Cybersecurity / Phishing Simulation

Phishing Simulation for Malaysian Organisations

Find out how many of your people would click, how many would hand over a password, and how many would report it. We run controlled phishing campaigns across your workforce, measure the real behaviour, and turn the result into a plan your board can sign off.

Written authorisation and safe-by-design landing pages Click, submission and report rates by department Pairs with HRD Corp claimable awareness training
Overview

A safe rehearsal of the attack that causes most breaches

What it is

Phishing simulation is a controlled exercise in which we send realistic but completely harmless phishing emails to your employees, under written authorisation from your organisation. Nothing is installed, no malware is used, and no real credential is ever captured or stored. What we capture is behaviour: who opened the email, who clicked the link, who went on to type a password into the landing page, and critically, who recognised the attempt and reported it.

A campaign typically runs over one to two weeks across your whole workforce or a defined population. Templates are modelled on the lures that actually land in Malaysian inboxes: e-invoice and LHDN notices, DuitNow payment requests, HR payroll and EPF letters, courier delivery notifications, Microsoft 365 password expiry warnings and internal IT service desk messages.

Anyone who clicks lands on a short coaching page rather than a scolding, explaining the specific red flags in the email they just received. The teaching moment happens at the exact second the mistake is made, which is when it sticks.

Why organisations need it

Email remains the most common way into an organisation, because it targets the one control you cannot patch. Attackers do not need to defeat your firewall if a member of your finance team will open the door for them.

The 2024 amendments to Malaysia's Personal Data Protection Act tightened the consequences. A personal data breach now has to be notified to the Commissioner, and affected individuals told where there is significant harm, on a timeline measured in days not months. Regulators, auditors, cyber insurers and enterprise clients running vendor assessments increasingly ask the same question: how do you know your staff can spot a phishing email? "We ran a training session" is not an answer. A measured click rate, a trend over four quarters and a documented remediation plan is.

Simulation also tells you where to spend. Most organisations discover their risk is not evenly spread. One department, one branch or one shift pattern will carry most of the exposure, and that is where the budget should go first.

Key features

What a phishing simulation programme measures

Every campaign produces the same core metrics, so you can compare this quarter against last quarter, and one business unit against another, without arguing about methodology.

Realistic campaign design

Templates built around lures your staff genuinely receive, in the tone and format they expect. We agree difficulty in advance, from an obvious mass-mail attempt through to a targeted message referencing your real suppliers, systems and internal terminology.

Click tracking

Every open and click is logged with a timestamp, device type and whether the interaction happened on a corporate machine or a personal phone. Time-to-click matters as much as the raw number: the staff who click within sixty seconds are the ones a real attacker gets to first.

Credential submission tracking

The most serious signal is not a click, it is a password. Our landing pages record that a submission was attempted and discard the value immediately. We never see, store or transmit the actual credential, and the report shows submission counts, never passwords.

Reporting behaviour

The metric most programmes ignore and the one that shortens a real incident. We measure how many staff reported the email, how quickly, and through which channel, then help you set up a one-click report button so reporting is easier than deleting.

Department risk comparison

Results are broken down by department, branch, seniority, tenure and role so you can see exactly where the exposure sits. Finance, HR and customer-facing teams usually look different from engineering, and new joiners usually look different from everyone.

Executive reporting

A one-page summary written for a board audience: current risk position, movement since the last campaign, the three actions that would move the number most, and how you compare against organisations of similar size and sector.

Benefits

What the business gets out of it

The point of a simulation is not to catch people out. It is to give management a number they can manage, and to shorten the gap between an attack landing and someone raising the alarm.

You replace an assumption with a measurement

Most leadership teams believe their staff would spot a phishing email. A first campaign settles the argument in a fortnight and gives you a baseline to improve against.

Security budget goes where the risk actually is

Department-level results let you target intensive coaching at the twenty percent of the workforce carrying most of the exposure, instead of paying for the whole company to sit through the same session again.

You build evidence a regulator or auditor will accept

Campaign reports, remediation plans and trend data form a documented record that your organisation actively manages human risk. That record matters during a Commissioner enquiry, an ISO 27001 audit, a client vendor assessment or a cyber insurance renewal.

Incidents get contained faster

An organisation where staff report suspicious email in four minutes contains an incident very differently from one where the first sign of trouble is a customer complaint three weeks later.

Executives get protected properly

Senior staff are the highest-value targets and usually the least tested. Simulation surfaces that gap quietly, before it is discovered the expensive way.

Awareness training stops being a tick-box exercise

When a training session is scheduled off the back of real results from your own people, attendance, attention and retention all change. See our cybersecurity awareness training programmes for the follow-through.

Process

How Orbix runs a phishing simulation

A first engagement runs about four to six weeks end to end, including scoping and the debrief. Follow-up campaigns are faster because the groundwork is already done.

01

Scoping and written authorisation

We agree the population, the campaign difficulty, the schedule and the rules of engagement, including which teams are excluded and what happens if someone escalates to the police or a bank. Your authorised signatory signs off before anything is sent. This document is what makes the exercise lawful and it protects both sides.

02

Technical preparation

We whitelist the sending infrastructure with your IT team so simulated mail reaches inboxes rather than being silently filtered, register the landing domains, and run a small pilot to a test group to confirm delivery, tracking and the coaching page all behave correctly.

03

Baseline campaign

The first campaign is deliberately unannounced and pitched at a realistic difficulty. Announcing it produces a flattering number that tells you nothing. Emails are released in waves over several days so that early clickers cannot warn the rest of the office.

04

Live monitoring and instant coaching

We watch results as they come in and flag anything that needs an immediate response, for example a genuine credential compromise discovered along the way. Staff who click see a short coaching page straight away, framed as guidance rather than punishment.

05

Analysis and reporting

Raw data becomes three outputs: an operational report for IT and security, a department heat map for line managers, and a one-page executive summary for the board. We walk your team through all three in a debrief session.

06

Remediation and repeat

We agree the follow-up actions, typically targeted training for high-risk groups, a reporting button rollout, and a technical control or two. Then we schedule the next campaign, because a single data point is a curiosity and a trend line is a programme. Continuous delivery is covered under human risk management.

Deliverables

What you receive

Everything is delivered as documents you own and can circulate internally, not as a dashboard login that expires when the engagement ends.

Baseline phishing risk report

Full campaign results with click rate, credential submission rate, report rate, time-to-click and time-to-report, set against sector context.

Department and branch heat map

A visual comparison across business units, locations and seniority bands so managers can see their own position at a glance.

One-page executive summary

Written for directors and audit committee members. No jargon, one risk position, three recommended actions.

Remediation roadmap

A prioritised ninety-day plan covering training, process and technical controls, with an owner and an effort estimate against each item.

Coaching and awareness assets

The coaching pages, red flag reference cards and internal comms templates used during the campaign, yours to reuse.

Training completion certificates

Where the campaign is combined with a formal awareness session, participants receive certificates that can be verified through our certificate verification page.

Suitable for

Who phishing simulation is built for

Any organisation where staff use email can benefit, but the return is highest where a single mistaken click leads directly to money moving or personal data leaving.

Industries

We run campaigns across regulated and unregulated sectors. Regulated organisations tend to need the documentation trail as much as the result itself.

Financial services and banking Insurance and takaful Healthcare and clinics Professional services Manufacturing Government-linked companies Education Retail and e-commerce Logistics and shipping Property and construction

Company sizes

Campaign design changes with headcount. Under fifty people we usually run a single wave; above a thousand we segment by business unit so line managers get results they can act on.

50 to 200 employees 200 to 1,000 employees 1,000+ employees Multi-branch operations Regional teams across ASEAN

Departments

Whole-workforce campaigns give the truest picture, but these functions are where an unnoticed click causes the most damage.

Finance and accounts payable Human resources Customer service Sales and business development Procurement Operations IT and support Executive leadership
Why choose Orbix

Why organisations choose Orbix for phishing simulation

Plenty of vendors will sell you a phishing platform. Fewer will sit with your risk committee afterwards and explain what the number means.

A governance approach, not a tool sale

We approach phishing simulation as a governance activity, not a technical stunt. The output is designed to feed your risk register, your audit evidence pack and your board reporting cycle, which is where it has to land for anyone to act on it.

Recommendations you can actually implement

Every finding comes with a recommendation someone in your organisation can actually own, sized against the resources you have. We will not hand you a forty-page report recommending a security operations centre if you have two people in IT.

Consultants who have sat on your side of the table

Our consultants have run compliance, data protection and security functions inside Malaysian organisations, not only advised on them from outside. That shows up in the advice: we know what a lean IT team can absorb in a quarter, and we know which recommendations get quietly shelved.

Built for the Malaysian operating context

Scenarios use Malaysian references your staff will recognise, from DuitNow payment requests and e-invoice notices to LHDN and EPF correspondence. Reporting is framed against the obligations your regulators and auditors actually cite, including the 72-hour personal data breach notification duty introduced by the 2024 amendments to the PDPA.

HRD Corp expertise where it applies

Awareness training that follows a simulation can be delivered as an HRD Corp claimable programme through our registered training arm, which for levy-contributing employers makes the follow-through close to cost-neutral. See HRD Corp claimable cybersecurity training.

FAQ

Phishing simulation questions we get asked

Yes, when it is properly authorised. The exercise is conducted against your own organisation, on systems you control, under a written authorisation signed by someone empowered to give it. We also recommend a general clause in your acceptable use policy or employee handbook stating that the organisation may conduct security testing, which most Malaysian employers already have. What we do not do is test third parties, customers or suppliers without their own separate written consent.

Only if it is run badly. Programmes that name and shame individuals, or attach disciplinary action to a first click, poison the well and drive under-reporting, which is the opposite of what you want. We design campaigns around aggregate reporting, coaching rather than blame, and clear internal communication after the first campaign explaining why it was done. Handled that way, staff generally find it interesting rather than threatening.

Quarterly is the practical baseline for most organisations, with monthly campaigns to high-risk groups such as finance. Annually is too infrequent to change behaviour and the results swing too much to be a useful trend. Continuous delivery is available through our human risk management programme.

First campaigns commonly land somewhere between fifteen and thirty percent depending on template difficulty, and that is normal rather than alarming. What matters is the direction of travel and the report rate. An organisation at a twelve percent click rate with a forty percent report rate is in far better shape than one at eight percent where nobody reports anything, because in the second case an attacker operates unnoticed.

No. The landing pages register that a submission event occurred and discard the field contents at the point of capture. Nothing is written to storage or transmitted onward. Reports show how many people submitted, never what they submitted. We are happy to walk your IT or data protection team through exactly how this works before you sign.

No administrative access is required. Your IT team allowlists our sending infrastructure so simulated mail is delivered rather than filtered, which is a configuration change on your side that we document step by step. We do not need mailbox access, directory credentials or anything beyond the recipient list you choose to provide.

The simulation itself is a consulting service. The awareness training delivered alongside it can be structured as an HRD Corp claimable programme through SBL-Khas for levy-contributing employers, subject to grant approval before the session takes place. Most clients scope the two together for exactly this reason. See our HRD Corp claimable training page for how the claim process works.
Get started

See what your click rate actually is

Tell us your headcount, your industry and what triggered the interest, whether that is an audit finding, a near miss, a board question or a regulator letter. We will come back with scope, timeline and a fixed quotation. No obligation, and we will say so if you do not need us yet.