Social Engineering
Most serious incidents do not start with a firewall. They start with a person. We test the human layer with realistic, custom-built campaigns across email, phone, text and in person, always controlled and within agreed rules, then turn the results into training that makes your team harder to fool.
In plain terms
Your people are the real perimeter
Attackers rarely break in through a clever exploit anymore. They log in, using a password an employee typed into a convincing fake page, or handed over on a well-scripted phone call, or a door someone politely held open for a stranger in a hi-vis vest. Technology alone cannot stop this, because it targets human trust, not a system flaw. The only way to know how your organisation would respond is to safely test it.
We build campaigns that look and feel like the real thing, tailored to your organisation, and measure exactly how people react. The goal is never to catch anyone out or assign blame. It is to give you a clear, honest baseline, and to turn every click into a teaching moment that makes your whole team, and its procedures, harder to manipulate.
There is an important reason to do this deliberately rather than wait for a real attack to teach the lesson: the first time your people meet a convincing scam should be one you designed, in a safe setting, where a mistake costs nothing and becomes a lasting lesson. Done well, a programme like this steadily moves your organisation from “we hope people are careful” to “we can show, with numbers, that our team spots and reports these attacks.”
Scope & coverage
What we test
Phishing (email)
Realistic, custom-built email campaigns at the difficulty you choose, from broad awareness tests to highly targeted spear phishing.
- Custom sender domains and convincing landing pages
- Credential-capture and attachment scenarios
- Finance, IT-support, HR and delivery pretexts
- Difficulty tuned from obvious to expert-level
Vishing (phone) & smishing (SMS)
Manipulation that never touches the inbox: voice and text pretexts that test whether staff act on a convincing caller or a well-timed message.
- IT-support and helpdesk impersonation calls
- Password-reset and MFA-fatigue scenarios
- SMS lures with time pressure and authority cues
- Tests of your phone-based verification procedures
Physical & mystery guest
A tester poses as a delivery driver, contractor or new employee and attempts to walk in, exactly as a real intruder would.
- Tailgating through controlled doors
- Reception and visitor-procedure pretexting
- Reaching desks, meeting rooms and network ports
- Testing whether people and process, not just locks, stop entry
Security Awareness Training
The other half of the job: practical training built on your own campaign results, so learning is concrete, relevant and measurable.
- Sessions shaped by what your test actually found
- Tailored to users, management and IT
- Recognising lures, safe credential handling, reporting
- Optional re-test to prove the improvement
OSINT-informed targeting
A side capability that makes every scenario realistic: we research what is public about your organisation, just as an attacker would.
- Exposed emails, roles and reporting lines
- Credentials leaked in past third-party breaches
- Details that make a pretext believable
- A clear view of what to remove from public sight
The value
What you gain
Measurable, honest results
Opens, clicks, submitted credentials and, crucially, who reported the attempt. A real baseline you can track and improve over time.
A more resilient team
Every simulation doubles as training. People who have safely met a realistic attack are far more likely to spot the real one.
Progress you can prove
Run as a one-off or as a rolling programme with quarterly scenarios of increasing difficulty, and show measurable improvement to your board.
Methodology
How we work
Scope & scenarios
We agree the audiences, channels, difficulty and pretexts together, and keep everything ethical and within bounds.
Build & launch
We create the infrastructure, content and, where relevant, the on-site plan, then run the campaign over an agreed window.
Measure
We record every interaction safely: opens, clicks, calls, entries and reports, without ever storing real passwords.
Debrief & train
We present the results to your team and turn them into practical guidance and training people will actually remember.
For the technical reader
Under the hood
Campaigns run on dedicated, custom-built infrastructure with realistic sender domains and landing pages, so the test reflects what a real adversary would actually send, not an obvious template every filter already blocks. We tune difficulty precisely, from a generic lure any alert user should catch to a targeted, well-researched message crafted for a specific team, and we can combine channels the way real attacks do: an email that references a phone call that follows a text.
We handle data responsibly throughout. Submitted passwords are never stored, results are reported at the level of trends and teams rather than singling people out, and the whole exercise is designed to build a positive reporting culture instead of a culture of blame. Where captured credentials are involved, we also check whether MFA and Conditional Access would have blocked the login, so you learn about your technical safety net as well as your people.
We also treat social engineering as a measurement of your controls, not only your people. When someone does enter a credential, we look at whether MFA, Conditional Access, or impossible-travel rules would have stopped the login; when a caller talks their way toward a password reset, we examine the helpdesk procedure that let them get that far. The outcome is a picture of both layers of defence, the human and the technical, and where each can be tightened.
Deliverables
What you receive
Executive summary
Clear, business-level conclusions written for management and decision makers, no jargon required.
Technical findings by risk
Every issue classified from Critical to Low with a CVSS score, so your team always knows what to fix first.
Evidence for every finding
Screenshots, logs and a proof of concept for each issue, so nothing is theoretical and everything is verifiable.
Prioritised remediation plan
Concrete, actionable fixes: urgent security measures first, strategic improvements next.
Debrief workshop
A walkthrough of the findings with your team, including questions and answers and next steps.
Retest of key findings
Confirmation that the most important gaps have actually been closed after your team has fixed them.
Who it's for
When social engineering testing makes sense
A natural first step
Social engineering is often the realistic opening move of a black-box penetration test or a full red team engagement. Run it on its own to measure and train your people, or as the first stage of a wider assessment that shows exactly how far a single click, call or open door could let an attacker go.
Questions & answers
Social engineering: questions and answers
Isn't this just tricking our own employees?
The aim is never to catch people out or assign blame. It is to give everyone a safe encounter with a realistic attack and turn it into learning. Results are reported as trends across teams, never as a list of who failed, and the whole exercise is designed to build a culture where people report mistakes early.
Do you store the passwords people type in?
Never. We record that a credential was submitted, which is what matters for the metrics, but the actual password is never stored. The exercise is designed from the start to handle data responsibly and in line with GDPR.
Is phishing simulation allowed under GDPR?
Yes, when it is done properly. The testing is fully authorised by your organisation, scoped in advance, and the data is handled carefully and reported at the level of teams and trends. We agree the rules of engagement with you before anything starts.
What is a “mystery guest” or physical test?
It is the in-person side of social engineering. A tester poses as a delivery driver, contractor, or new employee and tries to walk into your building, tailgating through doors or talking past reception, to see whether your people and procedures, not just your locks, actually stop an intruder.
Will you tell us which individuals failed?
No. We report results by team and by trend so you can target training where it is needed, without singling anyone out. Naming individuals damages the reporting culture that keeps you safe.
How do we actually improve after a test?
We turn the findings into focused awareness training, then, if you wish, run the simulation again to prove the change. Run as a rolling programme with increasing difficulty, it produces a metric you can report and improve every quarter.

