Social Engineering & Phishing
Realistic phishing campaigns and social engineering simulations that test your people and your technical controls, with clear metrics at the end.
What is a social engineering assessment?
A social engineering assessment tests whether an attacker can trick your people into handing over access. Phishing email gives attackers the most common way in: a convincing message that gets someone to click a link, enter a password or open a file. A good assessment measures your employees, and it also measures the technical controls that should stop the attack before it ever reaches them, like email filtering, link protection and multi-factor authentication.
We already run phishing training. How is this different?
Training platforms send template emails on a schedule to build awareness, and they do that job well. A social engineering engagement works like a real attack. We build lures around your organization: your vendors, your software, your internal processes. We register lookalike domains and craft messages that slip past your filters.
When someone enters a password, the useful question becomes what that password would let an attacker do. With your approval, we check whether your multi-factor authentication holds up and what an attacker could reach with the access we captured. A training platform can't tell you that.
Will you tell us who clicked?
The report includes full campaign metrics: who received the message, who opened it, who clicked, who entered credentials and who reported it. Reporting rate matters as much as click rate. An employee who reports a phish quickly gives your IT team a chance to stop the attack for everyone else.
We'll talk during scoping about how you want individual results handled. Some organizations want names for follow-up training. Others want aggregate numbers only. Either works.
Do you only do email?
Email phishing makes up most engagements, and it's where we recommend starting. If your risks call for it, we can discuss other scenarios during scoping, like phone-based pretexting aimed at your help desk.
Who should know the test is happening?
Keep the circle small: usually the person who approves the engagement and whoever manages email security. Tell too many people and word spreads, and the results stop reflecting reality. We'll make sure whoever handles IT support knows how to verify the activity if an employee reports it, so nobody wastes an afternoon chasing our test as a real incident.
What should we expect from the results?
One or many employees may click, and the useful questions come after the click: Did the email filter catch the rest? Did multi-factor authentication stop the attacker? Did anyone report it, and how fast did IT respond? The report answers those questions and gives you specific fixes for the technical controls, along with numbers you can track over time.
How long does it take, and what does it cost?
Campaigns usually run over one to three weeks so that messages land the way a real attack would, not all at once. The number of employees, the number of campaigns and how much custom work each lure needs drive the price.
Related services and reading
- M365/Azure Security Assessment: tighten the email and identity settings phishing relies on.
- Cloud Penetration Testing: what an attacker reaches with one phished Microsoft 365 account.
- How to prepare for a penetration test: a free checklist that walks your team through scope, timing and rules of engagement.
Curious how your team would hold up?
Tell us how many people you have and what you already do for security awareness. We'll help you design a campaign that tells you something useful.
Let's Plan a Campaign