Exhibitor Press Releases

31 Jul 2026

Security Awareness Methodology Forged on Europe’s Cyber Front Line: What Is SECAWA’s Practical Anti-Phishing Training?

SECAWA Hall: Level 5 Stand: 5-I15
SECAWA
Security Awareness Methodology Forged on Europe’s Cyber Front Line: What Is SECAWA’s Practical Anti-Phishing Training?
Pratical Anti-Phishing Platform SECAWA

Find out why one-off cybersecurity training is no longer enough to address today’s social engineering attacks, what SECAWA’s Practical Anti-Phishing Training includes, and how regular training can reduce simulation click rates from 50% to under 4% within a year.

Practical Anti-Phishing Training (PTA) is a long-term, automated educational program built around cyberattack simulations. It teaches employees how to recognize and respond appropriately to social engineering attacks through:

  • controlled phishing simulations,
  • nanolearning modules triggered at the moment a mistake is made, 
  • ongoing measurement of real-world behavior.

The methodology is developed by SECAWA, a European cybersecurity company based in Poland – a country that regularly faces advanced social engineering campaigns. In 2025, CSIRT NASK recorded, among other incidents, a campaign impersonating Poland’s deputy minister of digital affairs and targeting individuals responsible for cybersecurity in local government. Its purpose was to obtain contact details that could be used in subsequent, more precisely targeted attacks (CERT Polska, 2025 Annual Report).

The scale of the problem is far from marginal.

  • In its 2026 annual report, Fortinet identified a lack of employee awareness as one of the top three causes of security breaches for the third consecutive year, cited by 55% of respondents in 2025. The picture is equally clear at both the European and Polish levels:
  • In the European Union, phishing accounts for 60% of all initial access points into victims’ infrastructure, while more than 80% of observed social engineering campaigns now use AI support (ENISA, Threat Landscape 2025).
  • In Poland, CERT Polska recorded 78,391 phishing incidents in 2025 – 30% of all reported incidents – while most victims click a malicious link within 15 minutes of receiving the message (CERT Polska, 2025 Annual Report).

Despite this, most organizations still provide cybersecurity training only once a year, typically in the form of a presentation followed by a quiz – a format that measures theoretical knowledge rather than real behavior under pressure or during everyday routines.

How Does Practical Anti-Phishing Training Work?

Practical Anti-Phishing Training operates as a continuous cycle built around four integrated components: personalized social engineering attack simulations, nanolearning delivered at the moment of error, a mechanism for reporting suspicious messages, and ongoing measurement of employees’ real-world behavior.

Personalized Social Engineering Attack Simulations

Each simulation scenario is tailored to the organization’s industry, employee roles, and tools – and is based on attacks currently being observed in the real world, rather than outdated templates created years ago. As a result, the training reflects current tactics instead of textbook examples that cybercriminals abandoned long ago.

Today, simulations include email phishing, smishing, and attacks delivered through workplace communication platforms such as Microsoft Teams. The platform is continuously expanded to cover new channels as quickly as attackers adopt them.

Nanolearning at the Moment of Mistake

Nanolearning is a short, contextual lesson triggered automatically when an employee falls for a simulated attack. The mechanism draws on a natural learning response: making a mistake creates a brief increase in alertness that strengthens memory retention. As a result, educational content delivered immediately after an error can be up to ten times more effective than traditional theoretical training.

Each lesson takes less than a minute and does not require employees to log in to a separate platform or interrupt their work.

Suspicious Message Reporting

A dedicated Outlook and Gmail add-in allows employees to report a suspicious message with a single click – without risking the further spread of a potential threat within the organization.

When the message is part of a simulation, the system records the employee’s correct response. When it is not, the report is sent directly to the client’s security team for further analysis. No confidential content from the organization’s email correspondence is shared with SECAWA – the platform receives only a signal confirming that the employee reported the message.

Measuring Real-World Behavior Over Time

The platform tracks how employees respond to simulated attacks – from opening a message and clicking a link to reporting or ignoring the threat – and displays the results in real time on a dashboard.

Unlike a knowledge test, this measurement captures actual behavior rather than self-reported understanding. The same data can be used to adjust the difficulty of future simulations to the risk level of a specific department or role. It also helps organizations support compliance documentation under European regulations and frameworks such as DORA, NIS2, KSC 2.0, and the GDPR.

What Results Does Practical Anti-Phishing Training Deliver?

Organizations that implement Practical Anti-Phishing Training see click rates on simulated phishing attacks fall from around 50% to below 4% within one year of regular training. These are real-world results from SECAWA deployments across highly demanding organizations in Polish public administration and the European enterprise sector.

Results Become Visible Within the First Few Months

In one such deployment, the click rate dropped from 42% to 5% within eight months, falling below 10% after approximately four months of regular simulations.

Unlike one-off training, where employees’ vigilance gradually declines as theoretical knowledge fades, awareness continues to grow – because the training takes place as an ongoing cycle rather than a single event.

Employees Start Reporting Threats – Not Just Avoiding Clicks

A lower click rate is only half the result. The other half is the growing percentage of employees who actively report suspicious messages using the integrated reporting button.

In another SECAWA deployment, the reporting rate reached 48% after six months of training, compared with an almost nonexistent reporting rate at the outset. This gives the organization its own network of human sensors – employees who respond before a threat has a chance to spread.

The scale of these results is supported by more than 150,000 employees trained through PTA across organizations on three continents – the outcome of over seven years of helping businesses build resilience against social engineering attacks.

About SECAWA

SECAWA has been developing Practical Anti-Phishing Training since 2019. For the past seven years, it has helped organizations in Poland and across the European Union build resilience against social engineering attacks by combining its proprietary educational platform with experience gained from hundreds of deployments in the public and enterprise sectors. The company is a technology partner of PWCyber, a program run by Poland’s Ministry of Digital Affairs, and a donor to the CISO #Poland Foundation.

At Tech Week Singapore and Cyber Security World Asia 2026, SECAWA is showcasing its solution as part of SSM Cyber 360 – an offering that combines Practical Anti-Phishing Training with CDeX’s Polygon cyber range in a single platform for managing human and technical risk.

The SECAWA team invites attendees to visit its booth in the EZONE area to see the platform in action and discuss how European security awareness teams are responding to the social engineering attacks being observed today – not those described in textbooks written years ago.

Loading

2026 Partners

Official Airline Partner


 

Official Ride Partner


 

Official Event Partner


 

Official Press Release Distribution Partner


 

Official Accreditation Partner


 

Attraction Partner


 

Association Partner


 

Event Partner


 

Event Partner


 

Event Partner


 

Event Partner


 

Event Partner


 

Media Partner


 

Media Partner


 

Media Partner


 

Media Partner


 

Media Partner


 

Media Partner


 

Media Partner


 

Media Partner


 

Media Partner


 

Media Partner


 

Media Partner


 

Media Partner


 

Media Partner


 

Media Partner


 

Media Partner


 

Mark Your Calendars