Phishing simulations and MDR as a dual shield

Social engineering attacks like phishing are becoming increasingly sophisticated and difficult to detect due to the use of generative artificial intelligence. Data from ENISA and the Baobab Data Breach Report show that phishing remains one of the most common attack tactics. Nevertheless, 46% of large enterprises do not conduct phishing simulations, and 53% of SMEs do not use multi-factor authentication (MFA). This makes a multi-layered security strategy all the more important: combining practical phishing simulations with Managed Detection and Response (MDR) integrates organizational and technical protective measures to sustainably strengthen cyber resilience.
Evolution of the threat landscape through AI-assisted phishing
According to analyses by the European Union Agency for Cybersecurity (ENISA), approximately 60% of all cyber incidents in Europe are based on social engineering scenarios. The introduction of generative AI models has drastically changed the quality and scalability of these attacks. Grammatical errors and awkward phrasing are largely a thing of the past; instead, attackers can now automatically tailor messages to the specific context of the recipient. According to current data from ENISA , 80% of the social engineering attacks analyzed already showed signs of AI assistance. This makes it significantly harder to manually identify suspicious emails during the workday.

Adoption of technical and organizational protective measures
Despite the shift in attack quality, studies reveal gaps in the implementation of fundamental security mechanisms:
- Phishing tests in large enterprises: The Data Breach Report shows that 46% of companies with over €100 million in revenue do not conduct phishing simulations.
- Use of multi-factor authentication (MFA): Among companies with an annual revenue of less than €50 million, 53% do not use multi-factor authentication Stolen credentials allow direct access to the system without exploiting technical software vulnerabilities and are particularly easy to exploit without MFA protection.
Research by KnowBe4 also shows that without prior training or testing, on average 33% of employees click on malicious links in phishing emails.
Phishing simulations as an organizational measure
Phishing simulations serve as an organizational measure to verify and specifically strengthen security awareness within an organization under controlled conditions. If an employee reacts to a simulated message during a test, they receive immediate feedback explaining the specific characteristics of that phishing email. Experience shows that such repeated test series reduce the click rate on potentially harmful links from over 30% to under 5%.
The two-pillar model: Phishing training and Managed Detection and Response (MDR)
Since organizational measures cannot completely rule out clicks on phishing emails, a comprehensive security architecture requires the addition of technical protection systems. Baobab Risk Solutions combines preventive training approaches with technical monitoring systems.
Pillar 1: Context-based phishing simulations
The phishing simulations are tailored to each individual company. They take into account the software infrastructure in use as well as publicly available data points to create realistic test scenarios.
- Commissioning: Provision of the free training framework.
- Simulation: Execution of simulated phishing campaigns during ongoing operations.
- Evaluation: Data-driven analysis of interaction rates and security gaps.
- Training: Targeted professional development to consolidate security awareness.
Pillar 2: Technical protection via Managed Detection and Response (MDR)
The Baobab MDR Service monitors endpoints and networks 24/7 for anomalous behavior and unauthorized access attempts. Should employees accidentally open malicious content or enter credentials on compromised sites, automated control mechanisms based on the zero-trust principle take effect: if the system detects suspicious follow-up activity after a link click, the affected components are immediately isolated to effectively prevent any spread throughout the corporate network. In this way, the Baobab MDR Service technically mitigates human error in daily operations, complementing preventive awareness training with a reactive, real-time layer of protection.
Achieving Cyber Resilience Through a Holistic Approach
Given the rapid evolution of AI-powered attack methods, a single security mechanism is no longer sufficient to permanently secure corporate networks. Effective protection against modern phishing scenarios requires the interplay of targeted organizational prevention and reliable technical control. While practical phishing simulations sustainably strengthen employee security awareness, a continuous Managed Detection and Response (MDR) service provides the necessary safety net in an emergency. Only this combination of trained teams and an intelligent security architecture enables companies of all sizes to minimize risks and permanently strengthen their digital resilience against future threats.


