Skip to content
Knowledge base Updated: February 5, 2026

KSC NIS2 — Cyber Hygiene and Phishing: How Should the CISO Build a Security Culture?

Your employees are your first line of defense, but are they ready for a real-world attack? Social engineering simulations are the best way to test their alertness in a safe environment. This is not a

Theoretical cyber security training has its place, but its effectiveness is limited. You can show employees slides with the definition of phishing hundreds of times, but nothing will prepare them for a real-life run-in with the threat as well as a controlled, hands-on exercise. It’s the same principle that governs fire alarm rehearsals - don’t just teach people where the emergency exits are, but regularly practice the evacuation process itself, so that in a moment of real crisis, the response is automatic and instinctive. In the world of cyber security, such a combat exercise is simulated social engineering attacks.

Conducting a controlled phishing campaign within a company, during which we send crafted but secure messages to employees, is one of the most effective tools today for building real resilience. However, for this tool to have the desired effect, it must be used wisely. A poorly planned or poorly communicated campaign can do more harm than good - destroying trust, creating frustration and creating a “culture of blame.” Done well, it becomes an invaluable learning experience that transforms employees from potential victims into an active and vigilant first line of defense.

Shortcuts

What are simulated social engineering attacks and why are they a key component of a security awareness program?

Simulated social engineering attacks are authorized, controlled exercises in which a security team (internal or external) attempts, using social engineering techniques, to get employees to perform a specific, potentially dangerous action. The goal is to verify their level of awareness and resistance to manipulation in a realistic but fully secure environment.

The most common form is phishing simulations, which involve sending crafted emails, but advanced programs include:

  • Smishing: sending fake SMS messages.

  • Vishing: making controlled phone calls in which a tester impersonates an IT employee, for example.

  • USB media attacks: intentionally “losing” infected flash drives on company premises.

They are a key component of the Security Awareness program because, unlike theory, they provide practical experience and measurable data. They allow an objective assessment of what percentage of employees are vulnerable to attack, which departments are most at risk and what types of scenarios are most effective. These data are invaluable indicators (KPIs) for measuring the effectiveness of the overall program and planning further actions.

📚 Read the complete guide: SOC: Security Operations Center - czym jest, jak działa, jak wybrać

In addition to measuring “click-through rates,” what goals should a simulation campaign achieve?

Many companies make the mistake of treating phishing campaigns solely as a test, with the main goal of measuring how many employees “flunked out” by clicking on a link. This is a very narrow and often harmful approach. An effective simulation campaign should pursue much broader, more strategic goals.

Overarching goal: Education, not evaluation. The primary goal of any simulation should be to create an engaging and memorable learning experience. The goal is not to “catch” an employee in a mistake, but to teach them how to avoid similar mistakes in the future.

Other key objectives include:

  • Building “muscle memory.” Regular exercise develops in employees instinctive caution and the habit of critically analyzing any unexpected news.

  • Testing reporting procedures: The campaign is an excellent test not only for employees, but also for the IT department. How many employees, instead of clicking, used the “Report phishing” button? How quickly did the IT department respond to these reports?

  • Collecting data for further analysis: The results of the campaign allow us to identify at-risk groups (e.g., new people, specific departments) and tailor future training to them.

  • Strengthening safety culture: A well-executed campaign, combined with positive communication, shows that the company takes safety seriously and invests in developing the competence of its employees.

How to plan an effective phishing campaign step by step?

A successful campaign requires careful planning. The process can be broken down into several key steps.

  • Define the objectives and get approval: what exactly do you want to achieve? Is this a general test of awareness or a verification of resistance to a specific type of attack (e.g., “fraud on the CEO”)? Present the goals and plan to the board and get formal approval. This is absolutely crucial.

  • Determine the target audience: Is the campaign to cover all employees or only selected departments (e.g., finance, HR)? Start with a smaller, pilot group at first.

  • Select or create a scenario: Based on the target, select or create a realistic phishing message scenario. It should be tailored to the company’s business context. A message about an “invoice problem” will be more credible in the accounting department than in the marketing department.

  • Prepare an educational page (landing page): Design the page that employees will go to when they click on the link. It must clearly and positively inform about the simulation and indicate what should have been paid attention to.

  • Set up the technical aspects: Prepare the domain and server for sending emails, and set up “whitelisting” (whitelisting) on the company’s spam filters to ensure that your simulated message reaches inboxes.

  • Plan communication: Prepare a communication plan before (if overt training) and after the campaign (summary of results, tips).

How do you effectively communicate results to employees and management without creating a “blame culture”?

The way results are communicated is absolutely critical to the success of the entire program. The goal is to motivate learning, not public stigma, which only leads to fear and resentment.

Communication to employees:

  • Focus on the positives: Instead of saying “30% of you clicked,” say “70% of us correctly identified and ignored the attack attempt, plus X number of people proactively reported it - that’s a great result!”.

  • Be anonymous: Never publicly disclose who specifically clicked on a link. Individual results should be treated as confidential information, serving at most to assign a person additional individual micro-training.

  • Use the results to educate: Summarizing the campaign, once again show the anonymized message and point out key “red flags” to reinforce knowledge.

Communication to the board:

  • Present trends, not individual results: Show how the percentage of clicks changes (decreases) over time as successive campaigns are run. This shows the return on investment (ROI).

  • Speak the language of risk: Translate results into specific business risks. “A high click-through rate in the finance department means an increased risk of a successful ‘fraud on the CEO’ attack.”

  • Present an action plan: Always link the presentation of results to a concrete plan for further action (e.g., “we propose to conduct a dedicated workshop for the finance department”).

How to run an effective simulation campaign: Good and bad practices

Best practices (Do this)Bad practices (Avoid it)
Campaign objective: To educate and build “muscle memory.” Treating the campaign as safe exercise.The goal of the campaign: “busting” and shaming employees. Treating the results as a test for credit.
Communication: Transparent, positive and supportive. Obtain board approval and “tone at the top” support.Communication: Lack of communication or communication based on fear. Conducting “surprise” campaigns without leaders’ approval.
Response to “click”: Immediate, contextual feedback on the learning page. Use of “teachable moment”.Reaction to “click”: Lack of any feedback or, worse, public stigmatization and punishment of employees.
Analysis of results: Anonymous, focused on trends and identification of risk groups for follow-up planning.Analysis of results: Creating “lists of shame.” Focusing on individual failures rather than overall progress.

What advanced scenarios, such as BEC or vishing simulations, can be implemented?

Once an organization has mastered the basics and its resistance to simple phishing has increased, the bar should be raised and more advanced scenarios should be tested that better reflect real, targeted attacks.

BEC simulations (“CEO scam”): Instead of a link to a fake site, the message simulates an urgent order from a board member (CEO, CFO) requesting a wire transfer or the return of sensitive data. The purpose of this test is to verify that employees (especially from finance and HR departments) follow “out-of-channel” (out-of-band) verification procedures for such unusual requests.

Vishing (voice phishing) simulations: This is a test of resistance to manipulation over the phone. The tester, playing the role of a bank, technical support or even law enforcement employee, calls selected employees and tries to vish them for information. The goal is to see if the employees can respond assertively and follow a verification procedure (“I’ll hang up and call back the official number myself”).

Spear-phishing simulations: Instead of mass mailing, highly personalized messages are created for a small group of key individuals (e.g., executives), using information gathered about them from open sources (OSINT).

How does nFlo design and execute advanced, multi-vector social engineering campaigns?

At nFlo, we view socio-technical simulations as one of the most important tools in the arsenal of a mature organization. We understand that their effectiveness depends on realism, proper planning and, most importantly, wise use of the results. Our services in this area are comprehensive and always “tailor-made” for the client.

Our team of offensive security experts designs and executes highly realistic attack scenarios that are based on our knowledge of the actual tactics, techniques and procedures (TTPs) of real cybercriminals. We do not use generic, easily recognizable templates. Our campaigns are carefully crafted to reflect the client’s business context and pose a real challenge.

What sets us apart is our ability to perform advanced, multi-vector simulations. In addition to standard phishing campaigns, we also implement vishing (voice attacks), smishing (SMS), and USB media tests. After each campaign, we provide a detailed but fully anonymized report for management, which analyzes trends and identifies areas for improvement. Most importantly, we actively support post-campaign activities by offering dedicated training sessions and workshops for those user groups that have proven most vulnerable.

How to report the result without starting a blame exercise

The fastest way to make a simulation programme unrepeatable is to publish who clicked. People stop reporting suspicious messages, which removes the one signal that actually shortens an incident. The reporting rule that keeps a programme alive is simple: results are aggregated by department, never by name, and the metric that gets celebrated is the report rate rather than the click rate.

That framing — including who may stop a campaign and how the result is presented to management — is part of the scope of phishing simulations.

Learn key terms related to this article in our cybersecurity glossary:

  • Cybersecurity — Cybersecurity is a collection of techniques, processes, and practices used to…
  • Phishing — Phishing is a type of social engineering attack that aims to deceive the victim…
  • Spear Phishing — Spear phishing is an advanced form of phishing in which attackers target…
  • Cybersecurity Incident Management — Cybersecurity incident management is the process of identifying, analyzing,…
  • Social Engineering — Social engineering is a set of psychological manipulation techniques used by…

Learn More

Explore related articles in our knowledge base:


Explore Our Services

Need cybersecurity support? Check out:


See also:

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist