The human factor

Social Engineering

Most serious incidents do not start with a firewall. They start with a person. We test the human layer with realistic, custom-built campaigns across email, phone, text and in person, always controlled and within agreed rules, then turn the results into training that makes your team harder to fool.

Social Engineering

In plain terms

Your people are the real perimeter

Attackers rarely break in through a clever exploit anymore. They log in, using a password an employee typed into a convincing fake page, or handed over on a well-scripted phone call, or a door someone politely held open for a stranger in a hi-vis vest. Technology alone cannot stop this, because it targets human trust, not a system flaw. The only way to know how your organisation would respond is to safely test it.

We build campaigns that look and feel like the real thing, tailored to your organisation, and measure exactly how people react. The goal is never to catch anyone out or assign blame. It is to give you a clear, honest baseline, and to turn every click into a teaching moment that makes your whole team, and its procedures, harder to manipulate.

There is an important reason to do this deliberately rather than wait for a real attack to teach the lesson: the first time your people meet a convincing scam should be one you designed, in a safe setting, where a mistake costs nothing and becomes a lasting lesson. Done well, a programme like this steadily moves your organisation from “we hope people are careful” to “we can show, with numbers, that our team spots and reports these attacks.”

Scope & coverage

What we test

Phishing (email)

Realistic, custom-built email campaigns at the difficulty you choose, from broad awareness tests to highly targeted spear phishing.

  • Custom sender domains and convincing landing pages
  • Credential-capture and attachment scenarios
  • Finance, IT-support, HR and delivery pretexts
  • Difficulty tuned from obvious to expert-level

Vishing (phone) & smishing (SMS)

Manipulation that never touches the inbox: voice and text pretexts that test whether staff act on a convincing caller or a well-timed message.

  • IT-support and helpdesk impersonation calls
  • Password-reset and MFA-fatigue scenarios
  • SMS lures with time pressure and authority cues
  • Tests of your phone-based verification procedures

Physical & mystery guest

A tester poses as a delivery driver, contractor or new employee and attempts to walk in, exactly as a real intruder would.

  • Tailgating through controlled doors
  • Reception and visitor-procedure pretexting
  • Reaching desks, meeting rooms and network ports
  • Testing whether people and process, not just locks, stop entry

Security Awareness Training

The other half of the job: practical training built on your own campaign results, so learning is concrete, relevant and measurable.

  • Sessions shaped by what your test actually found
  • Tailored to users, management and IT
  • Recognising lures, safe credential handling, reporting
  • Optional re-test to prove the improvement

OSINT-informed targeting

A side capability that makes every scenario realistic: we research what is public about your organisation, just as an attacker would.

  • Exposed emails, roles and reporting lines
  • Credentials leaked in past third-party breaches
  • Details that make a pretext believable
  • A clear view of what to remove from public sight

The value

What you gain

Measurable, honest results

Opens, clicks, submitted credentials and, crucially, who reported the attempt. A real baseline you can track and improve over time.

A more resilient team

Every simulation doubles as training. People who have safely met a realistic attack are far more likely to spot the real one.

Progress you can prove

Run as a one-off or as a rolling programme with quarterly scenarios of increasing difficulty, and show measurable improvement to your board.

Methodology

How we work

01

Scope & scenarios

We agree the audiences, channels, difficulty and pretexts together, and keep everything ethical and within bounds.

02

Build & launch

We create the infrastructure, content and, where relevant, the on-site plan, then run the campaign over an agreed window.

03

Measure

We record every interaction safely: opens, clicks, calls, entries and reports, without ever storing real passwords.

04

Debrief & train

We present the results to your team and turn them into practical guidance and training people will actually remember.

Custom infrastructureMFA & Conditional Access reviewGDPR-aware handlingNo real credentials storedFully authorised & scoped

For the technical reader

Under the hood

Campaigns run on dedicated, custom-built infrastructure with realistic sender domains and landing pages, so the test reflects what a real adversary would actually send, not an obvious template every filter already blocks. We tune difficulty precisely, from a generic lure any alert user should catch to a targeted, well-researched message crafted for a specific team, and we can combine channels the way real attacks do: an email that references a phone call that follows a text.

We handle data responsibly throughout. Submitted passwords are never stored, results are reported at the level of trends and teams rather than singling people out, and the whole exercise is designed to build a positive reporting culture instead of a culture of blame. Where captured credentials are involved, we also check whether MFA and Conditional Access would have blocked the login, so you learn about your technical safety net as well as your people.

We also treat social engineering as a measurement of your controls, not only your people. When someone does enter a credential, we look at whether MFA, Conditional Access, or impossible-travel rules would have stopped the login; when a caller talks their way toward a password reset, we examine the helpdesk procedure that let them get that far. The outcome is a picture of both layers of defence, the human and the technical, and where each can be tightened.

Deliverables

What you receive

Executive summary

Clear, business-level conclusions written for management and decision makers, no jargon required.

Technical findings by risk

Every issue classified from Critical to Low with a CVSS score, so your team always knows what to fix first.

Evidence for every finding

Screenshots, logs and a proof of concept for each issue, so nothing is theoretical and everything is verifiable.

Prioritised remediation plan

Concrete, actionable fixes: urgent security measures first, strategic improvements next.

Debrief workshop

A walkthrough of the findings with your team, including questions and answers and next steps.

Retest of key findings

Confirmation that the most important gaps have actually been closed after your team has fixed them.

Who it's for

When social engineering testing makes sense

Your staff handle payments, customer data, or sensitive information that an attacker would find valuable.
You have invested heavily in technology but have never tested the people who use it.
You are rolling out or renewing security awareness training and want a real baseline to measure it against.
Your finance or HR teams are exposed to invoice fraud and business email compromise.
You need to demonstrate, for NIS2 or an audit, that human risk is being actively managed.
You want an ongoing programme that proves your people are getting harder to fool over time.

A natural first step

Social engineering is often the realistic opening move of a black-box penetration test or a full red team engagement. Run it on its own to measure and train your people, or as the first stage of a wider assessment that shows exactly how far a single click, call or open door could let an attacker go.

Questions & answers

Social engineering: questions and answers

Isn't this just tricking our own employees?

The aim is never to catch people out or assign blame. It is to give everyone a safe encounter with a realistic attack and turn it into learning. Results are reported as trends across teams, never as a list of who failed, and the whole exercise is designed to build a culture where people report mistakes early.

Do you store the passwords people type in?

Never. We record that a credential was submitted, which is what matters for the metrics, but the actual password is never stored. The exercise is designed from the start to handle data responsibly and in line with GDPR.

Is phishing simulation allowed under GDPR?

Yes, when it is done properly. The testing is fully authorised by your organisation, scoped in advance, and the data is handled carefully and reported at the level of teams and trends. We agree the rules of engagement with you before anything starts.

What is a “mystery guest” or physical test?

It is the in-person side of social engineering. A tester poses as a delivery driver, contractor, or new employee and tries to walk into your building, tailgating through doors or talking past reception, to see whether your people and procedures, not just your locks, actually stop an intruder.

Will you tell us which individuals failed?

No. We report results by team and by trend so you can target training where it is needed, without singling anyone out. Naming individuals damages the reporting culture that keeps you safe.

How do we actually improve after a test?

We turn the findings into focused awareness training, then, if you wish, run the simulation again to prove the change. Run as a rolling programme with increasing difficulty, it produces a metric you can report and improve every quarter.

Icon

Trusted Protection for Your Digital World

Your safety is our mission. Your trust is our commitment

Click below to schedule your free risk assessment and learn how we can help protect your world.

Start Protecting Your Business

BackgroundShape