PHISHING SIMULATION

See who would click, before an attacker finds out.

Controlled, recurring phishing campaigns across email, SMS, Teams and voice that measure how your people really behave, teach them at the moment of the mistake, and turn human risk into a number that falls over time.

Design your campaign

A senior consultant replies within one business day.

Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.

Already trusted by

This is how an attacker tries to compromise your team.

Walk through a real phishing email. At each critical point we show the technique the attacker is using, and what we train your people to spot.

Outlook
Home View Help
Inbox 43 unread
  • Notion Eva Riera shared 'Q2 launch: final review' 10:12
  • Slack Daily summary · #eng-platform · 14 messages 10:04
  • John Smith [ URGENT ] New Client details required 09:47
  • Calendly New booking: Tom <> Acme procurement (Fri 14:00) 09:31
  • Atlassian [JIRA-4287] Carla M. moved 'Auth refactor' to In Review 09:18
  • GitHub [northbank/api] Pull request #1442 needs review 09:02
  • Dropbox Sign Document signed: NDA · Stoneridge Capital 08:47
  • AWS Your monthly bill is now available 08:14
  • Eva Riera Re: Friday playback · slides v3 attached 07:55
[ URGENT ] New Client details required
John Smith <john.smith@rnicrosoft.com>
to Tom Hill Thu 29/01/2026 09:47

Hi Tom,

Hope everything is great.

Please we are required you download this PDF so that we can validate the client payment within the next 30 minutes.

Best regards, John

Client.verification.pdf.exe
1.2 MB
01 INBOX

9:47. A normal Thursday inbox.

Forty-three unread. Clients, suppliers, the usual noise.

Why this triggers an alert

This is the moment attackers pick: mid-morning, mid-task. A new email feels like work, not like a threat.

If you don’t always verify, your team may not verify either.

A trained pause is the strongest control any company has, and the cheapest one to install.
READY WHEN YOU ARE

Want to know if your team’s logins are already exposed?

Give us your corporate domain and we will run an initial exposure check across the dark web and open sources: leaked credentials, brand and domain mentions, and stealer-log hits, the raw material for targeted phishing against your people.

Why this matters.

Phishing is not a training box to tick. These are the numbers behind the risk your people carry every day, and what a recurring programme does to them.

62%
of breaches involve a human element, not just a technical flaw
Verizon 2026 DBIR
~1 in 6
breaches is a social engineering breach, and phishing is its main technique
Verizon 2026 DBIR
~1 in 3
employees clicks a phishing email before any training
33.1% baseline, KnowBe4 2025
up to 75%
fewer clicks after a year of monthly simulations
SANS 2025

Email is just the start. We also run vishing calls, smishing texts, QR-bait posters, calendar-invite phishing and AI assistant impersonation. If your team uses it daily, we can weaponise it.

PHISHING AS A SERVICE

Phishing as a Service: simulate, measure, improve

Not a one-off test. A recurring programme that measures how your people really behave, teaches them at the moment of the mistake, and keeps human risk in view.

Microsoft 365 Security 09:47
<no-reply@rnicrosoft.com>

Action required: your password expires today

Hi user, your Microsoft 365 password expires in two hours. Click below to keep your access. You have until 11:47 to confirm.

Microsoft 365 Security Team
ASPERIS · TRAINING MOMENT

That was a phishing simulation. Here’s what to notice next time.

No score, no leaderboard, no email to your manager. Take thirty seconds, then go back to your inbox.

Three signals in this email:
  • 01
    Sender rnicrosoft.com, not an "m". It is an "r" followed by an "n", which draw one at a glance.
  • 02
    Greeting "Hi user": real Microsoft 365 mail uses your display name.
  • 03
    Pressure "expires in two hours", "until 11:47": urgency is a common tactic.
An employee receives a lure built to look like real Microsoft 365. They click, and that’s where most awareness programmes stop.
The same screen flips into a thirty-second debrief. Three signals are highlighted instantly.
01

Tailored campaigns

Scenarios built for your sector, brand and context, from mass phishing to spear phishing aimed at C-level, finance, IT and HR.

02

Every channel attackers use

Email, SMS (smishing), corporate chat (Teams, Slack) and voice (vishing). Not just the inbox.

03

Teaching at the moment of the mistake

Anyone who falls gets instant feedback: the signs they missed and what to do next time, when they are most receptive to learning.

04

Metrics that mean something

A dashboard of opens, clicks, credentials submitted, attachments opened and reports, segmented by department, location and risk profile.

05

A continuous programme

Recurring campaigns with rising difficulty, so you see real improvement over time and scenarios that adapt to your results.

06

Inside your Asperis platform

Every campaign sits alongside your other offensive-security results, for one view of technical and human risk.

Loved by security teams.

At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive. We especially value their ability to adapt to our needs and the depth with which they approach each project. Results are clear, structured and useful for decision-making and continuous security improvement. We like working with Asperis for the judgment and value they bring to every collaboration. Their work has helped us strengthen our security level.
Sergi Laencina Verdaguer, CISO
NPAW
ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives. Thanks to their advice, we took the strategic step of completing our Microsoft ecosystem and reinforcing it with CrowdStrike for advanced mobile device protection, significantly raising our security level.
Jordi Bondia, IT Director
SALVI
With Asperis you don’t hire a service. You hire a partner. They don’t look to bill a project. They look to establish a relationship of trust, caring about the key points that affect your organisation’s security. Professionalism, know-how and diligence.
Juan Valer Tecedor, Software Engineer
GNOSS

Frequently asked questions

If we haven’t covered yours, ask in the introductory meeting. Most answers are decided in fifteen minutes.

A phishing simulation is a controlled, authorised exercise that sends realistic fake phishing to your own staff to see who clicks, submits credentials or reports it, then trains them on the spot. It measures real behaviour rather than knowledge, which is what actually predicts risk.

We design scenarios for your context, send them across the channels attackers use, and record what each person does: open, click, submit or report. Anyone who falls gets immediate feedback, and you get segmented metrics and a trend line across recurring campaigns.

Yes, when it is authorised, controlled and handled with care, which is how we run it. Campaigns are agreed with you in advance, comply with GDPR, and are designed to teach, not to shame; results are used to prioritise training, never to punish individuals.

Smishing is phishing by SMS or text message, and vishing is phishing by phone call. Attackers use both alongside email, so we simulate all of them, plus corporate chat like Teams and Slack, to test every channel your people can be reached on.

Regularly, not once a year. A recurring programme, typically monthly, drives far larger and more durable reductions in click rate than annual training, because behaviour change comes from repeated, realistic practice.

Yes, when run as a continuous programme. Independent benchmarks show click rates falling sharply over a year of regular simulations, and because we measure open, click, submission and reporting rates, you can see the reduction in your own numbers rather than take it on faith.

Want to measure the real awareness level of your team?

Book a free 30-minute call. We will look at your current situation, design a scenario tailored to your organisation, and show you how the reporting platform works.

  • Real-world lure design based on threat intelligence.
  • Detailed reporting on employee behaviour and awareness gaps.
  • Remediation recommendations tied to training outcomes.
Request an initial simulation
Reply within one business day. Senior consultant on the call.

Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.

Or email [email protected] directly. A senior specialist replies.