from a single training or a single simulation. Security Awareness requires an ongoing process of learning, recognising and improving.
Through periodic campaigns, security awareness remains actively present within the organisation.
Support for NIS2 & Compliance
Security Awareness plays an important role within NIS2, information security policy and internal risk management.
Reports and periodic evaluations help organisations demonstrably address people-related risks.
Integration with Managed SOC
Security Awareness is not separate from security monitoring. Insights from phishing campaigns can be combined with monitoring, detection and security reports from the Managed SOC.
This creates a more complete picture of your organisation’s cyber resilience.
Practical Advice & Improvement actions
Results only become valuable when they lead to concrete improvements. That’s why we help organisations translate points for attention into practical measures, training and improvement actions.
This way, Security Awareness grows into a structural part of the security strategy.
How is our Security Awareness service structured?
Step 1 - Baseline measurement & Analysis
We start with an initial phishing campaign to gain insight into the current level of knowledge and risk behaviour within the organisation.
Step 2 - Simulation & Awareness
Employees receive realistic phishing campaigns and awareness content that matches current threats and practical situations.
Step 3 - Reports & Insights
Results are made visible via dashboards and reports so that trends, improvements and points for attention become visible.
Step 4 - Continuous Improvement
Through periodic simulations, evaluations and additional training, security awareness remains an active part of the organisational culture.
What does a phishing simulation cost?
The cost of phishing simulations depends on the number of users, the desired frequency of campaigns, the reporting needs and any additional awareness training.
For some organisations, a one-off campaign is enough to carry out a baseline measurement. Other organisations choose an ongoing awareness programme in which employees are regularly tested and informed about new threats throughout the year.
During a no-obligation conversation, we discuss which approach best suits your organisation.
Frequently asked questions
How often should a phishing campaign be run?
Cyber threats change constantly. That’s why we recommend running phishing simulations and awareness campaigns periodically, so that security awareness remains actively present and improvements become measurable.
Do phishing simulations support NIS2?
Yes. Security Awareness plays an important role within NIS2 and risk management. Phishing simulations and awareness campaigns help organisations demonstrably address people-related cyber risks.
What is a phishing simulation?
A phishing simulation is a controlled test in which employees receive a realistic phishing email. The goal is not to judge employees, but to gain insight into risk behaviour and increase security awareness within the organisation.
Are employees assessed individually?
No. The goal of phishing simulations is awareness and improvement, not assessing individual employees. Results are used to make risks visible and to better tailor training.
Why are phishing simulations important?
Many cyberattacks start with a phishing email, a suspicious link or information shared by employees. Phishing simulations help organisations gain insight into risk behaviour and increase security awareness within the organisation.
How does malware get onto my computer?
In most cases this happens because someone clicks on a link. Sometimes, however, it can be a lot more innocent. A few years ago, for example, malware ran for a while on the news site nu.nl via an advertisement. Clicking on it installed malware demanding ransom because of viewed pornographic content.
How does someone know my password?
Sometimes we also see people receiving an email claiming their systems have been hacked and that the sender knows their password, where the password mentioned in the email is indeed one they actually use.
In such a case your password was probably obtained in a hack of another organisation or institution. There’s little you can do about this either. However, it is of course better not to use the same password everywhere. For more tips on passwords, see our password page.
You can also check on the website Have I Been Pwned whether your email address has ever been leaked in a hack. Examples include LinkedIn, which in 2016 turned out to have leaked 164.000.000 email addresses and passwords, and Dropbox with 68.000.000 email addresses and passwords. More recently, in 2021 Booking.com was in the news, and closer to home the webshop Allekabels, and the list could go on.
Someone is actually sending email from my email address, what is going on?
This can have two causes:
- The technical settings of your domain name are not in order, making your domain name easy to spoof. If the technical security of your email systems is also not in order, a forged email can easily get past security. This is the least severe cause and can be fixed simply by activating the correct technical settings.
- Someone is actually sending mail using your own email address. That can mean only one thing: you’re dealing with a hack. Contact a professional immediately, change your passwords and preferably set up two-step verification (MFA), which protects your email system much better.
Someone is sending email in my name on the internet, what can I do about it?
In principle, there is nothing you can do about it. Anyone can create an email address and put a fictitious name, or even your company, in the display name. This means your employees or contacts receive an email with, for example, “Ralph Dykstra | B/Focused ICT Services”. However, if we look at the sender address, it’s often quickly recognisable that this is not the real sender, but a hacker trying to fish for information this way.
The advice is therefore: pay close attention and think logically.
I’ve been hacked, do I have to pay ransom to get my data back?
Here the main rule is: prevention is better than cure. Always make sure you have a good backup! If you don’t have one, we do have a challenge. We certainly won’t get the data back quickly. It is then mainly your own choice, although paying ransom is no guarantee that you will actually get your data back.