Get a phishing test and awareness measurement
Do you know what happens when a phishing email gets through your spam filter? What percentage of employees clicks, enters credentials or reports the incident? Does your compliance officer require demonstrable implementation of article 21(2)(g) Dutch Cybersecurity Act? For these situations a controlled phishing simulation provides concrete, measurable validation of the human layer of your security.
DongIT performs phishing simulations tailored to your sector, risk profile and organization size. From classic credential phishing to modern variants such as spear phishing, MFA fatigue and Business Email Compromise. Findings are mapped to NIS2 article 21, ISO 27001 Annex A.6.3 and NCSC awareness guidelines so your reporting is directly usable for internal reporting and external audits.
Our phishing tests are performed by OSCP-certified ethical hackers who see modern attack techniques daily. Reporting via our self-developed Security Reporter platform. CCV Keurmerk-accredited. Data stays in Europe. Delivery per Works Council guidelines and GDPR.
Which phishing scenarios do we test?
Phishing is not what it was ten years ago. Modern attackers combine psychology, technique and current context. Our simulations cover the full spectrum of contemporary phishing variants, tailored to what your employees can actually encounter.
- Credential phishing. Cloned login pages of your own SSO portal, Microsoft 365, cloud environment or bank site. Measuring whether employees enter their password on unfamiliar URLs.
- Spear phishing. Targeted campaigns on specific departments or individuals with company-specific context from public sources (LinkedIn, annual reports, news articles).
- Business Email Compromise (BEC). CEO fraud, invoice fraud and supplier impersonation. Often without links or attachments, purely text-based social engineering.
- MFA fatigue and OAuth phishing. Modern attack techniques that bypass classic MFA through repeated push notifications or consent to malicious OAuth apps.
- Attachment phishing. Emails with malicious documents (Excel macros, HTML smuggling, ISO containers) that attempt to bypass your endpoint security.
- Vishing and smishing. Phone-based social engineering and SMS phishing as a supplement to email simulations, for organizations with elevated risk profiles.
Per scenario we measure clicks, credential entry, attachment opens, reports to IT security and time to detection. Results are analyzed by department, job function and attack type so your awareness strategy can be sharpened in a targeted way.
Why a phishing test for your organization?
Phishing is responsible for more than 80% of all successful cyberattacks that begin with initial access. Ransomware campaigns, personal data breaches and Business Email Compromise almost all start with a click on the wrong link. For Dutch organizations there are three concrete reasons to make awareness demonstrable:
NIS2 obligation
Article 21(2)(g) Dutch Cybersecurity Act requires "basic cyber hygiene and cybersecurity training". A measured phishing simulation is the most concrete implementation. Actively enforced by RDI from 15 August 2026.
ISO 27001 requirement
Annex A.6.3 requires "information security awareness, education and training". Measurable phishing simulations deliver demonstrable evidence for your ISMS and external audit.
Cyber insurance
An increasing number of cyber insurers require annual awareness measurements as a condition for coverage, especially after claim incidents. Structured reporting meets these requirements.
Beyond compliance there is a concrete operational benefit: organizations that perform annual phishing simulations typically see click rates drop from 25% to less than 5% within two years. The investment in awareness usually pays for itself with the first incident prevented.
Why choose DongIT for your phishing test
A phishing simulation must be realistic without becoming disruptive. Without legal risks, without unnecessary stress for employees and with clear learning objectives. Our approach is tailored to what works in Dutch organizations.
- Works Council-compliant. We support with Works Council consent and legal parameters. What is allowed, what is not and how to communicate about it.
- GDPR-compliant. Employee data is reported in aggregated form, no individual shaming reports. Ethical and compliant.
- CCV Keurmerk Pentesten. Independent accreditation that safeguards quality and methodology. For your compliance reporting an additional quality indicator.
- Realistic and current. Our scenarios are based on attacks we see daily in pentest engagements, not ten-year-old templates.
- Immediate learning moments. Employees who click receive an educational landing page directly, no "gotcha" but concrete tips.
- Data stays in Europe. Simulation infrastructure and reporting platform run on European hosting, no US clouds.
Our approach: from intake to awareness report
Every phishing engagement starts with a thorough intake and ends with an actionable report and concrete next steps. We follow a structured approach aligned with how internal security teams and compliance officers work.
Intake and scenario design
We jointly determine target groups, scenario types (credential, BEC, MFA fatigue), tone of voice and desired level of realism. We also help arrange Works Council consent and internal communication.
Baseline measurement
For a first phishing engagement we perform a baseline measurement without announcement. This provides a realistic picture of the current awareness level, which later serves as a comparison point.
Simulation execution
Simulated phishing campaigns are sent through our controlled infrastructure. We monitor in real time for clicks, credential entry, attachment opens and reports to IT security.
Educational intervention
Employees who click are directed to an educational landing page with concrete tips. No shaming, only constructive learning moments for those involved.
Reporting and analysis
Delivery via Security Reporter. Metrics by department, job function and attack type, mapped to NIS2 and ISO 27001 requirements. Executive summary for management, technical details for security teams.
Follow-up advice and awareness training
Concrete recommendations for awareness programs, technical measures (email gateway settings, MFA hardening) and measurable objectives for subsequent measurements.
Phishing test combined with pentesting
Phishing simulations reach their maximum value in combination with technical pentesting. Credentials obtained from a successful phishing show what a real attacker could do with that access. A few combinations we have experience with:
Phishing and network pentest
Obtained credentials are used for assumed breach scenarios on your internal network. Realistic impact measurement of "what if someone clicks".
Phishing and Entra ID audit
Post-phishing testing for MFA bypass, OAuth app scopes and Conditional Access. Concrete validation of your M365 security configuration.
Phishing and NIS2 audit
Awareness measurement as part of broader NIS2 reporting. Direct link to article 21(2)(g).
Phishing and ISO 27001 audit
Demonstrable evidence for Annex A.6.3 (awareness) and A.5.10 (acceptable use). Directly usable for your ISMS.
Phishing and BIO2
For Dutch government organizations: awareness measurements as part of BIO2 reporting, directly usable for your ENSIA cycle.
Recurring measurements
Annual or biannual measurements to demonstrate progress. Most valuable for NIS2 oversight and cyber insurer requirements.
What does a phishing test cost?
Phishing simulations are always scoped bespoke because costs depend heavily on organization size, number of scenarios, frequency and legal preparation. Unlike our standard pentest packages, phishing engagements have their own cost structure.
What determines the price:
- Number of employees in scope
- Number and complexity of scenarios per measurement
- Frequency (one-off, biannual, annual)
- Works Council coordination and legal preparation
- Combination with pentesting (network, Entra ID)
For recurring annual engagements or combination with pentesting, more favorable rates apply.
Scoping conversation as start
For every phishing engagement we start with a complimentary scoping conversation covering your goals, target groups and legal parameters. We deliver a concrete tailored quotation within three business days.
Frequently asked questions about phishing testing
Below are the most frequently asked questions about phishing simulations and awareness measurements. For a complete overview please visit our FAQ page.
Is a phishing test legally permitted?
Yes. Phishing simulations are permitted provided you respect the correct legal parameters. In the Netherlands this typically requires Works Council consent, transparency toward employees about the fact that awareness measurements take place (not necessarily the exact timing), and GDPR-compliant processing of measurement data. We support you with setting this up correctly.
Do employees need to be informed in advance?
Employees must generally know that periodic phishing simulations take place, for example via the employee handbook or security policy. They do not need to know the specific campaigns in advance. This is a balance between realistic measurement and employee rights.
Do individual employees receive penalties or consequences?
No. Our reporting is deliberately aggregated by department or job function, not by individual. Employees who click receive an educational landing page with tips, no penalties. We explicitly advise organizations not to use phishing measurements for performance evaluations.
What is a good click rate?
For a first unannounced measurement, 15-30% click rate is typical, depending on sector and organization size. After a year of repeated measurements and targeted training, we typically see a drop to 3-8%. Under 5% after two years is a good goal for most organizations.
How often should I perform phishing tests?
For NIS2 and ISO 27001 we recommend at least annually, with interim sample measurements each quarter. For organizations with elevated risk profiles (financial, healthcare, government) monthly frequency can be valuable to maintain awareness.
Can you also provide awareness training?
Our focus is technical simulation and measurement. For comprehensive awareness programs we work with partners offering e-learning platforms, gamification and train-the-trainer. Based on our measurement results we advise which training is most effective for your specific situation.
What if real phishing arrives during our simulation?
Our simulations are clearly marked in the logging of your email gateway so your security team can distinguish them from real incidents. When real phishing is reported by employees or detected by tooling during the simulation period, your team can take immediate action without confusion.
How long does a phishing test take?
Preparation time is typically 2-3 weeks (including Works Council coordination). Execution itself can vary from one campaign over a few days to a campaign series over 2-4 weeks. Reporting follows within one week after completion. Total duration 5-8 weeks.
Ready to make your awareness demonstrable?
Preparing for NIS2, ISO 27001 or a cyber insurer audit? Want concrete insight into how your employees respond to modern phishing techniques? We start with a complimentary scoping conversation covering your goals, target groups and legal parameters. Response within one business day. Quotation within three business days.
Nederlands