Your people are the attack surface.
Phishing, vishing, and pretexting, tested properly, before somebody else tests them for you.
A social engineering assessment is a live simulation, not a slideshow. We use the same techniques a real attacker would to find out how your team responds, then show them exactly what they missed.
The gap
Attackers stopped breaking in. They ask to be let in.
Firewalls, mail filtering, and endpoint protection have all got good enough that going through them is hard work. Going around them is not. A convincing email, a confident phone call, or somebody carrying a box through a door held open for them will beat a well configured network most days of the week.
Security awareness training tells your team that this happens. It cannot tell you whether they would catch it on a Tuesday afternoon, three weeks later, when the request looks routine and they are busy. The only way to know that is to have somebody actually try, in a controlled way, and count what happens.
What we test
Every way in that runs through a person.
Pick one technique or run the lot. Most businesses start with email, because that is where the volume is, then add phone and a physical visit once they have seen the first set of results.
Phishing
Email lures written around your real suppliers, your real branding, and the systems your team logs into every day. Not a generic template with obvious spelling mistakes.
Tells you: Who clicks, who enters credentials, and who reports it.
Vishing
Phone calls that impersonate IT support, a known supplier, or a senior staff member, asking for the kind of small favour that quietly hands over access.
Tells you: Whether identity gets verified before access is granted.
Smishing
SMS lures using the pretexts currently landing on Australian phones: missed deliveries, payroll changes, and urgent verification codes.
Tells you: How your team treats requests that arrive on a personal device.
Pretexting & MFA fatigue
Invoice redirection, supplier impersonation, and repeated authentication prompts sent until somebody taps approve just to make them stop.
Tells you: Whether your payment and approval processes hold under pressure.
Physical intrusion
Walking in behind someone, testing your visitor process, checking for unlocked workstations, live network ports, and documents left where they should not be.
Tells you: What somebody could achieve with ten minutes inside your office.
OSINT footprint
Everything an attacker can assemble about your business before making contact: staff names and roles, email formats, suppliers, tooling, and exposed credentials from past breaches.
Tells you: How much of the groundwork is already done for them.
How it runs
Five stages, from signed off to sorted.
- 01
Scope and authorise
We agree what is in scope, what is strictly off limits, when testing runs, and who can call it off. Nothing begins until that is signed by someone with the authority to sign it.
- 02
Reconnaissance
We build the same picture of your business an attacker would, working only from public sources. That research is what makes the rest of the exercise convincing.
- 03
Build the lures
Emails, calls, messages, and pretexts are written specifically for your business. Generic tests produce generic results, and staff learn nothing from a lure nobody would have fallen for.
- 04
Run the campaign
Testing runs over an agreed window while we track what happens: who engages, who verifies, who reports it, and how long your business takes to notice.
- 05
Debrief and uplift
You get the findings and the fixes. Your team gets a session showing the actual lures used and the tells they missed, which is the part that changes behaviour.
Run safely
Testing your team should never turn on your team.
This work only stays useful if everyone trusts how it is run. Four rules apply to every engagement, and they are written into the agreement before anything starts.
Nothing starts without written authorisation from someone empowered to give it for your business.
Scope, timing, exclusions, and a contact who can call it off are all agreed before the first message goes out.
Reporting is aggregate and no-blame. No staff member is named to management as having failed.
Captured credentials are never used beyond proving access, and everything collected is destroyed on sign-off.
What you get
A result you can act on, not a scare campaign.
The report
- Every finding, prioritised by how much damage it could actually cause
- Click, submit, and report rates across the campaign
- A breakdown by team, so you know where to focus
- The exact lures used, so nothing about the exercise stays hidden
- Specific remediation steps, ordered by what to fix first
- A plain English summary you can hand to a board or an insurer
The debrief
A session with your team walking through the actual lures we sent, the tells that were there, and what to do next time. People remember the email that fooled them far longer than they remember a training module.
The retest
A second campaign later in the year, using fresh pretexts, to show whether anything actually changed. This is the part that turns a one-off exercise into a measurable trend you can put in front of a board or an insurer.
Who it suits
Sized for a real business, not an enterprise budget.
The large testing firms do excellent work, and they are built for organisations with a security team to hand the report to. If you have twenty staff, a bookkeeper who pays invoices, and nobody whose actual job is security, that engagement is priced and shaped for somebody else.
This is the same discipline, scoped for the business you actually run, delivered by the person who supports your systems and will still be there to fix what the test finds. That last part matters more than it sounds. A report from a stranger tends to sit in a drawer.
Common questions
The things people ask before they commit.
Is this legal? Do I need anyone's permission?
Yes it is legal, and yes you need permission, which is why we will not start without written authorisation from someone empowered to give it for your business. If any part of the scope touches a third party such as a landlord or a shared building, that has to be authorised too. We work all of this out with you during scoping.
Will this embarrass or punish my staff?
No. Reporting to management is aggregate, and we do not name individuals as having failed. The goal is a team that recognises the next attempt, and people who feel set up to fail tend to hide mistakes rather than report them. The debrief is run as training, not as a naming exercise.
How long does it take?
A focused phishing exercise for a small team can run inside a week. A broader assessment covering email, phone, and a physical visit usually runs over two to four weeks, mostly because the campaign window needs to be long enough to be realistic.
How often should we run one?
Once a year as a baseline, and more often if you have high staff turnover, handle client funds, or have had a close call. A single test is a snapshot. Running them periodically is what actually moves the needle, because it keeps the topic alive between tests.
What does it cost?
It depends on headcount, how many techniques you want covered, and whether a physical visit is involved, so we scope it before quoting rather than publishing a number that would be wrong for most businesses. The scoping conversation is free and there is no obligation attached to it.
Do you test our systems as well as our people?
Social engineering is the focus of this page, but the two are connected. If the exercise shows that one clicked link leads straight to your file server, that is a technical finding and it goes in the report. We can also look at the controls that should have caught the attempt, such as mail filtering, endpoint protection, and how your accounts are secured.
Get started
Want to know how your team would react?
Tell us roughly how many staff you have and what worries you, and we will come back with a scope and a price. The conversation is free, and there is no obligation attached to it.