{"id":12220,"date":"2025-02-04T14:21:17","date_gmt":"2025-02-04T14:21:17","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/04\/13\/better-than-theory-how-phishing-simulations-boost-employee-security-awareness\/"},"modified":"2026-07-04T12:24:20","modified_gmt":"2026-07-04T12:24:20","slug":"better-than-theory-how-phishing-simulations-boost-employee-security-awareness","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2025\/02\/04\/better-than-theory-how-phishing-simulations-boost-employee-security-awareness\/","title":{"rendered":"Phishing Simulations: Better Than Theory"},"content":{"rendered":"<p style=\"background:#69d8ed;color:#fff;padding:4px 14px;border-radius:20px;font-size:0.85em;margin-bottom:18px\">5 min read<\/p>\n<p><strong>Phishing causes billions in damages to companies every year. According to Bitkom, total losses from cyberattacks on German companies amounted to \u20ac203 billion in 2022. In 2024, 94 percent of all companies fell victim to at least one phishing attack. Traditional training programs have proven largely ineffective. An alternative is offered by msecure, a subsidiary of the synaforce Group, which simulates real-world phishing scenarios during regular business operations.<\/strong><\/p>\n<h2>Key Takeaways<\/h2>\n<ul>\n<li>94 percent of companies fell victim to phishing attacks in 2024 (Keepnet Labs, 2025).<\/li>\n<li>AI-generated phishing emails achieve a 54 percent click-through rate, compared to just 12 percent for manually crafted messages.<\/li>\n<li>In March 2024, synaforce received BSI C5 certification for cloud services, specifically tailored for critical infrastructure customers.<\/li>\n<li>The NIS2 Implementation Act has been legally binding in Germany since December 6, 2025. Registration with the BSI became mandatory starting January 2026.<\/li>\n<li>A strategic partnership with TEHTRIS delivers an AI-powered XDR platform for MSPs and enterprises.<\/li>\n<\/ul>\n<div class=\"evm-stat evm-stat-highlight\" style=\"text-align:center;background:#f0f9fa;border-radius:12px;padding:32px 24px;margin:32px 0\">\n<div style=\"font-size:48px;font-weight:700;color:#69d8ed;letter-spacing:-0.03em\">94 %<\/div>\n<div style=\"font-size:15px;color:#444;margin-top:8px\">of companies were targeted by at least one phishing attack in 2024<\/div>\n<div style=\"font-size:12px;color:#888;margin-top:8px\">Source: Keepnet Labs, Phishing Statistics 2025<\/div>\n<\/div>\n<h2>What is Phishing simulations?<\/h2>\n<p>Phishing simulations is a concrete priority for companies in 2025 because it directly shapes scalable data center capacity, energy efficiency and compliance. This article uses synaforce as an example to show which requirements, figures and operational steps matter in practice.<\/p>\n<h2>Why Does Phishing Remain Dangerous?<\/h2>\n<p>Obtaining access credentials through fake emails remains one of the most significant entry points for cybercriminals into German companies. In 2024, approximately 20 percent of all emails worldwide contained phishing or spam content. Between three and four billion phishing emails are sent daily. According to <a href=\"https:\/\/www.bitkom.org\/Presse\/Presseinformation\/Wirtschaftsschutz-2022\" target=\"_blank\" rel=\"noopener\">Bitkom<\/a>, the total damages caused by cyberattacks on German businesses-ranging from password theft to ransomware-amounted to 203 billion euros in 2022.<\/p>\n<p>Much like spam, phishing aims to defraud victims: deceptively authentic emails, messages, AI-generated calls, or websites trick recipients into disclosing user and account information.<\/p>\n<p>In the past, phishing emails could often be identified by awkward wording or errors in the subject line. However, that is no longer the case, especially since the advent of trainable AI models such as ChatGPT. According to recent analyses, <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/15\/ki-phishing-82-prozent-angriffs-mails-maschinen\/\" target=\"_blank\" rel=\"noopener\">AI-generated phishing emails<\/a> achieve a click-through rate of 54 percent, compared to just 12 percent for manually crafted ones. Moreover, detecting them via cryptic URLs has become increasingly difficult: who would notice .co for Colombia instead of .com, or the substitution of &#8220;r n&#8221; for &#8220;m&#8221; in &#8220;rnicrosoft.com&#8221;?<\/p>\n<p>It is precisely this ability to recognize such threats that employees must develop, emphasizes G\u00f6tz Blechschmidt, Managing Director of the IT security consultancy <a href=\"https:\/\/msecure.de\/\" target=\"_blank\" rel=\"noopener\">msecure<\/a>, a subsidiary of the synaforce Group.<\/p>\n<blockquote style=\"border-left:4px solid #69d8ed;margin:32px 0;padding:20px 24px;background:#fafafa;border-radius:0 8px 8px 0;font-size:1.1em;line-height:1.6;color:#333\"><p>\n&#8220;The threat landscape was already immense in 2024, and it is unlikely to improve in 2025. Our collective resilience will be crucial in addressing these ever-more complex dangers.&#8221;<br \/>\n<cite style=\"margin-top:12px;font-size:0.8em;color:#888;font-style:normal\">Andreas Braidt, CEO of synaforce GmbH<\/cite>\n<\/p><\/blockquote>\n<h2>Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Every question is locked. A tap unlocks the answer.<\/p>\n<details>\n<summary><strong>What makes phishing so dangerous today?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Phishing attacks are dangerous because they exploit human psychology to trick individuals into revealing sensitive information, such as login credentials. With the rise of AI-generated phishing emails, these attacks have become more convincing and harder to detect, making them an even greater risk for organizations.<\/p>\n<\/details>\n<details>\n<summary><strong>How can companies protect themselves against phishing?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Companies can protect themselves by implementing multi-layered security measures, including employee training on recognizing phishing attempts, deploying advanced email filtering systems, and regularly updating cybersecurity protocols. Additionally, fostering a culture of vigilance and continuous learning is essential to mitigate risks.<\/p>\n<\/details>\n<details>\n<summary><strong>What role does AI play in modern phishing attacks?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">AI plays a significant role in modern phishing attacks by enabling the creation of highly realistic and personalized phishing emails. These AI-generated messages are designed to bypass traditional detection methods, increasing their success rate and posing a serious challenge to cybersecurity defenses.<\/p>\n<\/details>\n<details>\n<summary><strong>How do phishing attacks impact businesses financially?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Phishing attacks can lead to substantial financial losses for businesses, including direct costs such as ransom payments, indirect costs related to system downtime, and long-term damage to reputation. In Germany alone, cyberattacks resulted in 203 billion euros in damages in 2022, highlighting the severe economic consequences of these threats.<\/p>\n<\/details>\n<h2>Effectively Complement Traditional Training<\/h2>\n<p>The goal of data protection training, such as that offered by msecure, is to raise employees\u2019 awareness about handling emails with caution. Participants learn what to look out for and which links they should never click. However, given the sheer volume of information employees are bombarded with in their daily work, traditional training measures often have only a short-term impact.<\/p>\n<p>msecure therefore relies on simulating real phishing scenarios during regular business operations. Instead of theoretical lectures, employees experience realistic attacks within their own work environment. Anyone who clicks on a simulated phishing email immediately receives an explanation of how they could have recognized the forgery. This practice-oriented training promises more direct and lasting awareness than conventional training formats.<\/p>\n<h2>synaforce 2024: Setting New Standards in IT Security<\/h2>\n<p>In 2024, synaforce took decisive steps to strengthen its position as a provider of advanced <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/11\/hardening-active-directory-5-immediate-measures-against-identity-attacks\/\" target=\"_blank\" rel=\"noopener\">IT security solutions<\/a>. A central milestone was achieving C5 certification from the BSI (Federal Office for Information Security) in March 2024. This certification confirms that synaforce\u2019s cloud services meet the highest security standards and are specifically suitable for customers in critical infrastructure sectors (KRITIS).<\/p>\n<p>Furthermore, synaforce strategically prepared for the implementation of the <a href=\"https:\/\/www.securitytoday.de\/en\/2024\/11\/07\/nis2-in-germany-act-now-before-its-too-late\/\" target=\"_blank\" rel=\"noopener\">NIS2 Directive<\/a>. The company\u2019s existing certification base, which includes ISO\/IEC 27001, ISAE 3402, and EN 50600, was further strengthened by the C5 certification. Since December 6, 2025, the NIS2 Implementation Act has been binding in Germany. As of January 2026, affected entities are required to register with the BSI.<\/p>\n<div id=\"attachment_3352\" style=\"width: 260px\" class=\"wp-caption alignright\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-3352\" class=\"wp-image-3352 size-medium\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2024\/12\/tobias_lehner-250x167.jpeg\" alt=\"Modern data center with illuminated server aisles \u2013 article about phishing simulations and synaforce, section 1\" width=\"250\" height=\"167\" srcset=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2024\/12\/tobias_lehner-250x167.jpeg 250w, https:\/\/www.securitytoday.de\/wp-content\/uploads\/2024\/12\/tobias_lehner-768x512.jpeg 768w, https:\/\/www.securitytoday.de\/wp-content\/uploads\/2024\/12\/tobias_lehner-700x466.jpeg 700w, https:\/\/www.securitytoday.de\/wp-content\/uploads\/2024\/12\/tobias_lehner-120x80.jpeg 120w, https:\/\/www.securitytoday.de\/wp-content\/uploads\/2024\/12\/tobias_lehner.jpeg 974w\" sizes=\"auto, (max-width: 250px) 100vw, 250px\" \/><p id=\"caption-attachment-3352\" class=\"wp-caption-text\">Tobias Lehner, CTO of synaforce GmbH. Image source: synaforce GmbH.<\/p><\/div>\n<p>\u201cWe are proud of what we achieved in 2024. However, the current threat landscape demonstrates how crucial it is to consistently expand our capabilities. 2025 will be another year of progress for us, during which we will further intensify our commitment to cybersecurity,\u201d says Tobias Lehner, CTO of synaforce.<\/p>\n<h2>Strategic Partnership with TEHTRIS<\/h2>\n<p>Another highlight was the strategic partnership with TEHTRIS. Together, both companies present the TEHTRIS XDR AI PLATFORM, an AI-powered security solution. It monitors all endpoints, networks, and cloud services in real time and centrally manages all security measures through a dashboard. Companies benefit from comprehensive protection, compliance security, and the modularity of the solution. Managed Service Providers can increase the efficiency of their security measures and expand their portfolio with proactive Managed Detection and Response (MDR) without having to invest in expensive infrastructures themselves.<\/p>\n<h2>What awaits companies in 2025 and 2026<\/h2>\n<p>The IT security landscape presents growing challenges for companies. Cybercriminals are increasingly using deepfake technologies to bypass voice recognition systems in verification processes. <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/19\/identity-attacks-2026-why-hackers-no-longer-break-in-they-log-in\/\" target=\"_blank\" rel=\"noopener\">Identity attacks<\/a> are becoming the preferred method: instead of hacking systems, attackers simply log in.<\/p>\n<p>In addition, Advanced Persistent Threats (APTs) are increasingly returning to the spotlight. These are characterized by their longevity and precision, allowing attackers long-term access to valuable information. The targets are increasingly KRITIS companies, which are additionally exposed due to the <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/14\/ot-security-2026-119-ransomware-groups-target-industrial-facilities\/\" target=\"_blank\" rel=\"noopener\">growing OT attack surface<\/a>.<\/p>\n<div id=\"attachment_3353\" style=\"width: 260px\" class=\"wp-caption alignleft\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-3353\" class=\"wp-image-3353 size-medium\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2024\/12\/andreas-braidt-250x167.png\" alt=\"Modern data center with illuminated server aisles \u2013 article about phishing simulations and synaforce, section 2\" width=\"250\" height=\"167\" srcset=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2024\/12\/andreas-braidt-250x167.png 250w, https:\/\/www.securitytoday.de\/wp-content\/uploads\/2024\/12\/andreas-braidt-768x512.png 768w, https:\/\/www.securitytoday.de\/wp-content\/uploads\/2024\/12\/andreas-braidt-700x467.png 700w, https:\/\/www.securitytoday.de\/wp-content\/uploads\/2024\/12\/andreas-braidt-120x80.png 120w, https:\/\/www.securitytoday.de\/wp-content\/uploads\/2024\/12\/andreas-braidt.png 1600w\" sizes=\"auto, (max-width: 250px) 100vw, 250px\" \/><p id=\"caption-attachment-3353\" class=\"wp-caption-text\">Andreas Braidt, CEO of synaforce GmbH. Photo source: synaforce GmbH.<\/p><\/div>\n<p>&#8220;The implementation of the NIS2 Directive plays a crucial role. synaforce actively supports companies with comprehensive consulting as well as the planning and implementation of targeted measures to minimize cyber risks and establish sustainable security strategies,&#8221; says Andreas Braidt, CEO of synaforce.<\/p>\n<div style=\"clear:both\"><\/div>\n<h2>Further Reading<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/15\/ki-phishing-82-prozent-angriffs-mails-maschinen\/\" target=\"_blank\" rel=\"noopener\">AI-Generated Phishing: Why 82 Percent of Attack Emails Now Come from Machines<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/19\/identity-attacks-2026-why-hackers-no-longer-break-in-they-log-in\/\" target=\"_blank\" rel=\"noopener\">Identity Attacks 2026: Why Hackers No Longer Break In-They Just Log In<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/14\/ot-security-2026-119-ransomware-groups-target-industrial-facilities\/\" target=\"_blank\" rel=\"noopener\">OT Security 2026: 119 Ransomware Groups Target Industrial Facilities with Precision<\/a><\/li>\n<\/ul>\n<p style=\"font-weight:700;color:#e6e3da;font-size:1.05em;margin:48px 0 16px;\">More from the MBF Media Network<\/p>\n<div style=\"display:flex;flex-direction:column;gap:14px;margin-bottom:40px;\"><a href=\"https:\/\/mybusinessfuture.com\/cybersecurity-boom-nis2-deutschlands-sicherheitsbranche\/\" class=\"st-net-card\" style=\"display:block;padding:16px 18px;background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;\"><span style=\"display:block;margin-bottom:6px;font-size:0.72em;font-weight:700;letter-spacing:0.06em;text-transform:uppercase;color:#aa8ac2;\">MyBusinessFuture<\/span><span style=\"display:block;color:#e6e3da;line-height:1.45;\">Cybersecurity Boom: Why NIS2 Is Driving Growth in Germany\u2019s Security Industry<\/span><\/a><a href=\"https:\/\/www.cloudmagazin.com\/en\/2024\/12\/18\/cybersicherheit-2024-synaforce-blickt-zurueck\/\" class=\"st-net-card\" style=\"display:block;padding:16px 18px;background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;\"><span style=\"display:block;margin-bottom:6px;font-size:0.72em;font-weight:700;letter-spacing:0.06em;text-transform:uppercase;color:#0bb7fd;\">cloudmagazin<\/span><span style=\"display:block;color:#e6e3da;line-height:1.45;\">Cybersecurity 2024: synaforce Looks Back<\/span><\/a><\/div>\n<h2>More on this synaforce topic<\/h2>\n<p>Additional service details, use cases and background are available from <a href=\"https:\/\/www.synaforce.com\/?utm_source=mbf-media&amp;utm_medium=fachartikel&amp;utm_campaign=synaforce-2026\" rel=\"noopener\" target=\"_blank\">synaforce for data center and infrastructure services<\/a>.<\/p>\n<ul>\n<li><a href=\"https:\/\/www.cloudmagazin.com\/en\/2023\/06\/23\/how-synaforce-unites-sustainable-data-center-performance\/\">Sustainable Data Center Performance with Synaforce<\/a><\/li>\n<li><a href=\"https:\/\/www.cloudmagazin.com\/en\/2025\/02\/19\/portfolio-synaforce-expands-portfolio\/\">synaforce Expands Portfolio with Herbst Acquisition<\/a><\/li>\n<li><a href=\"https:\/\/www.cloudmagazin.com\/en\/2025\/01\/30\/dora-enhanced-it-and-legal-security-in-the-financial-sector\/\">DORA: IT and Legal Security for Finance<\/a><\/li>\n<\/ul>\n<\/div>\n","protected":false},"excerpt":{"rendered":"Phishing causes billions in damages annually. In 2024, 94 percent of all companies fell victim to at least one attack. msecure, a subsidiary of the synaforce group, relies on simulating real-world scenarios in live operations rather than theoretical training.","protected":false},"author":53,"featured_media":12394,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"phishing simulations","_yoast_wpseo_title":"Phishing Simulations: Better Than Theory","_yoast_wpseo_metadesc":"See how realistic phishing simulations improve employee awareness and reduce breach risks\u2014backed by real-world results from 2024 security programs.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":[],"footnotes":""},"categories":[255],"tags":[],"class_list":["post-12220","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-praxis-umsetzung-en"],"evm_reading_time_minutes":8,"wpml_language":"en","wpml_translation_of":3366,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/12220","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/53"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=12220"}],"version-history":[{"count":5,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/12220\/revisions"}],"predecessor-version":[{"id":19793,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/12220\/revisions\/19793"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/12394"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=12220"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=12220"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=12220"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}