The post has been translated automatically. Original language: Russian
In a previous post, I wrote that phishing often works not because of "ignorance", but because of the context: haste, trust, and the habit of closing work tasks quickly.
Actually, the project we are currently working on grew out of this thought. noreply.kz .
We are creating a platform for companies that helps not only to check employees with phishing emails, but also to build a clear process: simulation > analysis > training > re-verification > analytics.
What's inside now:
• simulations of phishing campaigns;
• ready-made email templates and landing pages;
• Employee training after mistakes;
• LMS module with courses on cybersecurity;
• reports and metrics for the administrator;
• web-audit of the external surface of the company;
• compliance and security audit;
• The platform and training courses are available in three languages: Russian, Kazakh and English.
Our goal is to create a tool that helps companies see risks in numbers and gradually reduce the likelihood of incidents, rather than just "catching people making mistakes."
We are currently preparing pilot implementations and collecting feedback from IT, information security and HR teams.
If the topic of cybersecurity employee training is close to you or you have encountered phishing in the company, I will be glad to share my experience.
В прошлом посте я писал о том, что фишинг часто срабатывает не из-за "незнания", а из-за контекста: спешки, доверия, привычки быстро закрывать рабочие задачи.
Собственно, из этой мысли и вырос проект, над которым мы сейчас работаем — noreply.kz.
Мы делаем платформу для компаний, которая помогает не просто проверить сотрудников фишинговой рассылкой, а выстроить понятный процесс: симуляция > разбор > обучение > повторная проверка > аналитика.
Что сейчас есть внутри:
• симуляции фишинговых кампаний;
• готовые шаблоны писем и landing pages;
• обучение сотрудников после ошибок;
• LMS-модуль с курсами по кибербезопасности;
• отчёты и метрики для администратора;
• web-audit внешней поверхности компании;
• compliance и security-аудит;
• платформа и обучающие курсы доступны на трёх языках: русском, казахском и английском.
Наша цель - сделать инструмент, который помогает компаниям видеть риски в цифрах и постепенно снижать вероятность инцидентов, а не просто "ловить людей на ошибках".
Сейчас мы готовим пилотные внедрения и собираем обратную связь от IT, ИБ и HR-команд.
Если вам близка тема обучения сотрудников кибербезопасности или вы сталкивались с фишингом в компании, буду рад обменяться опытом.