Email campaigns
Realistic emails: fake HR notifications, accounting, IT, suppliers. Clickable links and lookalike forms.
We run real phishing campaigns: email, spear, QR, vishing. You get numbers on team vulnerability and micro-training for the ones who fail the test.
With a report broken down by team, vulnerable-role analysis and a security awareness plan.
Realistic emails: fake HR notifications, accounting, IT, suppliers. Clickable links and lookalike forms.
Targeted attack on executives and key staff using OSINT and personal details.
QR codes in emails and physical locations — bypassing email filters via mobile devices.
Phone-based social engineering: "IT support", fake HR, supplier impersonation to grab data.
How many opened the email, clicked through, entered creds. Segmented by team.
Who reported the suspicious email to IT or security. Ideal value — close to 100%.
Which teams / roles are most exposed. Targeted training — precise, not blanket.
Anyone who fails gets a short post-mortem: what went wrong, how to spot it next time.
Rolling out a security awareness programme — you need before/after numbers to show ROI.
Team's past 50+ — time to systematically check resilience to social engineering, not hope for the best.
Regulatory pressure plus a high cost of mistakes. Targeted training of accounting managers and executives.
After a real incident — checking whether team behaviour actually changed or the pattern will repeat.
Set the campaign size, scenarios, window, exclusions and report format.
Crafting emails, landing pages, attack infrastructure. Approved by the client before launch.
Email waves, QR collateral, vishing calls — on the agreed schedule.
Real-time tracking + micro-training for the ones who failed.
Report with team-level segmentation and a plan for the next iteration (in 3–6 months).
Describe the team and the scenarios you want. Details and approvals — in DevBay's secure chat.
After submission we open a dialog in the internal chat — that's where we continue.
Describe the team and desired scenarios — we'll build an approved campaign, run it and hand over the metrics and a training plan.