Phishing & Social Engineering
The part of security no firewall covers: your people. A controlled phishing campaign shows who clicks, who reports it, and what an attacker could do with a single stolen password. The point is not to embarrass anyone. It is to find out where the training should go, and to prove it worked.
Controlled and authorized. No blame, no gotchas. Retest included.
Get a fair, fixed quote
A phishing and social engineering test is a controlled, authorized campaign that safely mimics how attackers try to trick your staff, so you can find out where the training should go. It is a rehearsal, not a trap. Your people having email and answering the phone is not a finding; that is their job. What the test measures is how the organization spots a fake, reports it, and holds up when someone slips, and then it hands you a plan to make those numbers better. If you want the ground-level version first, our guide to what a penetration test is sets the scene.
What we test
A rehearsal, scoped to be fair to your people
We agree the realism level with you and design a campaign that reflects what your team actually faces. Here is what can be in scope, from a simple email test to a broader look at how an attacker would approach your people.
Email phishing
A controlled campaign of realistic phishing emails, the kind your staff actually receive, safely mimicking a login prompt or a too-good link. No real harm is done, and nothing is left running afterward.
Who clicks, and who reports
We measure both, because the number that matters most is not who clicked. It is who spotted it and reported it. A team that reports quickly limits the damage of the one person who did not, and that is what we are looking for.
What one credential reaches
When someone does hand over a password, we show what an attacker could actually do with it, and whether multi-factor authentication would have stopped them. That turns a click into a concrete, fixable lesson.
Pretext and targeting
From a broad campaign to a focused, believable pretext aimed at the roles an attacker would really target, like finance or reception. We scope the realism level with you, never blindsiding individuals for sport.
Phone and voice, if in scope
Attackers do not only use email. A voice-based test, someone calling to talk a staff member into resetting a password or granting access, can be added when it fits what you are trying to learn.
Physical and USB, if in scope
When it is relevant, we can test the low-tech routes too: a dropped USB drive, or whether a friendly stranger can walk past reception. These are optional and always agreed in scope, never a gotcha.
Here is the mindset that keeps this useful: nobody is graded, and the click is not the failure. Anyone can be caught by a convincing message on a hectic day. The thing worth measuring is whether your team recognizes and reports it, because a quick report is what stops one bad click from becoming a bad week. The test tells you where to aim the training, and nothing more.
How it works
From a fair campaign to a team that reports
No jargon, no drama, no surprises. Five steps, and you always know what is happening and why. The retest matters more here than almost anywhere else, because the whole value is proving the training actually moved the numbers, not just running the campaign once.
Curious what the write-up at the end looks like? We walk through it, section by section, in our guide to what a penetration test report looks like.
- 01
Scope
A short call to agree what a fair, realistic campaign looks like for your team, which channels are in play, and who authorizes it. We set the realism level together and put the rules of engagement in writing before anything starts.
- 02
Test
We run the campaign safely and record what happens: who clicked, who reported, and how quickly. Any credentials entered are captured only to prove the point, handled securely, and never used against you.
- 03
Report
A clear report in plain English, focused on patterns rather than pointing fingers. Where the risk actually sits, which teams or scenarios need attention, and how your reporting rate compares to what good looks like.
- 04
Fix list
A prioritized, do-this-first list, which for people usually means targeted training and a couple of technical changes, like enforcing multi-factor authentication where a stolen password would otherwise be enough.
- 05
Retest
A follow-up campaign after the training shows whether the numbers actually moved, which is the real proof it worked. A retest is included, not billed back as an upsell.
Turning a click into a fix
The click is the start of the lesson, not the end
When someone does enter a password, the useful question is what happens next. If that one credential opens email, remote access, and everything behind it, the finding is not really the person who typed it. It is that a single password was enough. More often than not, the fix is multi-factor authentication in the right places, which turns a stolen password into a dead end.
That is also where phishing meets the rest of your security. A credential that works is exactly the foothold an internal penetration test starts from, which is why the two pair so naturally.
Pricing
What a phishing test costs
Phishing and social engineering is part of our full-scope Large Enterprise tier, which starts at $10,000, and it can also be scoped on its own as a smaller, standalone campaign. Because scope varies so much, from a single email test to a multi-channel engagement with training and a retest, we price a standalone campaign by what you want to learn, and the quote is fixed once we agree it.
We publish our tier pricing, which most firms will not do, so you have a real reference point going in. The version worth paying for includes the retest, so you can prove the training changed the numbers.
Testing people because insurance asked?
Cyber-insurance questionnaires increasingly ask about phishing training and testing. If a renewal is what is prompting this, our readiness engagement lines the whole application up so the answers are honest and evidenced.
Cyber-insurance readinessFAQ
Phishing and social engineering: common questions
- What is a phishing and social engineering test?
- A phishing and social engineering test is a controlled, authorized campaign that safely mimics how attackers try to trick your staff, so you can find out where the training should go. It is a rehearsal, not a trap. We send realistic phishing emails, and sometimes add phone or physical tests when they fit, then measure who clicked, who reported it, and what a stolen password would have reached. The point is a clearer picture and a training plan, never embarrassing anyone.
- Is the goal to catch or embarrass employees?
- No, and we design the whole engagement to make sure it is not. The goal of a phishing test is to find out where the training should go, not to single anyone out. Reports focus on patterns, which teams and which scenarios need attention, rather than naming and shaming the person who clicked. Your staff having email and answering the phone is not a finding. How the organization spots and reports a fake is.
- What do you actually measure?
- Both the click rate and, more importantly, the report rate. Anyone can be caught by a good phish on a busy day, so the click rate alone is a shallow number. What really tells you where you stand is how many people recognized it and reported it, and how fast. A high report rate is the sign of a team that would blunt a real attack, and it is the number we most want to move.
- Do you warn our staff before the test?
- Leadership authorizes and scopes the campaign, but the individual staff being tested are usually not told in advance, because forewarned results would not tell you anything real. That is different from a gotcha: it is controlled, it is consented to at the right level, and it is agreed in writing. We set the realism and the boundaries with you so it stays fair to your people.
- Is it safe? Do you really steal passwords?
- It is safe and controlled. When someone enters a password into our test page, we capture only enough to prove the credential would have worked, handle it securely, and never use it to actually access anything. Nothing harmful is installed, and nothing is left running when the campaign ends. The whole point is to learn the lesson without any of the real-world damage.
- How much does a phishing test cost, and how long does it take?
- Phishing and social engineering is part of our full-scope Large Enterprise tier, which starts at $10,000, and it can also be scoped on its own as a smaller, standalone campaign. Because the scope varies so much, from a single email campaign to a multi-channel test, we price a standalone engagement by what you want to learn and give you a fixed quote. A basic campaign runs quickly; the more valuable version includes training and a retest to prove the numbers moved.
Find out where the training should go
Tell us about your team and what is prompting the test, an insurance renewal, a client requirement, or just wanting to know where you stand. We will come back with a fair, realistic campaign and a fixed quote. No pressure, no sales theater.