Most breaches start with a person, not an exploit. We run controlled campaigns against your own staff to measure how they respond under realistic pressure, then use the result to make the next attempt fail. The goal is a stronger team, never a list of names to punish.
What we test
- Email phishing. Targeted campaigns using pretexts relevant to your business, measuring click-through, credential entry, and reporting rates.
- Pretexting and vishing. Voice and messaging scenarios against agreed targets, scoped and authorized in advance.
- Physical and on-site. Tailgating, drop devices, and reception pretexts, where in scope and legally cleared.
- Reporting behaviour. How quickly staff flag a suspicious message, and whether your process actually catches it.
How it runs
We agree the pretexts, targets, and rules of engagement with a single point of contact before anything goes out. Nothing runs without written authorization. We report on aggregate behaviour first; individual results are handled carefully and only shared as your policy allows.
What you walk away with
- Measured baseline rates (clicked, submitted, reported) so you can track them over time
- A debrief that turns the campaign into targeted awareness training
- Concrete recommendations for the technical controls (email authentication, filtering, reporting tooling) that would have blocked the attempts
We treat this as a way to build resilience, not to embarrass anyone. Results are framed for improvement, and we recommend pairing the first campaign with follow-up training so people leave better equipped than they arrived.