Social engineering assessments
Attackers rarely break in when someone will let them in. We test how your people, processes and buildings respond to phishing, phone calls, impersonation and a confident stranger at the door.
The human step in most breaches
Most breaches include a human step: a convincing email, a call to the help desk asking for a password reset, a supplier invoice with new bank details. Technical controls reduce the risk, but people and processes decide the outcome.
We test the processes, not the individuals. The aim is to find where a well-meaning person can be led into a mistake, and to change the process so it cannot happen again.
What we test
Phishing
Email campaigns that mirror current lures, from credential harvesting to payload delivery. More on phishing simulation.
Vishing
Phone pretexting against help desks, finance and reception, including password and MFA reset requests.
Smishing and messaging
Text message and messaging app lures, where in scope.
Impersonation
Posing as suppliers, contractors, new starters or executives, by email, phone or in person.
Physical intrusion
Tailgating, badge cloning and access to offices and server rooms. More on physical testing.
Open-source reconnaissance
What an attacker can learn about your organisation and staff from public sources, used to make the tests realistic.
How the engagement runs
Agree scenarios
We agree targets, pretexts and boundaries, including themes that are off limits, such as health or personal matters.
Reconnaissance
We gather what an attacker could find about your organisation and the people in scope.
Run the campaign
Emails, calls or visits run over an agreed period, with your sponsor kept informed.
Report without blame
Results by team and process, not by named individual, with process and training changes that reduce the risk.
What you get
- Results by team, role and process, not a list of names.
- The process weaknesses that made each success possible.
- Practical changes to verification, reporting and training.
When to commission it
- When you have never measured how staff respond to targeted attacks.
- After changing help desk, finance or reception procedures.
- Following a real incident that involved deception.
- Alongside awareness training, to measure whether it works.
Questions we get asked
Will you name the staff who fall for it?
Do staff need to be told beforehand?
Is it legal?
Which test should we start with?
Related
Phishing simulation
Phishing simulations that mirror the lures attackers use now. Measure clicks, credential entry and reporting rates, then improve them over time.
Read more →Physical intrusion
Physical penetration testing: tailgating, badge cloning, reception pretexts and access to server rooms. Could someone walk in and leave with your data?
Read more →Red teaming
Covert, objective-led red team engagements that test whether your people, processes and technology detect and stop a determined attacker.
Read more →SavountFrom Perimeter to Identity: The New SaaS Attack Frontier
Single sign-on, session tokens and MFA fatigue: why identity is now the main attack surface for SaaS, and how to defend it.
Read the article →