Cyber resilience

What are Phishing Simulations and Security Awareness training?

Make employees resilient to phishing: realistic simulations, a baseline measurement, measurable reports and ongoing awareness, also supporting NIS2.

Need support? +31 45 303 0003 Advice or a quote? +31 45 303 0232

Available across the EU, delivered remotely.

Not every cyberattack targets systems, networks or software. Many security incidents occur because employees open a phishing email, click on a suspicious link or share data with an unauthorised party.

Phishing Simulations and Security Awareness training help organisations gain insight into how employees deal with digital risks. Through realistic simulations, awareness and targeted guidance, risks can be reduced and a higher level of cyber resilience is created within the organisation.

With Phishing Simulations and Security Awareness, B/Focused supports organisations in recognising risks, improving security awareness and creating a safety culture in which employees actively contribute to protecting company data.

Why our Security Awareness approach works differently

Measurable results & Reports

Security Awareness must be measurable. That’s why results, trends and points for attention are made visible through clear reports and dashboards.

This creates insight into risks, improvements and the effectiveness of previous awareness campaigns.

Risk-based Campaigns

Not every organisation faces the same risks. That’s why campaigns can be tailored to job profiles, departments, business processes and current threats.

This means simulations better match the daily practice of employees.

Continuous Awareness

Cyber resilience does not come from a single training or a single simulation. Security Awareness requires an ongoing process of learning, recognising and improving.

Through periodic campaigns, security awareness remains actively present within the organisation.

Support for NIS2 & Compliance

Security Awareness plays an important role within NIS2, information security policy and internal risk management.

Reports and periodic evaluations help organisations demonstrably address people-related risks.

Integration with Managed SOC

Security Awareness is not separate from security monitoring. Insights from phishing campaigns can be combined with monitoring, detection and security reports from the Managed SOC.

This creates a more complete picture of your organisation’s cyber resilience.

Practical Advice & Improvement actions

Results only become valuable when they lead to concrete improvements. That’s why we help organisations translate points for attention into practical measures, training and improvement actions.

This way, Security Awareness grows into a structural part of the security strategy.

How is our Security Awareness service structured?

Step 1 - Baseline measurement & Analysis

We start with an initial phishing campaign to gain insight into the current level of knowledge and risk behaviour within the organisation.

Step 2 - Simulation & Awareness

Employees receive realistic phishing campaigns and awareness content that matches current threats and practical situations.

Step 3 - Reports & Insights

Results are made visible via dashboards and reports so that trends, improvements and points for attention become visible.

Step 4 - Continuous Improvement

Through periodic simulations, evaluations and additional training, security awareness remains an active part of the organisational culture.

What does a phishing simulation cost?

The cost of phishing simulations depends on the number of users, the desired frequency of campaigns, the reporting needs and any additional awareness training.

For some organisations, a one-off campaign is enough to carry out a baseline measurement. Other organisations choose an ongoing awareness programme in which employees are regularly tested and informed about new threats throughout the year.

During a no-obligation conversation, we discuss which approach best suits your organisation.

Frequently asked questions

How often should a phishing campaign be run?

Cyber threats change constantly. That’s why we recommend running phishing simulations and awareness campaigns periodically, so that security awareness remains actively present and improvements become measurable.

Do phishing simulations support NIS2?

Yes. Security Awareness plays an important role within NIS2 and risk management. Phishing simulations and awareness campaigns help organisations demonstrably address people-related cyber risks.

What is a phishing simulation?

A phishing simulation is a controlled test in which employees receive a realistic phishing email. The goal is not to judge employees, but to gain insight into risk behaviour and increase security awareness within the organisation.

Are employees assessed individually?

No. The goal of phishing simulations is awareness and improvement, not assessing individual employees. Results are used to make risks visible and to better tailor training.

Why are phishing simulations important?

Many cyberattacks start with a phishing email, a suspicious link or information shared by employees. Phishing simulations help organisations gain insight into risk behaviour and increase security awareness within the organisation.

How does malware get onto my computer?

In most cases this happens because someone clicks on a link. Sometimes, however, it can be a lot more innocent. A few years ago, for example, malware ran for a while on the news site nu.nl via an advertisement. Clicking on it installed malware demanding ransom because of viewed pornographic content.

How does someone know my password?

Sometimes we also see people receiving an email claiming their systems have been hacked and that the sender knows their password, where the password mentioned in the email is indeed one they actually use.

In such a case your password was probably obtained in a hack of another organisation or institution. There’s little you can do about this either. However, it is of course better not to use the same password everywhere. For more tips on passwords, see our password page.

You can also check on the website Have I Been Pwned whether your email address has ever been leaked in a hack. Examples include LinkedIn, which in 2016 turned out to have leaked 164.000.000 email addresses and passwords, and Dropbox with 68.000.000 email addresses and passwords. More recently, in 2021 Booking.com was in the news, and closer to home the webshop Allekabels, and the list could go on.

Someone is actually sending email from my email address, what is going on?

This can have two causes:

  1. The technical settings of your domain name are not in order, making your domain name easy to spoof. If the technical security of your email systems is also not in order, a forged email can easily get past security. This is the least severe cause and can be fixed simply by activating the correct technical settings.
  2. Someone is actually sending mail using your own email address. That can mean only one thing: you’re dealing with a hack. Contact a professional immediately, change your passwords and preferably set up two-step verification (MFA), which protects your email system much better.

Someone is sending email in my name on the internet, what can I do about it?

In principle, there is nothing you can do about it. Anyone can create an email address and put a fictitious name, or even your company, in the display name. This means your employees or contacts receive an email with, for example, “Ralph Dykstra | B/Focused ICT Services”. However, if we look at the sender address, it’s often quickly recognisable that this is not the real sender, but a hacker trying to fish for information this way.

The advice is therefore: pay close attention and think logically.

I’ve been hacked, do I have to pay ransom to get my data back?

Here the main rule is: prevention is better than cure. Always make sure you have a good backup! If you don’t have one, we do have a challenge. We certainly won’t get the data back quickly. It is then mainly your own choice, although paying ransom is no guarantee that you will actually get your data back.

Getting acquainted · which step suits your organisation?

You will be speaking with Ralph Dykstra

Founder and owner of B/Focused

A conversation of about 30 minutes in which we get to know your organisation and look at the challenges, risks and opportunities in your IT environment.

Advice or a quote? Sales
+31 45 303 0232
Need support? Service desk
+31 45 303 0003