Social Engineering Assessment
Phishing campaigns and pretext calls run carefully, with the rules of engagement we’d want if we were on the receiving end. No gotcha emails sent to the new hire on day one.
What we’ll look at
- Pretext and scenario planning
- Email phishing simulation when authorized
- Credential harvesting controls review
- User reporting pathway evaluation
- Safe debrief materials
- Awareness improvement recommendations
What you get
- Approved scenario plan
- Campaign results summary
- Control and response observations
- Recommendations for reporting and awareness
- Executive summary
Why teams book it
- Improve human-layer resilience
- Validate reporting workflows
- Reduce credential theft risk
Common questions
Anything else, just drop us a line.
Yes — a scope and rules of engagement. It covers what’s in, what’s off limits, the test window, and the phone numbers to call if anything looks off mid-test.
In most cases. We write findings so your QSA can map them back to controls, and we’ll join the call if it helps. We can’t sign the RoC ourselves — that’s their job.
Yes. Either include it in the original scope or come back to us once the fixes are in. We re-run the same tests and write up what closed.