PHISHING
AWARENESS

 

Train your people to recognize phishing

Phishing is the most prevalent social engineering attack that virtually every organization comes in to contact with. It is one of the biggest cybersecurity risks. That’s why it is vital to understand how your workforce handles real life phishing attacks, and improve the detection and reporting rate. Let Security Innovation help you.

 

Your challenges

• How to keep your organization alert to phishing
• How to test and simulate the latest phishing tricks
• How to train to report phishing incidents

HOW WE SUPPORT YOU

 

 

E-MAIL PHISHING SIMULATION

We conduct phishing attempts on your employees through email messages and email attachments.

VOICE PHISHING

Our ethical social engineers call some of your employees, pretending to be from a trusted organization. They attempt to extract sensitive information over the phone by using urgency and fear tactics commonly employed by criminal attackers.

We also utilize voice cloning to make the voice sound like someone familiar.

You will receive anonymized video footage of the investigation, which you can use to train other employees. This is an effective learning method.

QR PHISHING

Scammers use fake QR codes to steal personal information or install malware. We distribute QR codes within your organization to assess how likely your employees are to scan them.

USB PHISHING

In USB phishing, criminals leave a USB stick with malware in your company or give it away. We simulate this to test how likely employees are to insert an unknown USB stick into their computer.

SMS PHISHING

SMS phishing is on the rise and becoming increasingly sophisticated. We send your employees fake SMS or chat messages containing a sense of urgency and a link. This allows us to test how likely your employees are to click on the link and share personal information.

CALL-BACK PHISHING

Callback phishing is a trending scam tactic. We send an email to your employees with a request to call back.

Customized approach

Depending on your needs, we tailor our phishing approach:

  • Broad phishing attempt targeting all employees with standardized scenarios for training and awareness purposes. This type is particularly effective for measuring the progress of awareness campaigns over time.
  • Targeted spearphishing attempt aimed at obtaining employee login credentials. The scenarios are based on OSINT (Open Source Intelligence) data collected about your organization and employees. This type of phishing service simulates a real attacker specifically targeting your organization.
  • Customized phishing specifically tailored to your requirements. For example, phishing with malicious office documents to mimic real Advanced Persistent Threat groups or ransomware infection vectors.

I’D LIKE TO LEARN MORE ABOUT THE PHISHING AWARENESS PROGRAM

Would you like to learn more about our Phishing Awareness Program? Please fill out the form below and we will contact you within one business day.