Human layer

Social Engineering & Phishing

Phishing, vishing and pretexting run with authorization and measured without blame — the human layer tested the way real attackers open the door.

Overview

What it covers

Most breaches start with a person, not a vulnerability. An email that looks routine, a phone call that sounds legitimate, a visitor who seems to belong — these bypass technical controls entirely. We test the human layer with controlled, authorized campaigns that measure real click, credential-entry and disclosure rates, then report them without naming or blaming individuals, because the goal is a stronger process, not a scapegoat.

Scope

What we test

Every engagement is scoped to your environment, but these are the areas a Social Engineering & Phishing engagement covers.

Email phishing

Targeted campaigns measuring click, credential-entry and reporting rates against realistic lures.

Voice pretexting (vishing)

Phone-based social engineering against help-desk and staff, testing verification procedures.

Pretext development

Believable scenarios built from open-source information, the way a real attacker would prepare.

Physical (where scoped)

Tailgating and on-site pretexting to test badge, reception and escort controls.

Awareness outcomes

Findings framed as process and training improvements, with no individual singled out.

Methodology

How the engagement runs

The same defensible sequence every time.

Scoping and a fixed-price quote, reconnaissance and threat modeling, manual exploitation with same-day escalation of critical findings, a report your engineers and auditors can both use, and a free retest once fixes ship.

1
Scoping & rules of engagement
Fixed-price quote in ~1 hour
2
Reconnaissance & threat modeling
Prioritize the paths that matter
3
Manual exploitation
Same-day critical escalation
4
Reporting
CVSS v3.1, reproduction, control mapping
5
Remediation retest
Included in the engagement
Questions

Social Engineering & Phishing, answered

Will you name employees who fail?

No. We report rates and patterns, never individuals. Naming people damages the security culture you are trying to build and discourages the reporting you want to encourage.

Is this authorized and legal?

Entirely. Every campaign runs under written authorization with agreed scope, targets and limits, and any physical work carries authorization letters for the people involved to present if challenged.

Ready to scope a Social Engineering & Phishing?

A 30-minute call gets you a fixed price and a start date, usually within the hour.