Service 08, included in your subscription

Social engineering testing

We measure how people and processes respond to realistic manipulation attempts, with anonymised reporting and practical recommendations.

What we test

Phishing

Credential-harvesting simulations, click measurement and reporting behaviour.

Vishing

Phone pretexts against approved teams and process checkpoints.

Smishing

SMS-based scenarios where approved and legally appropriate.

Help desk process

Reset flows, caller verification and escalation discipline.

Executive pretexts

Business email compromise style scenarios without unsafe payloads.

Campaign metrics

Department-level outcomes, anonymised risk patterns and training priorities.

What you get

A report your auditor and your engineers both understand

Executive summary, per-finding reproduction steps, severity-rated remediation guidance and retesting included once you have fixed the issue.

Book a call
PT-2026-0007 · REPORTRetest passed
Credential submission through finance pretextFIXED
Help desk reset approved without verificationFIXED
Low report rate among target groupFIXED

FAQ

Common questions

Can this be run without shaming staff?

Yes. We recommend anonymised, process-focused reporting so the result improves resilience rather than creating blame.

Do you support vishing?

Yes. Phone-based pretexting can be included where approved and scoped with safety boundaries.

Can you test our help desk?

Yes. Help desk impersonation and reset-process testing are common social engineering scenarios.