Whether your team can be tricked

Most breaches start with a person, not a server. A simulated phishing exercise shows whether realistic approaches can fool your team — and turns the result into training.

A brushed steel envelope with a glass fish hook resting on its seal

In short

Most breaches start with a person, not a server. A simulated phishing and social-engineering exercise shows whether realistic approaches get through, and turns the result into targeted training instead of blame. Verizon's 2026 report puts the human element in 62% of breaches, and 41% of social-engineering attacks now arrive somewhere other than email.

Most breaches start with a person, not a server. Verizon's 2026 Data Breach Investigations Report attributes 62% of breaches to the human element, and phishing alone accounts for 16% of initial access. A convincing email or a well-judged phone call remains the easiest way past good technical defences.

A simulated phishing and social-engineering exercise answers a question no firewall can: if someone tried this on your team next Tuesday, what would happen?

What the exercise actually involves

We agree the scope with you first, then run realistic approaches against your staff over an agreed window. That usually means a mix of:

  • Email phishing, using pretexts drawn from your real suppliers, systems and internal language rather than generic templates
  • Voice and SMS approaches, where the caller has done their homework on your org chart

Everything is authorised, logged and reversible. Nobody's credentials are used to reach real data. The output is a measurement, not a stunt.

Email is no longer the whole picture

This is the finding most businesses have not caught up with. 41% of social-engineering breaches now involve vectors other than email, and roughly a quarter arrive through social media or the phone.

The 2026 simulation data makes the point sharply. Median click rates on simulated email phishing sit at about 1.4%. For phone-based approaches the figure is 2%, a gap of roughly 40%. Your team is measurably more likely to be caught by a phone call than by an email, and almost all awareness training is built around the inbox.

Testing only email tells you about the channel your staff have already been trained on. Testing voice and SMS tells you about the one they have not.

Why AI has changed the economics

The old advice was to look for bad spelling and odd formatting. That advice is now actively harmful, because it teaches people to trust anything well written.

Attackers use AI to analyse a company's tone and mimic the vocabulary of its industry, producing correspondence indistinguishable from the genuine article. The tell is no longer the writing. It is the request: an unexpected urgency, a change of bank details, a login prompt that arrived at an odd moment.

Good simulation reflects this. If the test emails are obviously fake, the pass rate is meaningless.

What you get back

A report that leads with the numbers that matter to you:

  • How many people received each approach, how many engaged, and how many reported it
  • Time to first report, which is often the single most useful figure. A team that clicks but reports in four minutes is in far better shape than one that never clicks and never reports.
  • Which pretexts worked, and which departments or roles were most exposed
  • A prioritised set of fixes, split between training and technical controls

That last split matters. Some findings are training problems. Others are configuration problems that no amount of training will fix, such as external mail not being clearly marked, or multi-factor authentication missing on an account that should never have been without it.

Turning the result into training, not blame

The fastest way to make a business less safe is to publish a list of who clicked. People stop reporting, because reporting becomes an admission.

We report by group rather than by individual, and we frame the outcome around the reporting rate rather than the click rate. The goal is a team that treats an odd request as something to flag rather than something to be embarrassed about.

Repeating the exercise is what shows movement. A single test is a snapshot. Two or three across a year show whether the training landed.

Where it fits with everything else

Social-engineering testing sits alongside the technical work rather than replacing it. Penetration testing and vulnerability scanning tells you what an attacker could reach; this tells you whether they would need to bother.

For businesses working toward NIS2, it also feeds directly into the awareness and training obligations under Article 21. Ireland's National Cyber Security Centre published guidance for boards and senior executives in July 2026, and the direction of travel is clear: human risk is now a governance item, not an IT one.

Is it worth doing?

Irish SMEs lose up to €3.4bn and 7.2 million workdays a year to repeated cyber disruption, according to research from eir Business supported by Microsoft. That works out at roughly €50,000 per SME annually. The damage is rarely one catastrophic event. It is the cumulative cost of things that keep getting through.

A simulation is a cheap way to find out which of those things would get through here, before someone runs the same test without asking.

If you would like to see what a scoped exercise would look like for your team, get in touch and we will talk it through.

All field notes

Start with a free IT review.

You'll get a clear picture of where you're exposed today, and what it looks like to have your whole IT covered as one managed system. No obligation.