APOLLOSEC

Social engineering assessments

Attackers rarely break in when someone will let them in. We test how your people, processes and buildings respond to phishing, phone calls, impersonation and a confident stranger at the door.

The human step in most breaches

Most breaches include a human step: a convincing email, a call to the help desk asking for a password reset, a supplier invoice with new bank details. Technical controls reduce the risk, but people and processes decide the outcome.

We test the processes, not the individuals. The aim is to find where a well-meaning person can be led into a mistake, and to change the process so it cannot happen again.

What we test

  • Phishing

    Email campaigns that mirror current lures, from credential harvesting to payload delivery. More on phishing simulation.

  • Vishing

    Phone pretexting against help desks, finance and reception, including password and MFA reset requests.

  • Smishing and messaging

    Text message and messaging app lures, where in scope.

  • Impersonation

    Posing as suppliers, contractors, new starters or executives, by email, phone or in person.

  • Physical intrusion

    Tailgating, badge cloning and access to offices and server rooms. More on physical testing.

  • Open-source reconnaissance

    What an attacker can learn about your organisation and staff from public sources, used to make the tests realistic.

How the engagement runs

  1. Agree scenarios

    We agree targets, pretexts and boundaries, including themes that are off limits, such as health or personal matters.

  2. Reconnaissance

    We gather what an attacker could find about your organisation and the people in scope.

  3. Run the campaign

    Emails, calls or visits run over an agreed period, with your sponsor kept informed.

  4. Report without blame

    Results by team and process, not by named individual, with process and training changes that reduce the risk.

What you get

  • Results by team, role and process, not a list of names.
  • The process weaknesses that made each success possible.
  • Practical changes to verification, reporting and training.

When to commission it

  • When you have never measured how staff respond to targeted attacks.
  • After changing help desk, finance or reception procedures.
  • Following a real incident that involved deception.
  • Alongside awareness training, to measure whether it works.

Questions we get asked

Will you name the staff who fall for it?

We report by team, role and process. Individual results are shared only if you ask for them in advance and staff have been told it may happen. Blaming individuals makes people less likely to report the next real attack.

Do staff need to be told beforehand?

Not about specific tests. Many organisations tell staff that simulated attacks happen from time to time, which is good practice and still lets the test be realistic.

Is it legal?

Yes, with proper authorisation. We work under a signed scope and letters of authority, and avoid pretexts that would be unlawful or harmful, such as impersonating the police or exploiting personal crises.

Which test should we start with?

Phishing simulation usually gives the broadest picture for the effort. Help desk vishing is often next, because password and MFA reset processes are a common route into otherwise well-protected organisations.

Find out who would let an attacker in.

Talk to us