blackforestbaits
Attack simulations

Does your team click on phishing?

Find out before a real attacker does. blackforestbaits simulates realistic attacks by email, letter, USB stick and phone — and gives you a hard number instead of a gut feeling.

  • Documented NIS2 evidence
  • No effort for your IT team
  • Hosted in Germany
Phishing simulation result
34 %
click rate
118 of 348 employees clicked
Action needed · report ready
The problem

The technology is secured. The human factor is not.

The vast majority of successful cyber attacks do not start with a security hole but with an email — not because your IT is poor, but because people under time pressure make mistakes. blackforestbaits makes that risk measurable before somebody else exploits it.

89 %
of all successful cyber attacks begin with phishing
Source: Verizon DBIR
267
days pass on average before a data breach is discovered
Source: IBM Cost of a Data Breach
€4.9 m
average cost of a cyber incident in Germany
Source: Bitkom Wirtschaftsschutz
1 in 3
mid-sized companies has already been the victim of an attack
Source: Bitkom Wirtschaftsschutz
Simulations

Four attack routes — individually or as an annual programme

Email simulation

A phishing email tailored to your company, sent to your workforce. The result: click rate, submission rate and a clear picture of what needs doing.

Letter phishing

The blind spot in the letterbox: letters with QR codes and social engineering by post — including tracking of who responds.

USB simulation

Prepared USB sticks in the car park, at the entrance, in the canteen. How many get plugged in?

Vishing (phone)

CEO fraud scenarios over the phone, simulated in a compliance-safe way. Rising sharply in Germany.

NIS2 annual programme

The complete annual programme under § 30 (2) no. 7 BSIG: every simulation format, quarterly reports and an awareness certificate from a single source — as solid evidence for regulators, auditors and cyber insurers.

How it works

How a simulation runs

01

Onboarding

Kick-off, technical setup, defining target groups — usually in under a week.

02

Simulate

Realistic tests across the chosen channels, matched to your industry.

03

Evaluate

Reports show click rates, trends and progress by department.

04

Improve

Targeted awareness modules for the areas that need support.

What you get out of it

Measurable impact, documented compliance

Considerably fewer clicks

After around twelve months of continuous awareness work, click rates typically drop substantially.

Evidence on paper

Documentation for GDPR, NIS2 and cyber insurers — cleanly, quarter by quarter.

An alert workforce

Employees who report suspicious emails instead of clicking them.

No IT effort

We handle setup and delivery in full.

Product site

All the details from the manufacturer

blackforestbaits is a product of Blackforestbytes GmbH in Offenburg — the same team that also builds our custom developments. You can read up directly there, or handle everything through us.

blackforestbaits.de
blackforestbaits — attack simulations you can book directly

How high is your click rate?

A first simulation will show you — discreetly, compliance-safe and with no effort for your IT team.

WhatsApp💬