Home › Services › Phishing simulation
Security · people, not only mail filters
A controlled phishing campaign against your own staff, run inside Microsoft Defender so nothing leaves your tenant, with a report of who clicked, who entered a password and who reported it — and then the two things that matter: training for the people who fell for it, and the tenant settings that would have stopped the real one.
Why
Mail filters catch most phishing. The messages that get through are the well-crafted ones: a supplier invoice with new bank details, a “shared document” from a colleague, a Microsoft password-expiry notice. Whether those work depends on people, and you do not know your number until you test it. First campaigns typically see 15–30% of staff click and 5–12% enter a password. After training and a second round, the numbers roughly halve.
Defender for Office 365 Plan 2 licensing confirmed or the 90-day trial activated; allow-listing so the simulation lands; scenarios chosen with you — credential harvest, malicious attachment, link in attachment, OAuth consent. Nobody outside IT and management knows.
Two to three realistic messages, staggered over a week, from lookalike senders. Every open, click, password entry and report-to-IT is recorded. Anyone who clicks lands on a training page immediately, not a shaming page.
A written report by department and scenario; a 45-minute debrief with management; targeted training assigned in Defender to the people who clicked; and a hardening list — the Conditional Access, Safe Links, DMARC and MFA settings that would have blunted the real attack, with prices to implement.
What you get
The report is the thing you keep; the hardening list is the thing that changes the number next time.
Click rate, credential-entry rate and report rate overall and by department, per scenario, with the industry comparison Defender provides. Names are in the appendix for HR and IT only.
Microsoft’s training modules assigned automatically to the people who clicked, tracked to completion. Short, specific to what they fell for, not an annual compliance video.
Ordered by impact: enforce MFA everywhere, Conditional Access for unmanaged devices, Safe Links with click-time scanning, DMARC at reject, external-sender tagging, disabling legacy authentication. Each with a fixed price to implement.
The second campaign, three months later, is the one that shows whether anything changed. We schedule it in the debrief; most clients run one a quarter afterwards on a plan.
Attack simulation training lives in Microsoft Defender for Office 365 Plan 2, and every user who receives the simulated mail needs the licence — not only the administrator. Business Premium and Microsoft 365 E3 include Plan 1, which does not have it; E5 does. Microsoft offers a 90-day Plan 2 trial for the tenant, and that is enough to run the first campaign and the training. If you decide to keep simulating quarterly, Plan 2 is a modest add-on, or the Defender Suite for Business Premium and E3 brings it together with Defender for Endpoint P2 and Entra ID P2. The plan finder prices both →
What we will not do: run a simulation from an outside tool that sends real-looking mail through your filters from the internet. It trains your filters to trust the wrong things, and the results are not comparable to Microsoft’s baseline.
Fixed price
Tell us the headcount and whether you already have Defender for Office 365 Plan 2 or E5. You get a fixed price, a date, and the scenarios list to approve. From €1,200 for up to 100 users; larger tenants and multi-entity groups quoted per scope.
Questions
Only the people you name — usually IT and the executive sponsor. The messages come from lookalike senders and land in normal inboxes. Anyone who clicks sees a training page at once, which is the moment the lesson sticks.
No. Names go to HR and IT in an appendix; the main report is by department and scenario. Training is assigned, not discipline. Companies that shame clickers get fewer reports of real phishing afterwards, which is the opposite of the goal.
Not for the first campaign: Microsoft’s 90-day Plan 2 trial covers it. To simulate quarterly you need Plan 2, the Defender Suite add-on, or E5 for every targeted user.
It usually is the first time: 15–30% is typical. The point is the second campaign after training and hardening, which is where the number drops. The report is a baseline, not a verdict.
Yes. Each tenant is a separate campaign in its own Defender portal; the report is consolidated by entity. Quoted per scope.