Phishing attacks are quick and easy to implement and deliver an enormous return on investment, which has motivated criminals to create increasingly sophisticated and creative phishing ‘lures’.
These are often indistinguishable from genuine emails, text messages or phone calls; in general, affected users don’t report the compromise until it is too late, inflicting enormous damage on your organisation. Senior management need regular assurance that staff have been properly trained on how to spot phishing emails, and the only real way to achieve this is through a simulated phishing attack.
This service is entirely bespoke and will be crafted according to your needs. A typical engagement will comprise the following stages:
Our phishing campaign will be performed before and after training to track improvement.
High-level, non-technical summary of vulnerabilities identified, your business’ risks, and comparison results.
Detailed description of when the assessment was performed, the type of assessment and its objectives.
Details of how the template was designed, what identifies it as a phishing email and supporting web pages.
Overview, consultant’s commentary and anonymised breakdown of the results.
Download the full service description
This test will be performed using IT Governance’s proprietary security testing methodology, which is closely aligned with the SANS, OSSTMM (Open Source Security Testing Methodology Manual) and OWASP (Open Web Application Security Project) methodologies.
This service is suitable for organisations that want to understand their staff’s awareness levels or test the effectiveness of their phishing training.
This simulated phishing attack will establish whether your employees are vulnerable to phishing emails, enabling you to take immediate remedial action to improve your cyber security posture.
Our CREST-certified penetration testing team will perform a simulated phishing attack to determine your organisation’s current susceptibility to this type of attack, identifying the groups of users most at risk.
Embed phishing knowledge quickly and effectively with this short, punchy ten-minute game to test your employees’ knowledge. It covers:
Teach staff how phishing attacks work, the tactics employed by cyber criminals and what to do when they’re targeted. The course covers: