Kellner Simora Internasional

PHISHING SIMULATION & AWARENESS SERVICES

Phishing Simulation is a controlled, authorized exercise: we send realistic — but completely harmless — phishing emails to your staff, then safely measure who opens, who clicks, who submits credentials, and who reports it. It is a fire drill, not a fire — turning an invisible, unmeasured human risk into clear data you can act on, before a real attacker runs the same test without your permission.

 

More than 90% of breaches begin with a person being deceived — not a system being cracked; Google and Facebook lost US$121 million to convincing fake-vendor emails, and Twitter’s 2020 breach began with a single phone call. A single click can bypass firewalls, encryption, MFA, and ISO-documented processes. ISO 27001 Annex A (People Controls, A.6.3) requires security awareness — a phishing simulation is how you prove those controls actually work, with evidence rather than assumptions. Every engagement is built on four principles:

  • Safe & Controlled — fully authorized, with no real damage to systems, data, or people.
  • Realistic Lures — modelled on the exact tactics real attackers use today.
  • Measurable — human behaviour becomes concrete, trackable metrics.
  • No-Blame — designed to teach and build habits, never to punish.

Our Six-Phase Engagement Methodology

Kellner Simora Internasional delivers phishing simulation as a full cycle — assess, train, and re-test — aligned with ISO 27001 and Indonesia’s PDP Law:

  • Scoping & Planning — define targets, rules of engagement, and success metrics.
  • Baseline Simulation — launch a first campaign to capture an honest starting point.
  • Campaign Execution — run varied lures, mass and spear, across the organisation.
  • Analysis & Metrics — measure open, click, submit, and report rates by department.
  • Awareness Training — debrief and coach staff with a live session and training deck.
  • Re-test & Improve — re-run to prove improvement and embed a security culture.

The Attack Scenarios We Simulate

  • Mass Phishing (broad, high volume) — wide-net lures such as password reset and account expiry notices, Microsoft 365 re-verification, package delivery notifications, and HR benefits or payroll updates — testing everyday vigilance across the whole organisation.
  • Spear Phishing (targeted, researched) — tailored lures crafted from real details, such as CEO or finance urgent wire requests (BEC), IT security alerts, executive meeting invitations, and trusted vendor invoices — testing your highest-value, highest-risk people.

Deliverables & the Metrics That Matter

Every engagement produces a baseline risk report with open, click, submit, and report rates; a departmental heatmap showing exactly where to focus; a board-ready executive summary; a live awareness session with training deck; a prioritised remediation roadmap; and compliance evidence mapped to ISO 27001 and PDP Law controls.

 

The number we care about most is the report rate: one employee reporting a suspicious email can stop an attack for the entire company. Regular, professional phishing simulation demonstrates a strong commitment to cybersecurity — and strengthens the one layer no technology can protect: your human firewall.

Get a Quote

Get A Quote