Services
Social Engineering Assessment
We test your most critical security layer — your people — with realistic, fully authorized attack simulations under a signed scope.
Scoped by quote, priced fixed
Tell us about your environment and we’ll propose the approach, the timeline, and a fixed price — typically within 48 hours.
Request a quoteYour people are your perimeter
No matter how strong your technical defenses are, a single employee clicking the wrong link or sharing credentials over the phone can compromise the whole organization. Social engineering remains the most effective attack vector behind the majority of successful breaches.
We simulate the same tactics, techniques, and procedures used by real threat actors, testing people, processes, and physical controls to find weaknesses before they are exploited for real.
Authorization and rules of engagement
Every campaign is consent-based and conducted only under explicit written client authorization. Before any activity begins, we agree a clear scope, rules of engagement, and safe-word procedures.
This authorization-first approach applies equally to pretexting, phishing, vishing, smishing, and physical testing, keeping the assessment realistic while staying within agreed boundaries.
Phishing, vishing, and smishing
Phishing campaigns range from OSINT-driven spear phishing and credential-harvesting portals to safe-payload delivery, business email compromise, and multi-stage attacks, with metrics such as click, submission, and report rates tracked by department.
Voice phishing tests resistance to helpdesk and executive impersonation and MFA fatigue, while SMS phishing covers fake IT alerts, delivery lures, MFA interception, and QR-code phishing.
Physical testing and awareness
Physical social engineering tests controls and employee responses through tailgating, impersonation, badge cloning, USB drop attacks, dumpster diving, and unauthorized photography.
We also evaluate your security culture by auditing awareness programs, testing policy compliance, assessing incident reporting speed, and scoring department-level risk.
What you get
Deliverables include a detailed campaign report with anonymized individual and department results, an executive risk summary with trend analysis, and customized awareness training recommendations.
The engagement is scoped as a custom project with a fixed price and includes a re-test within a defined window and compliance evidence for SOC 2, ISO 27001, PCI DSS, and HIPAA audits.
Frequently asked questions
Do you need our authorization first?
Always. Every campaign is consent-based and runs only under explicit written authorization, with scope, rules of engagement, and safe-word procedures agreed before we begin.
How is the engagement priced?
It is scoped as a custom engagement with a fixed price after we understand your environment and objectives.
Are individual results exposed?
No. Reporting presents anonymized individual and department-level results alongside an executive risk summary, so the focus stays on improving the culture.
Does it support compliance?
Yes. The engagement provides compliance evidence for SOC 2, ISO 27001, PCI DSS, and HIPAA, and includes a re-test to measure improvement.