3-second decision
Under time pressure, gut instinct decides - not the knowledge from the last e-learning module. Phishing emails strike exactly at that moment.
Phishing Simulation
Find out how vulnerable your organisation is to social engineering. Tailored campaigns or a managed platform - we measure what e-learning modules cannot show.
The Problem
Compliance training conveys knowledge - but does not change behaviour. Only employees tested under realistic conditions learn to spot the difference.
Under time pressure, gut instinct decides - not the knowledge from the last e-learning module. Phishing emails strike exactly at that moment.
Employees who pass every training course with 100% still click on phishing emails. Only a realistic simulation reveals the true picture.
The average cost of a data breach (IBM). A regular phishing simulation is the most cost-effective prevention measure available.
Real-world example
This realistic mock-up shows the typical warning signs in a phishing email. Watch as the 5 most common red flags are revealed step by step - exactly how we test your employees.
im Rahmen unserer routinemäßigen Sicherheitsüberprüfung haben wir ungewöhnliche Aktivitäten in Ihrem Online-Banking-Konto festgestellt. Zum Schutz Ihrer Daten haben wir den Zugang zu Ihrem Konto vorübergehend eingeschränkt.
Mit freundlichen Grüßen
Thomas Weber
Abteilung Kontosicherheit
Deutsche Kredit Bank AG
Diese E-Mail wurde automatisch generiert. Bitte antworten Sie nicht auf diese Nachricht.
Deutsche Kredit Bank AG | Taunusanlage 12 | 60325 Frankfurt am Main
Spot the 5 warning signs
The display name says "Deutsche Kredit Bank AG", but the actual address is service@dk-bank-sicherheit.com: a foreign domain with no relation to the bank.
Your real bank knows your name. "Sehr geehrter Kunde" ("Dear customer") signals a mass phishing campaign sent to thousands of recipients.
"Within 24 hours" plus an account-suspension threat: a classic panic tactic. Legitimate companies never set deadlines this short via email.
The button promises the official site, but the real URL is dk-bank-sicherheit.com/verify: a phishing domain. Always check the link target!
No legitimate company asks you to enter passwords, TANs or credit card details via email. Never log in through email links.
Click or hover the numbered warning signs in the email.
Two models
Choose between personal support from our social engineering experts or a self-service managed platform. If you would rather evaluate the software side first, our comparison of the 12 best phishing simulation tools shows what open-source options can do - and where their limits are.
Recommended Manual Phishing SimulationPersonal support from our experts | Managed Managed Phishing PlatformSelf-service platform via phished.io | |
|---|---|---|
| Included |
|
|
| From €3,000 per campaign | Available as a monthly retainer |
Not sure which model fits? Free consultation in 15 minutes.
Attack scenarios
Every scenario is individually tailored to your organisation - from the sender address to the pretext:
Business Email Compromise · Wire Fraud
Spoofed instructions from senior management. Test whether your finance team responds to fraudulent wire transfer requests.
Fake Login · M365 Phishing
Fake login pages for Microsoft 365, VPN portals or internal tools. How many employees enter their credentials?
Payload Delivery · Macro Documents
Fake invoices, applications or supplier emails with simulated malicious attachments - without any real risk.
Quishing · Physical Vector
Manipulated QR codes on posters, in meeting rooms or on business cards. We also test physical attack vectors.
OSINT · Targeted Attack
Highly personalised attacks on specific individuals or departments - with OSINT research and tailored pretexts.
We develop industry-specific scenarios to your specifications.
Comparison
Both models have their strengths. The ideal solution? Often a combination - manual baseline test, then managed for ongoing operations.
| Manual Simulation | Managed Platform | |
|---|---|---|
| Scenarios | Individually handcrafted | Hundreds of ready-made templates |
| Support | Dedicated point of contact | Self-service + support |
| Frequency | 1-4x per year | Continuous / automated |
| Languages | German & English | 30+ languages |
| Reporting | Management report as PDF | Real-time dashboard |
| Ideal for | Baseline & deep-dive test | Ongoing operations & measurement |
Maximum impact? Manual baseline test + managed retainer for ongoing operations.
How it works
Together we define target groups, scenarios and success metrics. Which departments will be tested? Which attack scenarios are realistic for your organisation?
Our social engineering experts develop tailored phishing emails, landing pages and pretexting scenarios - aligned to your company structure and industry.
The campaign is rolled out and monitored in real time. We capture open rates, click rates, credential entry rates and reporting rates.
Detailed results report with benchmarks, department comparisons, risk assessment and concrete recommendations for action.
On request, we support you with regular follow-up campaigns. Security awareness is not a one-off project - it is a continuous process.
GDPR & Compliance
Phishing simulations involve personal data - which is why GDPR compliance is not an afterthought for us, but a core component of every campaign.
Anonymised
Anonymised evaluation
Results at department level only
Works council
Works council-ready
Pre-coordination with works council & DPO
Privacy
No individual exposure
Individuals are never identified
Germany
Data stored in Germany
Infrastructure on German servers
References
These case studies are available in German.
Related services
Simulations have the greatest impact when combined with other measures:
Kick-off before the simulation - your employees experience live how attackers operate.
Details 02Gamified security training - employees solve security challenges in a fun, competitive format.
Details 03Test the technical side - our pentesters find vulnerabilities in your systems.
DetailsWhy organisations trust AWARE7
Pure awareness platforms don't test systems. Pure consulting firms are too far removed. AWARE7 combines both: we hack your infrastructure and train your employees: tailored to mid-sized companies, personal, without enterprise overhead.
Around 20% of our revenue comes from research projects for the BSI and the BMBF. Our studies, published at ACM and Springer conferences, analyse millions of websites and tens of thousands of phishing emails. Three of our executives are professors at German universities at the same time.
From first contact to final report, your data is stored on our own servers in Germany - no US cloud providers, no third-country transfers. Our AI also runs on our own hardware in Germany - with locally operated open-source models. Client and project data never reach external AI services. All staff are permanently employed, covered by social insurance and bound by uniform legal obligations.
More on digital sovereigntyWithin 24 hours you receive a binding fixed-price quote without hourly rate risk. A well-practised team and standardised processes ensure a clear schedule with a defined start and end date.
A personal project manager accompanies you from the first meeting to the retest. You book appointments directly with your contact person and keep the same contact throughout the project.
Peer-reviewed publications
Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations
ACM AsiaCCS 2025
Oskar Braun, Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
A Platform for Physiological and Behavioral Security
NSPW 2025
Jan Hörnemann
Privacy from 5 PM to 6 AM: Tracking and Transparency in the HbbTV Ecosystem
IEEE/IFIP DSN 2025
Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
Understanding Regional Filter Lists: Efficacy and Impact
PoPETS 2025
Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
Who is AWARE7 the right partner for?
Mid-sized companies with 50-2,000 employees
Companies that need real security, without paying for a DAX-corporation provider. Fixed price, clear scope, one point of contact.
IT managers & CISOs
Who have to argue convincingly in-house and need a report in boardroom language for that, not just technical findings.
Regulated industries
Critical infrastructure, healthcare, financial services: NIS-2, ISO 27001, DORA. We know the requirements and deliver evidence that auditors accept.
Organisations that rely on AWARE7 phishing simulations
Your phishing experts
Our social engineering specialists develop realistic campaigns for your organisation.
Target groups
Phishing attacks target every industry and every level of the hierarchy. These groups benefit most.
Every employee is a potential entry point. Broad campaigns show where the greatest risks lie within the organisation - cross-departmental and reported anonymously.
CEO fraud and Business Email Compromise target decision-makers directly. Spear phishing scenarios with personalised context test exactly the attack vectors most commonly used at executive level.
Accounting and HR manage sensitive data and payment approvals. Attackers use fake invoices, IBAN changes and malware-laden job applications. Targeted scenarios for these departments are particularly effective.
Even IT professionals are not immune to social engineering. Technically sophisticated attacks - such as fake support requests, vendor impersonation or manipulated update links - test security behaviour exactly where privileged access is managed.
The NIS-2 Directive requires technical and organisational measures to demonstrate attack resilience. Regular phishing simulations are a verifiable component of an ISMS and support compliance documentation with supervisory authorities.
Companies that have already been targeted have a particular need for action. A post-incident simulation analyses which gaps exist in the human security layer - and provides the foundation for a targeted training programme for lasting improvement.
“We thought our employees knew what phishing looks like. The simulation by AWARE7 proved us wrong - and in a way that does not single anyone out, but creates lasting awareness. Three months later, we had halved the click rate.”
Frequently asked questions
Aus dem Blog
Phishing erkennen: Checkliste mit Erkennungsmerkmalen für E-Mail-Phishing, Smishing und Vishing - mit Sofortmaßnahmen nach dem Klick.
Security Awareness messen: Phishing-Klickraten richtig interpretieren, Verhaltensmetriken, Wissenstests und ROI-Argumente für den Vorstand.
Ein Live Hacking ist eine gute Möglichkeit, Mitarbeiter zu sensibilisieren - doch was kostet ein Live Hacking?
Find out - with a professional simulation. We will provide you with an individual quote within 24 hours. Free and non-binding.
Free · 30 minutes · No obligation
Arturs Nikitins
Initial consultation & needs analysis
Looking for personal advice?
No obligation · Reply within 24h on business days