Skip to main content

Phishing tests by Neo Security

Engineers who can truly social engineer

The weakest link thinks they're too smart to click

You have won 10 million! At Neo Security we don't test with outdated Nigerian Prince templates.

We take the outcomes of our phishing tests seriously. And we help you improve them. When we phish your organization, it's also our job to make you resilient.

From CEO fraud to QR code attacks. We know the tricks inside out.

ISO 27001 & 9001
Cyberveilig NL

What is a Neo Security phishing test?

A phishing test simulates realistic attacks on your organization. But where others stop at click rates, we continue. We help with a scenario-focused approach to align what we do and don't test. This way we show, when asked, what an attacker can really achieve with that one wrong click.

The difference? We are engineers who reverse engineer malware, build Command & Control servers and know how modern phishing toolkit packages work. That technical depth makes our tests effective. And that's why we help your employees improve. Let our social engineers check your organization so you get an answer from a friendly attacker.

The goal:

From naive clickers to paranoid security champions

Concrete phishing scenarios we execute

Operation Quickwin - The basics

Duration: 1 week

  • Fake Microsoft 365 updates
  • Fake pay slips
  • IT-support password resets
  • Package delivery notifications

from €795

Operation Spearphish - Targeted attacks

Duration: 2-4 weeks

  • C-level whaling campaigns
  • Finance department with fake invoices
  • HR with malicious CVs
  • Developers with npm/pip packages

from €2,950

Operation Total Compromise - Full kill chain

Duration: 4-8 weeks

  • Multi-stage attacks with persistence
  • Domain takeover simulations
  • Ransomware deployment paths
  • Data exfiltration via DNS

on request

A client had perfect technical security. We could barely find anything and they truly received a positive report for that. When we were allowed to run a phishing test to check this side, it hit home. We had nearly 80 warnings within 10 minutes. The human element really needed more attention.

Neo Security

Social Engineering Team

Technology with a touch of psychology

The classics that still work

Some tricks? Timeless. Because they tap into our basic instincts.

  • Authority abuse -"The CEO is asking for iTunes gift cards" (yes, really)
  • Urgency exploits -"Your account will be blocked in 2 hours"
  • Curiosity triggers -"Photos from the Christmas party (some are spicy)"
  • Fear tactics -"Suspicious login detected from Russia"

Next-gen attack vectors

The attacks your awareness training doesn't warn about:

  • Browser-in-the-browser -Fake login windows within legitimate sites
  • Progressive web app phishing -Install our malware as an 'app'
  • OAuth token hijacking -"Login with Microsoft" as attack vector
  • QR code poisoning -That code in the cafeteria? Ours
  • Webhook manipulation -Your Slack/Teams can really serve as a C2 channel

The psychological precision

We first analyze your company culture. A tech startup falls for different triggers than an accounting firm. Those LinkedIn posts from your employees? A goldmine for targeting.

Neo Security

Security Awareness Team

Why Neo Security phishing is different

We build our own infrastructure

  • Custom phishing frameworks (no GoPhish templates)
  • Domain generation algorithms for evasion
  • SSL pinning bypass techniques
  • Automated payload obfuscation
  • Real-time dashboard with threat intelligence

We go beyond the inbox

  • Vishing with AI-generated executive voices
  • Smishing with Malicious SMS gateways
  • Physical USB drops with Custom firmware
  • WiFi pineapples with Captive portals
  • BEC simulation with Supply chain angle

We measure what really counts

  • Time-to-compromise - From click to domain admin
  • Lateral movement success - Percentage successful escalation
  • Data exfiltration volume - GB of 'stolen' data
  • Detection time - SOC response time
  • Mean-time-to-contain - From detection to remediation

The hard reality in numbers

From our red team database:

  • clicks on targeted phishing73%
  • fills in credentials45%
  • opens malicious attachments31%
  • installs our malware12%
  • reports the incident3%

After our training:

  • still clicks8%
  • fills in credentials2%
  • reports suspicious emails89%
  • average report time15 min
  • average prevented loss€2.3M

Phishing defense programs

Awareness Basics

€4,950 per year

  • Quarterly phishing campaigns
  • Automated micro-learning
  • Basic reporting dashboard
  • Email security review

Advanced Persistent Training

€14,950 per year

  • Monthly campaigns + ad-hoc tests
  • All attack vectors (email/SMS/voice)
  • Red team collaboration
  • Custom awareness content
  • Executive briefings

Managed Human Firewall

Price on request

  • Continuous testing
  • 24/7 phishing SOC
  • Real attack simulation
  • Threat intelligence integration
  • Board-level reporting

What makes Neo Security the best choice?

20 years of social engineering experience

From the time phishing was still called "dumpster diving" to modern AI-powered attacks. We haven't just witnessed the evolution - we helped shape it.

Engineers, not consultants

We write exploits, build infrastructure and reverse engineer malware from time to time. Our phishing tests are well organized because we report and take down those of criminals. We understand systems.

From test to aware

A click-rate report is not an endpoint but a starting point. We help build a security-conscious culture that withstands modern threats.

The phishing test that keeps your CISO awake

Neo Security phishing techniques

The Triple Bypass

Email → SMS verification → Voice confirmation. Three layers of social engineering that reinforce each other.

The Supply Chain Special

We first compromise your supplier, then email you from their domain. Trust is a weakness.

The Long Con

Weeks of reconnaissance, LinkedIn engagement, conference "networking". Then we strike with surgical precision.

The Emergency Exit

Simulated crisis (ransomware, data breach) followed by "helpful" vendors offering assistance. Panic creates vulnerability.

Start today with real resilience against phishing attacks.

Your employees sometimes think they recognize phishing. We prove otherwise. But much more importantly: we make them truly resilient against modern attacks. We turn your team into your defense line.

Acute phishing incident? 24/7 response: +31 20 716 5487

P.S. That security awareness training from last year? Our phishing emails go right through it. Time for a reality check and advice.

No hidden costs. No vendor lock-in. Results that keep you up at night. And soon, not anymore.