External Network Testing and a Phishing Simulation for a Railway Infrastructure Company
A phishing simulation combined with external network penetration testing to assess that showed how employees respond to a targeted attack.
Transport & Logistics
Germany
Background
The client builds, maintains and modernizes railway infrastructure in Western Europe, which places the company among the suppliers that keep transport systems running. An attack on a company of this kind reaches beyond its own accounts, and the management understood that well enough to look at the question before anything happened.
The concern was specific. From time to time, the company was already seeing modest attempts to spoof sender addresses and send phishing messages. Nothing serious had happened, but the pattern was enough to make management question how employees would respond to a well-prepared attack. They suspected the level of awareness was insufficient, but a suspicion was not enough to justify a training budget or identify where the biggest gaps were.The company therefore decided to run a controlled phishing simulation to measure employee response rather than rely on assumptions.
Challenge
Two questions had to be answered, and they concerned different parts of the company.
An assessment that answers only one of these questions leaves the other open, and the two are connected: credentials obtained from an employee are the shortest way past a perimeter that otherwise holds.
Solution Overview
We combined external perimeter testing with a controlled phishing campaign to assess both technical exposure and the human factor. The two tracks came together when credentials obtained through phishing were used to test how far an attacker could move inside the environment.
Testing the perimeter without any access
We received no accounts, network diagrams or credentials and worked the way an outside attacker would. We mapped the company’s internet-facing systems and assessed exposed services and authentication mechanisms for vulnerabilities and misconfigurations. We also checked the boundaries between those systems and the internal environment.
No employees were involved in this stage, so the assessment could run without disrupting operations.
Preparing a realistic phishing simulation
The client selected recipients across the company, including employees who regularly work with IT systems. We used dedicated campaign infrastructure and local-language messages so the simulation reflected how a real attacker would approach employees rather than simply testing whether the mail filter recognized a known testing domain.
Testing what happens after a successful phishing simulation
The campaign obtained user credentials, but the assessment did not stop there. We used that access to test which internal systems became reachable, how far the access extended, and where segmentation and access controls stopped further movement.
This is the part that turns an awareness exercise into a security assessment. A click rate tells management that employees click. What follows from the click tells them what it costs.
Reporting to two audiences
We documented the vulnerabilities, the attack paths and the weaknesses we found, and delivered prioritized recommendations aimed at reducing the exposed surface and strengthening the controls that failed. We then held separate debriefings for management and for the technical team, because the two need different things from the same assessment: one decides what to fund, the other decides what to change.
Results
The phishing simulation gave the company an evidence-based answer to the question it started with, and acted on it. Then the company planned security training for its staff on the basis of the results.
Beyond the awareness question, the client gained a documented view of their external perimeter, the attack paths that lead from a single compromised account into the internal environment, and a prioritized list of vulnerabilities to fix.
| Outcome | What it gave the client |
|---|---|
| A tested perimeter | The company saw its externally exposed systems as an attacker sees them, with the vulnerabilities and misconfigurations named |
| A measured level of awareness | Management replaced a concern regarding employees’ security awareness level with a documented result and used it to plan training |
| Validated internal controls | The company learned how far an attacker could reach after one successful phishing message, and which controls stopped the movement |
| A prioritized remediation plan | Both management and the technical team left the debriefings knowing what to change and in what order |
ABOUT IBA GROUP
IBA Group has been delivering custom projects since 1993 for clients in over 50 countries. Our security practice covers penetration testing across web, mobile, network, cloud, infrastructure, LLM and IoT environments, as well as source code and architecture reviews, red team and social engineering assessments, phishing simulations, OSINT, and digital forensics and incident investigations.
WANT TO HEAR IT FROM THE CLIENT?
Request a reference and we will send you what the company said about our work.
