Social engineering: the attack vector technology can't block

90% of cyberattacks start with a human being. We simulate real social engineering attacks — phishing, vishing, pretexting — to measure and improve your team's resilience before a real attacker does.

The weakest link isn't in your code

You can have the best firewall on the market, up-to-date patches and a strict password policy. But if one employee clicks a well-crafted email, hands over credentials on a convincing call, or plugs in a USB drive found in the parking lot, everything else collapses. Social engineering exploits human trust, urgency and authority — and those factors don't go away with technology.

Available simulation types

  • Mass phishing: email campaign simulating real threats (invoices, IT alerts, HR)
  • Spear phishing: personalized attacks on high-value profiles (CEO, CFO, IT admin)
  • Vishing: phone calls impersonating IT support or authorities
  • Smishing: malicious SMS mimicking banking or HR alerts
  • In-person pretexting: controlled attempt at unauthorized physical access
  • USB drop: USB devices placed in controlled environments to measure response
  • Combined campaign: several simultaneous vectors (phishing + vishing + in-person) in a single exercise

How we do it

  1. Scenario definition: We agree the simulation type, difficulty level and concrete objectives with leadership.
  2. OSINT reconnaissance: We gather public information about the company and target profiles to build credible, personalized pretexts.
  3. Controlled execution: We launch the campaign within the agreed scope. Everything is documented and no real data is exfiltrated or stored.
  4. Results analysis: We measure open rates, clicks, submitted credentials, completed calls and any agreed indicator.
  5. Report and training: We deliver the report with results by department and offer an awareness session for the affected teams.

Service deliverables

  • Results report by department and profile
  • Attack success rate with sector benchmark comparison
  • Identification of high-risk profiles
  • Technical and process recommendations
  • Post-simulation awareness session included
  • Phishing incident response policy

Who should run this test?

  • Companies that suspect their team doesn't spot well-crafted phishing emails
  • Organizations with high staff turnover or large recent onboarding waves
  • High-risk sectors: finance, healthcare, legal, HR and customer support
  • Companies that want to measure the real effectiveness of their training programs
  • Any company that must meet the awareness requirements of NIS2 or ISO 27001

Frequently asked questions

Will employees know it's a simulation?

Not during execution, so the results are representative. They will afterward, during the awareness session. Leadership is always informed before it starts.

What happens if an employee falls for the phishing attempt?

Nothing negative. The goal is educational, not punitive. The employee will see a notice page explaining they just took part in an exercise and what signs they should have noticed.

How often should this be done?

At least twice a year to maintain alertness. Organizations with higher exposure or that handle sensitive data should do it quarterly.

Can we exclude certain departments?

Yes. We can segment the scope by department, access level or any criteria you need.