Skip to main content Scroll Top

Phishing Simulation and Penetration Testing for AikGroup: The Test Is the Beginning, Not the End

  • Home
  • Case Study
  • Phishing Simulation and Penetration Testing for AikGroup

The Challenge: Phishing is not a question of if, but when

Phishing is no longer a question of if it will happen, but when. AikGroup, one of the leading financial groups in the region, recognized that technical protection alone is not enough, and that the weakest point in any system is the employee who is in a hurry, clicks without thinking, and doesn’t suspect anything.

Instead of waiting for this issue to be raised through a real attack, AikGroup decided to test it in advance; not as a one-time exercise, but as part of a continuous program of information system and personnel testing.

The Process: Phishing Simulation, Pen Test and Retest

Saga and AikGroup have been collaborating for some time on strengthening the organization’s security culture, combining phishing simulations with penetration testing. The main reason for launching the program was not any specific incident, but the need to clearly define resilience at both the human and technical levels.

The campaign was designed to answer a specific question: how well are AikGroup employees really prepared to recognize an attack attempt, regardless of how sophisticated it is. The team approached the task from a hacker’s perspective: creating a context convincing enough not to be easily recognizable, yet realistic enough not to lose credibility.

The results were not an end in themselves. What sets AikGroup apart is their approach after the first round: instead of stopping at initial findings, a retest was conducted. It represents a step that AikGroup identifies as the most important part of the entire program, as it allows validation of a trend, not just a one-time result.

The Result: Measurable progress year over year

According to AikGroup, the retest has consistently shown a positive trend, with each subsequent year better than the previous one, with clear measurable progress compared to earlier testing cycles. This is confirmation for the organization’s security team that investment in continuous education and testing genuinely changes employee behavior, not just their awareness of risk.

In the Client's Words

“What matters to me more than a professional relationship is that the relationship is open. We manage in a simple way to agree on the scope of testing, the ultimate objectives, and in this way we elegantly arrive at the final result.”

Dejan Dušić, Group CISO, AikGroup

For AIikGroup, this collaboration is not a one-time project but part of a long-term strategy to strengthen security culture at the technical and human levels, where each test does not end with a report, but with confirmed changes in behavior.

Book a security assessment of your IT environment

Client: AikGroup

Topic: Phishing Simulation and Penetration Testing

Portfolio: Cyber Security

Reading time: 3 min