People are the weakest link — strengthen them measurably

Employee security awareness training and phishing simulation

We set up organization-specific targeted phishing simulations with GoPhish; we deliver security awareness training to your staff and secure code development training to your software team. The simulation infrastructure runs on-premise, on your own hardware. Who clicked and the training data never leave your organization.

Explainer

What is a phishing simulation?

Most attacks start not with a technical vulnerability but with a person: a spoofed e-mail, a message that creates urgency, a landing page that looks like the real thing. A phishing simulation re-creates this scenario inside the organization in a controlled and harmless way; it measures who clicked and where they entered information. The aim is not to punish, but to see the organization’s overall resilience and strengthen it through training.

C3T runs this cycle: we set up the targeted scenario, measure the outcome, deliver the training and report progress through repeated campaigns. The simulation infrastructure runs on-premise, on the organization’s own servers; sensitive results never leave.

How do security awareness training and phishing simulation work?

The process has three steps: (1) targeted phishing simulation — organization-specific, realistic campaigns in Turkish are prepared with GoPhish, and click and data-entry rates are measured; (2) employee security awareness training — recognising spoofed e-mails, protection against social engineering and the reflex to report suspicious situations; (3) secure code development training for the software team. The simulation infrastructure runs on-premise, on the organization’s own servers; who clicked and the training records never leave the organization, and in KVKK terms the data stays in Türkiye. As the measure–train–re-measure cycle repeats, the click rate falls.

What we do

We work on awareness along three axes: targeted phishing simulation, security awareness training for all staff and secure code development training for the software team. All three are measurable and run on-premise.

Targeted phishing simulation

Organization-specific, realistic campaigns with GoPhish; measures the weakest link in a safe environment.

  • Organization-specific, targeted scenarios in Turkish
  • Click-rate and data-entry rate measurement
  • Aggregate reports at unit / department level
  • Instant feedback page (training for those who click)
  • Progress tracking through repeated campaigns

Employee security awareness training

Social engineering, phishing and safe-behaviour training for all employees.

  • Recognising phishing and spoofed e-mails
  • Password and multi-factor authentication habits
  • Protection against social engineering
  • The reflex to report suspicious situations

Secure code development training

Hands-on training that gives your software team a culture of developing without introducing vulnerabilities.

  • Common vulnerabilities and secure coding practice
  • Input validation and authorisation mistakes
  • Secret / key management discipline
  • Examples mapped to penetration testing findings

Open source stack and on-premise AI

Instead of an expensive SaaS platform, open source GoPhish and on-premise AI: realistic scenarios, full control, data stays in-house.

GoPhish (open source)

Phishing campaigns are built with GoPhish; organization-specific templates, landing pages and scheduling are entirely under your control.

Scenarios with on-premise AI

AI running on the organization’s own server helps produce realistic, targeted phishing messages in Turkish; the scenario content never leaves the organization.

Data in Türkiye, on-premise

Who clicked and the training records are kept within the organization’s own boundaries; no data is sent to SaaS platforms, and data sovereignty is preserved in KVKK terms.

Which compliance obligations it meets

Awareness is a mandatory control in many frameworks. Simulation and training records produce documented evidence that can be presented in audits.

ISO 27001 A.7.2.2

The information security awareness, education and training control. Simulation and training records form evidence that can be presented in audits.

KVKK employee training

The awareness of employees who process personal data is part of the technical and administrative measures under KVKK. Regular training meets this expectation.

BİGR awareness

BİGR (Turkey’s Information and Communication Security Guide) requires regular awareness and training in the public sector and critical infrastructure. Measurable simulation makes this tangible.

Why C3T

No report-and-leave; we measure, train and sustain

We treat awareness not as a one-off test, but as a cycle that runs on the organization’s own infrastructure. As the implementing partner, we set up the simulation, deliver the training and report progress.

Measure, train, measure again

Not a one-off test; we run the simulation → training → re-measurement cycle. As campaigns repeat, the drop in click rate is reported to the organization. The consultant does not write a report and walk away; we implement and sustain the process.

On-premise deployment, data stays in-house

GoPhish and on-premise AI are deployed on the organization’s own infrastructure. Who clicked, the training records and the scenario content never leave the organization. It runs under the same on-premise discipline as our penetration testing and compliance services.

Frequently asked questions

Does a phishing simulation single out employees?

No. The aim is not to punish but to measure and strengthen. People are the weakest link; the goal of the simulation is not to catch anyone, but to measure the organization’s overall resilience and raise it through training. Reporting follows rules agreed with the organization; on request, results are presented in aggregate at unit or department level rather than individually.

Where is the simulation and training data kept?

The GoPhish infrastructure runs on the organization’s own servers, on-premise (on your own hardware). Who clicked which link, who entered data and training completion records never leave the organization. In KVKK terms, the data stays in Türkiye, within the organization’s own boundaries.

Which compliance obligations does it help with?

Awareness training and simulation produce documented evidence that can be presented in audits for ISO 27001 control A.7.2.2 (information security awareness, education and training), the employee training expectation under KVKK (Turkish Personal Data Protection Law) and the awareness requirements of BİGR (Turkey’s Information and Communication Security Guide).

Are the scenarios tailored to our organization?

Yes. Instead of generic templates, we prepare targeted scenarios that resemble your sector, the services you use and your internal processes. On-premise AI helps produce realistic, targeted spear-phishing messages in Turkish; the content never leaves your organization.

Is it only a phishing test, or is there training too?

Both together. The simulation measures the weak spot; then staff receive security awareness training and the software team receives secure code development training. As the measure-and-train cycle repeats, the click rate falls and the organization’s resilience grows.

How does it connect with your other security services?

Awareness complements technical controls. Social engineering weaknesses found in penetration testing are closed through training; in compliance consulting, awareness is one of the required controls. This page connects directly with both the penetration testing and the compliance side.

Let’s strengthen your organization’s weakest link together

Let’s define an organization-specific phishing simulation and awareness training plan in a free feasibility call, taking your current team and processes into account. Your simulation data never leaves your organization.