LureLab · AI phishing simulations

Simulated phishing. Measurable resilience.

One platform, three modules. Simulations, threat monitoring and employee alerts, with a full GDPR compliance stack included in the service.

EU hostingAZOP approvedCSA Art. 21GDPR
Request a demoQuote on request
📱SMS
📧Email
📞Voice
💬WhatsApp
🔏QR code
🔑OAuth

Six simulation channels: attackers do not use email alone, and neither do we.

One platform · Three modules

From simulation to real threat

01
Phishing simulations
Core module

Multi-channel simulations tailored to your organisation and sector. Scenarios are AI-generated, in Croatian or English, with realistic senders.

  • Six channels: SMS, email, voice, WhatsApp, QR, OAuth
  • Wave cycles with training after every wave
  • Resilience report per organisation: a measurable evidence base
02
Cyber Watch
Threat monitoring

Real-time monitoring of SMS threats. Visibility into active smishing campaigns targeting local users.

  • Real-time SMS threat monitoring
  • Signals on active campaigns by sector
  • Basis for timely internal measures
03
Active Guard
Employee alerts

SMS and email alerts to employees, triggered by the CISO when a real threat exists. Targeted and controlled, not automated.

  • Alert triggered by the CISO, not an algorithm
  • SMS and email channel to all employees
  • Documented trail of every alert
ℹ Cyber Watch monitors threats; Active Guard alerts employees. Two modules, two functions, one platform.
Compliance stack · Included

A simulation without paperwork is a legal risk

A phishing simulation is processing of employees' personal data. LureLab ships with the documentation this requires, included in the service.

🧭

DPIA wizard

Guided data protection impact assessment

📋

ROPA

Records of processing activities

📄

DPA templates

Processing agreements under GDPR Art. 28

🏛️

Works council

Notification under Labour Act Art. 150 before simulations

🗁️

Audit log

Trail of all actions on the platform

Why active testing

Resilience is built through cycles, not workshops

Most incidents start with an employee's click. A one-off workshop does not change that risk; a continuous cycle of testing and training turns it into a measurable metric that drops wave by wave.

01
Simulation
A wave tailored to the organisation, unannounced
02
Measurement
Who opened, clicked, reported
03
Training
Targeted, based on the wave's results
04
Repeat
A new wave, a new channel, higher realism
🎯

Testing, not theory

An employee who once clicked a simulation remembers it better than any lecture. Experience is the strongest training.

📈

A trend, not a snapshot

One test shows a moment. Cycles across the year show a resilience trend: the evidence base auditors ask for.

⚖️

A legal obligation

CSA Art. 21(2) requires staff training. A continuous programme with reports is proof of implementation, not an attendance slip.

Next step

See LureLab live

A demo tailored to your sector. Pricing and scope are defined by a quote on request.

Request a demo
Contact
ID Shield Protect Ltd. · Zagreb
📞 +385 98 470-495
📧 info@idshield.com.hr
🌐 lurelab.eu