People & premises

Social engineering

Authorized phishing, vishing and pretext campaigns that measure what your people actually do under realistic pressure — and, more usefully, how quickly someone reports it and what happens next.

8
areas covered
5
stages, scoping to retest
In-house
testers, never subcontracted
portal.cyberlysecure.com/acme-health/coverage
Acme Health — Test coverage4 practices · 15 services · one team
In-house
Web app
API
SaaS
Mobile
Client-side
External
Internal
Segment test
Wireless
Cloud config
Hardware & IoT
AI & LLM
Social eng.
Physical
Red team
ApplicationsNetworkCloud & devicesPeople & premises
6 in scope · one team · one report
In-house testers 0 subcontracted
Every surface one team
What this is

What the test covers.

Awareness training tells you what your people know. A controlled campaign tells you what they do on a busy afternoon, and whether your process catches what an individual misses.

Every pretext is approved by you in writing before it is used. We measure reporting as carefully as clicking, because reporting speed is what actually limits the damage — and nobody is named to embarrass them.

PTES social engineering guidance NIST SP 800-115 MITRE ATT&CK initial access techniques

What we test

  • Email phishing: credential capture and, where authorized, attachment or link payloads
  • Voice pretext calls to helpdesk, reception and named departments
  • SMS and messaging pretexts
  • Multi-factor fatigue and relay scenarios, only where explicitly authorized
  • Physical media drops on site, where in scope
  • Reporting rate and time-to-report, not just click rate
  • What your helpdesk will do for a convincing caller — reset, enrol or divert
  • How your controls handled the message before a person ever saw it
How it runs

From scoping call to retest, here’s what happens.

Typically one to three weeks, depending on channels and number of waves.

1

Scope and authorize

We agree targets, volumes, pretext themes and every message before anything is sent, with written authorization in place.

2

Build the pretext

Campaigns are written around your environment and calendar so they are realistic rather than generic.

3

Run it safely

Credentials are never retained, payloads are benign, and anything that looks like real distress ends the interaction.

4

Measure the response

We record who clicked, who submitted, who reported, how fast, and what your team did with the report.

5

Report and debrief

Results are reported at team level with practical fixes — and, if you want it, a session for the people involved.

What it surfaces

The kind of thing this test tends to find.

Real examples of what this engagement uncovers — anonymized, and never every time. What matters is that you find out before somebody else does.

Reporting that is far slower than clicking, leaving a long unnoticed window

Helpdesk processes that will reset a factor for a confident stranger

Filtering that lets a plainly hostile message reach every inbox

A reporting button nobody uses because nothing visible happens afterwards

Departments under time pressure being measurably easier to deceive

Getting started

What you get, and what we need from you.

What you get

  • Technical report — Every finding, the evidence behind it and clear guidance your engineers can act on.
  • Executive summary — Your risk explained in plain language for leadership and the board.
  • Attestation letter — Signed confirmation of testing to hand your auditors.
  • Readout call — A walkthrough with the people who tested your systems.
  • Retest — Confirmation your fixes worked, documented for whoever needs to see it.

What we need from you

  • Written authorization from someone who can give it for your people
  • A target list and any individuals to exclude
  • Allow-listing decisions: do you want controls tested, or people
  • A named contact who will know the campaign is live

Missing something on this list? Bring it to the call — we scope around what you have.

Free attack-surface snapshot

Give us a domain. See what an attacker sees.

Not sure where to start? One of our testers reviews your internet-facing footprint and sends you a short summary of what an attacker would see — free. Nothing you don’t own is ever touched, and there’s no sales sequence.

  • Internet-facing hosts
  • Exposed services
  • Leaked credentials
  • TLS certificate hygiene

Request your snapshot

Free. No obligation.

We only ever test assets you own, with your written authorization.