Your strongest firewall can't stop an employee from being tricked.
I test how your people, processes, and building respond to the same tactics real attackers use: fake emails, phone calls, false identities, and open doors. You get a clear picture of where your team is exposed and what to change. One person plans the test, carries it out, and writes the report.
Request a scoping callWhat I test for
Each area is explained in plain language first, then in technical detail for your IT team.
Phishing
Will your employees click a fake email, open a bad attachment, or type their password into a fake login page?
Credential-harvesting and attachment-based campaigns, spear phishing against selected roles, click and submit rates, report rates, and whether email filtering, MFA, and your incident response process catch it.
Vishing
Will someone on your team hand over information or access to a stranger who simply calls and sounds convincing?
Pretext calls to help desks, front-line staff, and finance, targeting password resets, MFA changes, caller verification gaps, and disclosure of internal details.
Impersonation
Can someone pretend to be an executive, a vendor, or an IT person and get your staff to do what they ask?
Authority and vendor pretexting over email, phone, and chat, lookalike domains, and the checks your team applies to payment, access, and data requests.
Physical security
Can a stranger walk into your building, follow someone through a door, or plug something into your network?
Tailgating, badge and visitor process weaknesses, unattended workstations, exposed network ports, and sensitive documents left in reach.
OSINT and over-exposure
How much can an attacker learn about your company and staff from public sources before they ever contact you?
Open-source intelligence on employee names and roles, email formats, social media, job postings, exposed documents and metadata, and other details that make a convincing attack easy to build.
How I keep it safe and authorized
Social engineering involves real people, so the ground rules matter.
Written authorization first
Nothing starts until we agree in writing on what's in bounds, who at your company knows about the test, and what's off limits.
Focused on process, not blame
The goal is to find weak points in your systems and training, not to embarrass individual employees. Results are reported by pattern and role.
What working together looks like
- ScopeWe agree on which attack types to run, the testing window, and the rules of engagement in writing.
- ResearchI gather public information about your organization, the same way an attacker would.
- TestI carry out the agreed phishing, phone, impersonation, and on-site tests.
- ReportYou get an executive summary for leadership and detailed findings for your IT team, with recommended fixes and training priorities.
Wondering which tests fit your team?
Tell me about your business and I'll recommend where to start.
Get in touch