Social Engineering
Targeted phishing, vishing and pretexting campaigns modelled on the crews actually operating against your sector.
What you receive
- Campaigns modelled on live sector-specific lures
- Departmental risk scoring with trend over time
- Targeted follow-up training where it is needed
When you need this
Three situations that call for it. If none of them is yours, it probably is not the right spend.
Finance nearly paid a changed bank account
After a near-miss the useful question is not whether one person was careless. A pretexting campaign against the same route shows whether the payment-change process contains a step that verifies, or only a step that approves.
Your click rate looks too good to believe
Generic templates with a misspelt sender domain teach people to spot generic templates. Lures built from your suppliers, your tooling and the language your staff genuinely receive produce a number that means something — usually a worse one.
The helpdesk resets MFA over the phone
Account recovery is where a caller with a plausible story converts a name into a working session. Vishing against that desk tests the identity-proofing script under pressure, including what the agent does when the caller is angry and senior.
How it runs
Scoping call
Thirty minutes with an engineer, not a sales development rep. We establish what you actually need and tell you plainly if it is not us.
Written proposal
Fixed scope, fixed price, named delivery team, and the rules of engagement in writing before anyone touches a system.
Delivery
Weekly written status and a direct channel to the delivery lead. Critical findings are escalated the moment they are confirmed, never held back for the report.
Readout and retest
A working session with your team, an executive summary for your board, and a remediation retest included in the original scope rather than quoted separately.
No lock-in
Scoping costs nothing and carries no obligation. If the answer is that you do not need this, that is a legitimate outcome of the call.
Who turns up
The engineer on your scoping call is on the delivery team. We do not hand you to a different group after signature.
Scope
What this does not cover
This measures people and process. Whether your gateway would have stopped the message is a technical control question, covered by business email protection.
Reporting is by department and by route abused. We do not supply per-person lists, and a campaign run to identify individuals for discipline stops being useful.
A campaign is not a training programme — it tells you where teaching is needed, not what your staff will still remember next quarter.
- PCI DSS 4.0.1 Req. 12.6.3.1
- Requires the awareness programme to cover phishing and social engineering, alongside training at hire and at least annually.
- ISO/IEC 27001:2022 Annex A 6.3
- Requires awareness, education and training appropriate to the role and updated as policy changes; testing shows where it has not landed.
- GDPR Art. 6 and Art. 88
- Simulation results identify individuals, so processing needs a lawful basis, and employment-context rules vary between member states.
If the scope is wrong
Tell us on the call. Re-scoping before we start costs nothing; discovering it at the readout costs you the engagement.
Questions
The ones we are actually asked.
Is deceiving our own staff legally safe?
It is lawful with proper authorisation, but the results are personal data and in several member states employee monitoring engages works-council consultation before anything is sent. Settling that is part of scoping, not an afterthought.
Will this damage trust in the security team?
It can, if the exercise is built to catch people out and the results are used against them. Saying openly that campaigns happen without saying when, and reporting by group rather than by name, keeps the exercise usable more than once.
What click rate should we be aiming for?
Click rate is the weaker half of the measurement — report rate and time to report matter more, because one fast report lets a defender act while the campaign is still running. A low click rate with no reports at all is a poor result.
See what an attacker sees
We map your external attack surface the way an adversary does — exposed assets, leaked credentials, impersonation domains. No agent, no access, no cost.
30 min
A scoping call, with an engineer rather than a sales rep.
What it costs
Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.
Under attack now?
Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.