20+ years with Microsoft 1,100+ organisations under management 131 countries invoiced locally 4 of 6 Solutions Partner designations 4-hour first response
IT Partner.Microsoft Solutions Partner +44 20 8142 5752 Talk to us Get a quote

HomeServices › Phishing simulation

Security · people, not only mail filters

Phishing simulation: find out who clicks before an attacker does

A controlled phishing campaign against your own staff, run inside Microsoft Defender so nothing leaves your tenant, with a report of who clicked, who entered a password and who reported it — and then the two things that matter: training for the people who fell for it, and the tenant settings that would have stopped the real one.

PriceFrom €1,200 / £1,000 / $1,300
IncludesCampaign, report, debrief, hardening list
Duration3 weeks end to end
LicenceDefender for Office 365 P2 — 90-day trial is enough

Why

Most breaches start with one click, and the click rate is measurable

Mail filters catch most phishing. The messages that get through are the well-crafted ones: a supplier invoice with new bank details, a “shared document” from a colleague, a Microsoft password-expiry notice. Whether those work depends on people, and you do not know your number until you test it. First campaigns typically see 15–30% of staff click and 5–12% enter a password. After training and a second round, the numbers roughly halve.

Week 1 — set-up and baseline

Defender for Office 365 Plan 2 licensing confirmed or the 90-day trial activated; allow-listing so the simulation lands; scenarios chosen with you — credential harvest, malicious attachment, link in attachment, OAuth consent. Nobody outside IT and management knows.

Week 2 — the campaign

Two to three realistic messages, staggered over a week, from lookalike senders. Every open, click, password entry and report-to-IT is recorded. Anyone who clicks lands on a training page immediately, not a shaming page.

Week 3 — report, training, hardening

A written report by department and scenario; a 45-minute debrief with management; targeted training assigned in Defender to the people who clicked; and a hardening list — the Conditional Access, Safe Links, DMARC and MFA settings that would have blunted the real attack, with prices to implement.

What you get

Four deliverables, one of which is a number

The report is the thing you keep; the hardening list is the thing that changes the number next time.

The report

Click rate, credential-entry rate and report rate overall and by department, per scenario, with the industry comparison Defender provides. Names are in the appendix for HR and IT only.

Targeted training

Microsoft’s training modules assigned automatically to the people who clicked, tracked to completion. Short, specific to what they fell for, not an annual compliance video.

The hardening list

Ordered by impact: enforce MFA everywhere, Conditional Access for unmanaged devices, Safe Links with click-time scanning, DMARC at reject, external-sender tagging, disabling legacy authentication. Each with a fixed price to implement.

A repeat date

The second campaign, three months later, is the one that shows whether anything changed. We schedule it in the debrief; most clients run one a quarter afterwards on a plan.

Licensing

What licences it needs, and why you may not need to buy any

Attack simulation training lives in Microsoft Defender for Office 365 Plan 2, and every user who receives the simulated mail needs the licence — not only the administrator. Business Premium and Microsoft 365 E3 include Plan 1, which does not have it; E5 does. Microsoft offers a 90-day Plan 2 trial for the tenant, and that is enough to run the first campaign and the training. If you decide to keep simulating quarterly, Plan 2 is a modest add-on, or the Defender Suite for Business Premium and E3 brings it together with Defender for Endpoint P2 and Entra ID P2. The plan finder prices both →

What we will not do: run a simulation from an outside tool that sends real-looking mail through your filters from the internet. It trains your filters to trust the wrong things, and the results are not comparable to Microsoft’s baseline.

Fixed price

Book a simulation

Tell us the headcount and whether you already have Defender for Office 365 Plan 2 or E5. You get a fixed price, a date, and the scenarios list to approve. From €1,200 for up to 100 users; larger tenants and multi-entity groups quoted per scope.

Questions

Asked before booking

Will staff know it is a test?

Only the people you name — usually IT and the executive sponsor. The messages come from lookalike senders and land in normal inboxes. Anyone who clicks sees a training page at once, which is the moment the lesson sticks.

Does it punish people?

No. Names go to HR and IT in an appendix; the main report is by department and scenario. Training is assigned, not discipline. Companies that shame clickers get fewer reports of real phishing afterwards, which is the opposite of the goal.

Do we need to buy Defender for Office 365 Plan 2 first?

Not for the first campaign: Microsoft’s 90-day Plan 2 trial covers it. To simulate quarterly you need Plan 2, the Defender Suite add-on, or E5 for every targeted user.

What if the click rate is high?

It usually is the first time: 15–30% is typical. The point is the second campaign after training and hardening, which is where the number drops. The report is a baseline, not a verdict.

Can you run it across several tenants or entities?

Yes. Each tenant is a separate campaign in its own Defender portal; the report is consolidated by entity. Quoted per scope.