Service

Social Engineering and Phishing

Test phishing detection and response.

Controlled phishing against an approved target list. Pretexts, infrastructure and safety rails built per engagement, and a report your SOC and awareness programme can both act on.

What it is

A campaign measures what happens: who clicks, who submits credentials, who reports it, and how fast the SOC moves.

Two targeting modes: a list we propose from public employee data and you approve, or a list you provide. Both pass the same written review before launch.

Method

  • One or two pretexts, signed off by your White Cell before launch
  • Sender domain, mailer reputation and landing pages built per engagement
  • From a list you approve or a list you provide — never off-list
  • Execution inside an agreed window, monitored daily
  • Optional credential-harvest page — captures hashed at the boundary, never stored in clear
  • Optional MFA-bypass scenario via transparent proxy, in scope only
  • Detection and response timing: first report, SOC action, containment
  • Rails: pause word, ramp-down, post-test inbox cleanup support

What you get

  • Campaign report per pretext: hypothesis, design, results, evidence
  • Detection and response timeline: who reported it, and when SOC acted
  • Awareness gap analysis by unit or persona
  • Recommendations across training, mail-security tuning and process
  • Anonymised board summary with metrics beyond click rate

Ready to scope this engagement?

One email is enough to start. Tell us roughly what you want tested and we'll come back with a scoping call slot inside one business day.