External Network Testing and a Phishing Simulation for a Railway Infrastructure Company

A phishing simulation combined with external network penetration testing to assess that showed how employees respond to a targeted attack.

Industry

Transport & Logistics

Location

Germany

Background

The client builds, maintains and modernizes railway infrastructure in Western Europe, which places the company among the suppliers that keep transport systems running. An attack on a company of this kind reaches beyond its own accounts, and the management understood that well enough to look at the question before anything happened.

The concern was specific. From time to time, the company was already seeing modest attempts to spoof sender addresses and send phishing messages. Nothing serious had happened, but the pattern was enough to make management question how employees would respond to a well-prepared attack. They suspected the level of awareness was insufficient, but a suspicion was not enough to justify a training budget or identify where the biggest gaps were.The company therefore decided to run a controlled phishing simulation to measure employee response rather than rely on assumptions.

IS YOUR BUSINESS PROTECTED FROM CYBER THREATS?

CHECK YOUR IT TEAM'S CYBERSECURITY SKILLS FOR FREE

Challenge

Two questions had to be answered, and they concerned different parts of the company.

1.Perimeter.
Every organization exposes services to the internet, and over the years that exposure grows through systems nobody reviews any more. The company needed to understand how employees would respond to a realistic social engineering scenario and whether a successful phishing attempt could create a path into internal systems. A controlled phishing simulation was therefore needed to measure employee behaviour and security awareness in practice, rather than rely on assumptions.
2. People.
Technical controls block most attacks, but a message that looks like ordinary correspondence and asks an employee to sign in somewhere passes through most of them, because the employee enters the credentials themselves. Awareness is the one thing an audit of configurations cannot measure.

An assessment that answers only one of these questions leaves the other open, and the two are connected: credentials obtained from an employee are the shortest way past a perimeter that otherwise holds.

Solution Overview

We combined external perimeter testing with a controlled phishing campaign to assess both technical exposure and the human factor. The two tracks came together when credentials obtained through phishing were used to test how far an attacker could move inside the environment.

Testing the perimeter without any access

We received no accounts, network diagrams or credentials and worked the way an outside attacker would. We mapped the company’s internet-facing systems and assessed exposed services and authentication mechanisms for vulnerabilities and misconfigurations. We also checked the boundaries between those systems and the internal environment.

No employees were involved in this stage, so the assessment could run without disrupting operations.

Preparing a realistic phishing simulation

The client selected recipients across the company, including employees who regularly work with IT systems. We used dedicated campaign infrastructure and local-language messages so the simulation reflected how a real attacker would approach employees rather than simply testing whether the mail filter recognized a known testing domain.

Testing what happens after a successful phishing simulation

The campaign obtained user credentials, but the assessment did not stop there. We used that access to test which internal systems became reachable, how far the access extended, and where segmentation and access controls stopped further movement.

This is the part that turns an awareness exercise into a security assessment. A click rate tells management that employees click. What follows from the click tells them what it costs.

Reporting to two audiences

We documented the vulnerabilities, the attack paths and the weaknesses we found, and delivered prioritized recommendations aimed at reducing the exposed surface and strengthening the controls that failed. We then held separate debriefings for management and for the technical team, because the two need different things from the same assessment: one decides what to fund, the other decides what to change.

Results

The phishing simulation gave the company an evidence-based answer to the question it started with, and acted on it. Then the company planned security training for its staff on the basis of the results.

Beyond the awareness question, the client gained a documented view of their external perimeter, the attack paths that lead from a single compromised account into the internal environment, and a prioritized list of  vulnerabilities to fix.

OutcomeWhat it gave the client
A tested perimeterThe company saw its externally exposed systems as an attacker sees them, with the vulnerabilities and misconfigurations named
A measured level of awarenessManagement replaced a concern regarding employees’ security awareness level with a documented result and used it to plan training
Validated internal controlsThe company learned how far an attacker could reach after one successful phishing message, and which controls stopped the movement
A prioritized remediation planBoth management and the technical team left the debriefings knowing what to change and in what order

ABOUT IBA GROUP

IBA Group has been delivering custom projects since 1993 for clients in over 50 countries. Our security practice covers penetration testing across web, mobile, network, cloud, infrastructure, LLM and IoT environments, as well as source code and architecture reviews, red team and social engineering assessments, phishing simulations, OSINT, and digital forensics and incident investigations.

WANT TO HEAR IT FROM THE CLIENT?

Request a reference and we will send you what the company said about our work.