Phishing simulation for EU SMEs

Phish your employees before someone else does.

Nordvakt sends realistic, personalized phishing emails to your team — in their own language — then shows you exactly who clicked. Built for small and medium businesses navigating GDPR and NIS2.

Built by people from Banking · Pharma · Compliance
Inbox — Anna Lindqvist
IT
IT Helpdesk
<support@m1crosoft365.com> · 09:14
Action required: your password expires today
Hej Anna, your Microsoft 365 password for Nordvakt AB expires in 2 hours. Re-verify now to avoid losing access to your files…
Verify my account
!Simulated by Nordvakt — 7 of 24 employees clicked
EU data residency GDPR by design · signed DPA Supports NIS2 awareness duties Swedish · Estonian · Danish
What we offer

Phishing training, run for you — not another tool to learn.

We send highly customized phishing emails to your employees and report exactly who clicked and who didn't — in your team's own language. Designed for small and medium companies across the EU.

Highly customized lures

Realistic emails tailored to your tools, your industry and recent events — the kind real attackers actually send.

In your own language

Swedish, Estonian and Danish — written by native speakers, not machine-translated. Localization is where most simulations fail.

Clear, honest reporting

Who clicked, who reported, who ignored — plus practical guidance. No vanity metrics, no blame.

We run it for you

No platform to configure. You give us the context once; we handle sending, tracking and the report.

See it in action

A simulation, start to finish

All you need to do

Three steps. Then we take it from there.

No security team required. You spend about 15 minutes setting things up — everything after that is handled by us, end to end, including sending, tracking and your final report.

01

Sign up & share context

Tell us who to test, your language and a little about your company. ~15 minutes.

02

Approve the lures

We craft localized phishing emails for your context. You review and approve — or leave it to us.

03

Get your report

We send, track and deliver a clear report of who clicked — with guidance on what to do next.

Why it matters

One click is all it takes.

Most breaches at small companies start with a single convincing email. Here's what that one click can lead to.

Account takeover

Stolen credentials let attackers into email, files and payroll — often unnoticed for weeks.

Invoice & CEO fraud

A fake "urgent payment" from the boss can move real money out the door in minutes.

Ransomware & downtime

A single attachment can lock your systems and halt the business until you pay or rebuild.

Breach fines & trust

A personal-data breach can mean GDPR penalties, mandatory notifications and lost customers.

Compliance & requirements

Done the legal way, by default.

Testing your own employees is lawful when it's done transparently and with the right safeguards. We build those safeguards into every campaign — and give you the documents your auditors will ask for.

This overview is general information, not legal advice. We're happy to walk your DPO or counsel through specifics.

Signed Data Processing Agreement

A DPA is in place before any data is processed. You remain the controller; we're your processor.

Data minimization & EU residency

We use only work contact data, stored on EU infrastructure, and delete it per an agreed retention period.

Supports your NIS2 duties

Recurring awareness training and audit-ready documentation that map to NIS2 expectations for essential and important entities.

No-blame, transparent by policy

We help you inform staff that simulations may occur, so testing stays fair and within employment norms.

Pricing

Simple, transparent pricing

One per-seat price you can see up front. No hidden tiers, no seat minimum, no long lock-in — we win on simplicity and compliance depth, not by being the cheapest.

Per seat
From 50 kr
per user · per month · + VAT · billed quarterly
  • Realistic, localized phishing simulations
  • Automatic in-the-moment training for anyone who clicks
  • Audit-ready reporting mapped to NIS2
  • No seat minimum — a 12-person firm is as welcome as 200
  • No long lock-in · billed quarterly
  • Swedish-owned · data stays in the EU

Individuals can run simulations for themselves, family or friends on the same per-seat price — with each person's permission.

About us

We learned this defending banks and pharma.

Our team has spent years inside high-compliance industries — banking, pharmaceuticals and regulated infrastructure — where a single phishing email can become a front-page incident.

We kept seeing small and medium companies get hit by the exact same lures the big regulated firms had already learned to stop. Nordvakt brings that same discipline to SMEs across the Nordics and Baltics — without the enterprise price tag or the enterprise complexity.

“The companies most at risk are the ones who think they’re too small to be a target. They’re not — they’re just easier.”
EU
Data stays in the Union
3
Native languages, more on request
~15
Minutes to set up
0
Platforms for you to manage
Get started

Set up your first campaign

Tell us who to test and a little about your company. We'll take it from there and come back with localized lures to approve.

🔒 Your details are handled securely and are never sold. This preview form doesn't transmit data anywhere.

Book a demo

See a real campaign, on your terms

A 20-minute walkthrough — no slides, just the product and your questions.

Ask us anything

Have a question first?

Tell us your context and we'll give you a straight answer — no sales pressure.

FAQ

Questions, answered honestly

Yes. Running phishing simulations on your own employees for security training is lawful in the EU when done transparently and with the right safeguards — a legitimate interest under GDPR and part of an employer’s duty to keep systems secure. We sign a Data Processing Agreement and help you inform staff via policy. This is general information, not legal advice.

Draft answers for your review — refine the wording to match your legal position before launch.

Find out who'd click — before an attacker does.

Set up your first localized campaign in about 15 minutes. We handle everything after that.