SOLUTION

Social Engineering

Phishing & vishing — Authorized phishing, vishing and pretext campaigns that measure how your people respond under realistic pressure — and, more usefully, how quickly they report. The goal is not a click-rate to put in a board deck. It is finding out whether your reporting and response process works when someone does fall for it.

WHO THIS IS FOR

Is this the right engagement?

  • You want a baseline measurement of phishing susceptibility and reporting rate
  • You have security awareness training and no evidence of whether it changed behaviour
  • You need a social engineering component for a compliance programme or a red team
  • You want to test the response process, not just the people
When it is notIf the goal is to punish employees who click, we are not the right vendor. Campaigns are designed to improve reporting, and results are reported in aggregate.
WHAT YOU RECEIVE

Deliverables

  • Campaign results with click, credential-submission and reporting rates over time
  • Pretext analysis explaining what worked, what did not, and why
  • Response-process findings: how quickly reports reached your security team and what happened next
  • Aggregate reporting by department or population, never individual blame lists
  • Executive summary with prioritized awareness and process recommendations
  • Awareness debrief material written for the people who were targeted
METHODOLOGY

How the work is run

The same sequence runs underneath every engagement in this solution — specialised here for social engineering.

Scope & authorize

Target population, pretext themes, out-of-bounds individuals and escalation contacts agreed in writing before anything is sent.

Develop pretexts

Pretexts built from information genuinely available about your organization, reviewed with you before launch.

Deliver campaigns

Authorized delivery with full tracking of clicks, submissions and reports, and immediate containment if a campaign has unintended reach.

Measure response

Reporting rate and response time measured against the campaign timeline — the part that actually predicts outcomes.

Report & brief

Aggregate results, pretext analysis and process findings, walked through with security and people leadership.

Re-measure

An optional follow-up campaign measures whether the intervention changed behaviour.

TIMELINE

What to expect, and when

Indicative for a standard scope. Your dates are confirmed in writing before any testing begins.

StageDurationWhat happens
Scope & authorize2–5 business daysTargets, objectives and rules of engagement agreed in writing. Authorization signed before anything is touched.
Test & exploit5–10 business daysManual testing mapped to real attacker tradecraft. Findings are exploited and chained, not just flagged.
Report & brief3–5 business daysFindings report delivered, then walked through live with the engineers and the executives who own the risk.
Remediate & retestWithin 30 daysOne bounded retest validates fixes against every reported finding.
Total3–4 weeksFrom signed authorization to retest report, for a standard scope.
HOW WE WORK

What you can hold us to

Commitments that are checkable, not adjectives.

Reporting rate is the headline metric

Click rate alone predicts very little. We report how many people raised the alarm, and how fast.

Aggregate results only

Individuals are never named in reporting. Campaigns are designed to improve process, not to discipline staff.

Contained by design

Every campaign has agreed out-of-bounds individuals and an immediate stop procedure.

Credentials never retained

Submitted credentials are recorded as an event, not stored.

Testing under authorization only

Nothing is sent until the agreement and rules of engagement are executed.

QUESTIONS

Before you ask us

Do you store the passwords people submit?

No. A submission is recorded as an event with a timestamp; the credential itself is discarded.

Will you name the people who clicked?

No. Results are reported in aggregate, by population or department.

Can you test the help desk specifically?

Yes — vishing against password-reset and MFA-reset workflows is one of the most revealing tests we run.

See a price range in two minutes.

Select your scope in the estimator and get an indicative range, an outline timeline and what is included — no call required.

Choose which optional cookies BNO Security Group may use. You can update this choice at any time.

Necessary cookiesRequired for security, core features, and consent storage.
Always active
Analytics cookiesHelp us understand site traffic and improve the website.
Advertisement cookiesSupport relevant campaign measurement and advertising.