most phishing simulations make your coworkers aware of just clicking on any link or attachment in their mail. the link will send them towards a pretty landing page stating they are lucky this is just a phishing test.
We on the other hand want to know the behaviour of the coworkers before making them aware. A blank landing page of a google page or just no page at all would be nice, and the reporting after some weeks or so will be sent to the CEO to make the CEO aware of the risks if not taking any measurements. Any tips how to get the dipstick in the organisation to get an idea how bad it is?

We just rolled knowbe4 and they have a blank landing page template. I did the same thing to gauge our baseline before announcing things to staff.

Morning

Do you use O365 per chance? What about the attack simulations and reports you can gather there to present to the CEO. We use it here and the metrics are nice to show.

Would that work for you?