Social Engineering

Phishing and social engineering

Click rate is the wrong metric. Someone will always click, and publishing a league table of who did teaches your staff to hide it. The number that predicts how a real incident goes is how long it takes the first person to report the message, and whether anything happens when they do.

See pricing

What is included

  • Pretext development informed by what is publicly discoverable about you
  • An agreed target list, with anyone excluded on request
  • Infrastructure set up for the exercise and torn down afterwards
  • Measurement of delivery, interaction, credential submission, and reporting
  • Optional payload-free landing page for awareness rather than access

What you get

  • Time to first report, which is the headline number
  • Delivery and interaction rates in aggregate, never a named list
  • What your mail filtering caught and what it passed
  • What happened in the security queue when someone did report it
  • Awareness recommendations aimed at the process, not at individuals
  • Attestation letter for auditors and customers, on request
  • Remediation attestation after the retest, as a standalone document

Shape of the engagement

  • Scoped individuallyFixed in writing before testing starts. 1 to 3 weeks including the reporting windowTypical window. Built around your deadline if you have one. How pricing works

Reported, not clicked

We report aggregate numbers to you and we do not hand over a list of who clicked. That is a deliberate constraint and it is negotiable only in the direction of more privacy, not less. The reason is practical rather than principled: an exercise that produces a disciplinary list produces a workforce that conceals the next real phish, which is exactly the failure mode you are trying to prevent.

What we do measure precisely is the reporting path. How long until the first report, through what channel, and what happened next. An organisation where forty percent click but the first report lands in ninety seconds and triggers a response is in far better shape than one where five percent click and nobody tells anyone.

Authorization and boundaries

Written authorization from someone who can grant it for the people being tested, an explicit target list, an explicit exclusion list, and a defined window. No pretexts that impersonate a real named employee, a regulator, a medical provider, or anything touching a genuine personal emergency. No collection of credentials beyond the fact that a credential was submitted; we record that it happened, not what it was.

Where the research comes from

Pretext quality is the difference between an exercise that teaches something and one that everybody spots. We build pretexts from what is genuinely discoverable about your organisation, the same open sources an attacker would use, which is also a finding in itself when the discoverable surface turns out to be larger than you expected. Published research on phishing tradecraft and abuse of trusted infrastructure sits behind this work.

Questions

No, and that is deliberate. You get aggregate rates and a detailed picture of the reporting path. Naming individuals reliably produces a workforce that hides the next real phishing email, which costs you more than the exercise gains.

Realistic ones built from openly discoverable information about your organisation. Never impersonating a real named employee, a regulator, a health provider, or a personal emergency. The boundaries are written into the rules of engagement before anything sends.

We record that a credential was submitted. We do not store the credential itself. The landing page can also be configured with no credential field at all if awareness is the goal.

Voice pretexting can be scoped where it is legal in the relevant jurisdictions and authorized in writing. Physical intrusion is not part of this engagement.

Individually, on target list size, number of pretexts, and window length.

Scope it properly before you buy it.

Thirty minutes on the call, a fixed price in writing within 24 hours, and an honest answer if this is not the engagement you need.

See pricing