Frequently Asked Questions
Quickly find answers to your cybersecurity questions.
Smishing (SMS): SMS have an open rate above 90%, compared to 20 to 30% for emails. Messages typically imitate a delivery alert (postal service, DHL), a banking warning, or a government message. The link redirects to a fake login page. On mobile, the URL is often truncated and difficult to verify.
Vishing (voice): the attacker calls their victim directly, posing as IT support, a bank, or Microsoft. Real-time pressure and the human voice bypass the usual defenses. AI-generated voice deepfakes can now imitate the voice of a known colleague or manager.
The golden rule in both cases: never provide sensitive information following an unsolicited message or call — call the organization back directly via a known official number.
The effectiveness of cybersecurity training can be measured concretely using behavioural indicators:
- Click rate on simulated phishing — before/after training. A good programme reduces this rate by more than 70% within 6 months.
- Reporting rate — the number of employees who actively report a suspicious phishing attempt.
- Academy completion score — percentage of completed modules and quiz results.
- Trend over time — PhishTrainer dashboard with 12-month history.
These metrics are available in the Bexxo dashboard and can be exported for nDSG compliance reports.
- Perfectly written emails — gone are the spelling mistakes that used to help detect phishing. LLMs generate flawless emails in perfect English, adapted to the tone of the targeted company. AI-generated emails have a click rate four times higher than manually crafted ones (APWG / Keepnet 2025).
- Personalization at scale — AI can analyze a target's LinkedIn profile, public posts, and company website to create an ultra-realistic spear phishing in seconds. What used to take a human attacker hours now takes seconds.
- Voice and video deepfakes — vishing calls imitating a manager's voice, or entire video conferences with deepfake avatars, have already been used to trigger fraudulent bank transfers (documented cases in 2024 in Hong Kong: 25 million USD lost).
For an SME with 20 to 50 employees, the typical programme runs over 3 to 6 months:
- Week 1: set up PhishTrainer, send the first baseline phishing campaign.
- Months 1-2: Bexxo Academy access for all employees, introductory modules (30 to 45 min per module).
- Months 3-6: monthly phishing campaigns, targeted reminders for at-risk employees, progress report.
The setup is handled by Bexxo — no internal technical skills required. Monthly administration time is less than 2 hours for the HR or IT manager.
The nDSG (Swiss Federal Act on Data Protection, in force since September 2023) requires companies to implement organisational measures to protect personal data. Staff training is explicitly recommended by the Federal Data Protection and Information Commissioner (FDPIC) as an essential organisational measure. In the event of a data breach, the absence of documented training may increase the company's liability. Bexxo provides a monitoring report that serves as proof of due diligence in the event of an FDPIC audit. Fines of up to CHF 250,000 for data controllers in the event of a breach.