Social Engineering
Phishing & vishing — Authorized phishing, vishing and pretext campaigns that measure how your people respond under realistic pressure — and, more usefully, how quickly they report. The goal is not a click-rate to put in a board deck. It is finding out whether your reporting and response process works when someone does fall for it.
Is this the right engagement?
- You want a baseline measurement of phishing susceptibility and reporting rate
- You have security awareness training and no evidence of whether it changed behaviour
- You need a social engineering component for a compliance programme or a red team
- You want to test the response process, not just the people
Deliverables
- Campaign results with click, credential-submission and reporting rates over time
- Pretext analysis explaining what worked, what did not, and why
- Response-process findings: how quickly reports reached your security team and what happened next
- Aggregate reporting by department or population, never individual blame lists
- Executive summary with prioritized awareness and process recommendations
- Awareness debrief material written for the people who were targeted
Engagements in this solution
Each engagement is scoped around what you are actually running. Where pricing is standardized you can estimate it online in a couple of minutes.
Phishing Assessment
ESTIMATE ONLINEAuthorized email campaigns using pretexts developed for your organization, measuring click, credential-submission and reporting rates.
Vishing Assessment
ESTIMATE ONLINEAuthorized voice-based pretext calls testing help-desk and staff verification procedures, including password-reset and MFA-reset workflows.
How the work is run
The same sequence runs underneath every engagement in this solution — specialised here for social engineering.
Scope & authorize
Target population, pretext themes, out-of-bounds individuals and escalation contacts agreed in writing before anything is sent.
Develop pretexts
Pretexts built from information genuinely available about your organization, reviewed with you before launch.
Deliver campaigns
Authorized delivery with full tracking of clicks, submissions and reports, and immediate containment if a campaign has unintended reach.
Measure response
Reporting rate and response time measured against the campaign timeline — the part that actually predicts outcomes.
Report & brief
Aggregate results, pretext analysis and process findings, walked through with security and people leadership.
Re-measure
An optional follow-up campaign measures whether the intervention changed behaviour.
What to expect, and when
Indicative for a standard scope. Your dates are confirmed in writing before any testing begins.
| Stage | Duration | What happens |
|---|---|---|
| Scope & authorize | 2–5 business days | Targets, objectives and rules of engagement agreed in writing. Authorization signed before anything is touched. |
| Test & exploit | 5–10 business days | Manual testing mapped to real attacker tradecraft. Findings are exploited and chained, not just flagged. |
| Report & brief | 3–5 business days | Findings report delivered, then walked through live with the engineers and the executives who own the risk. |
| Remediate & retest | Within 30 days | One bounded retest validates fixes against every reported finding. |
| Total | 3–4 weeks | From signed authorization to retest report, for a standard scope. |
What you can hold us to
Commitments that are checkable, not adjectives.
Click rate alone predicts very little. We report how many people raised the alarm, and how fast.
Individuals are never named in reporting. Campaigns are designed to improve process, not to discipline staff.
Every campaign has agreed out-of-bounds individuals and an immediate stop procedure.
Submitted credentials are recorded as an event, not stored.
Nothing is sent until the agreement and rules of engagement are executed.
Before you ask us
Do you store the passwords people submit?
No. A submission is recorded as an event with a timestamp; the credential itself is discarded.
Will you name the people who clicked?
No. Results are reported in aggregate, by population or department.
Can you test the help desk specifically?
Yes — vishing against password-reset and MFA-reset workflows is one of the most revealing tests we run.