← All servicesPackage 01 / 0310 service lines

Social Engineering & Training

The people attackers actually call

Our main engagement. We run the attacks your staff will really face, then rebuild the judgement those attacks depend on. On site or remote, as a continuous program or a single assessment.

fig. 01Social Engineering & Training
  1. 01ReconnaissanceOrg chart, vendors and staff posts, from public sources only
  2. 02Pretext buildThe lure written per role, with cloned voice and video
  3. 03Multi-channel runEmail, phone, SMS, QR, chat and live video call
  4. 04Coaching on failureNinety seconds, delivered the moment somebody falls for it
  5. 05Risk scoreBehaviour by department, role and trend over time
Where the agents work

Agents build pretexts from live reconnaissance and generate the voice, video and message lures, so a simulation matches what an AI-equipped attacker can already produce.

What you are left holding

A workforce that verifies through a second channel, and a number your board can watch move.

01Flagship

Human Firewall Program

The flagship. Continuous social engineering defense.

A rolling program that measures how manipulable your organisation is, attacks it the way a real adversary would, and rebuilds the judgement of every person it touches.

Baseline assessmentContinuous simulationBehavioural coachingRisk scoring

Most awareness training teaches people to spot a badly written email. That skill is now worthless: generative models write better English than your staff do. We train something else entirely - the reflex to slow down when a request creates urgency, secrecy or fear, and to verify through a second channel before acting. The program starts with an OSINT baseline and an unannounced multi-channel simulation so we know where you actually stand. From there it runs continuously: targeted simulations by role and privilege, ninety-second coaching delivered at the exact moment somebody falls for one, live workshops for the highest-risk teams, and a human risk score that tells your board whether behaviour is genuinely changing.

  • OSINT baseline of your organisation's public attack surface
  • Unannounced multi-channel baseline simulation and exposure report
  • Role- and privilege-weighted simulation calendar
  • Just-in-time coaching triggered by failure, not annual slide decks
  • Manipulation-resistance workshops for finance, HR, IT support and leadership
  • Human risk score with department, role and trend breakdowns
  • Quarterly board pack mapped to your compliance framework
02

OSINT Exposure Assessment

See your company the way an attacker sees it.

A structured reconnaissance report showing exactly what can be learned about your organisation and staff from public sources - and how that becomes an attack.

Attacker's-eye viewPretext modellingFootprint mappingReduction plan

Before anybody sends a phishing email they build a map: who reports to whom, who approves payments, who is new and eager to help, which vendor invoices you monthly, which employee posts their badge photo. We build that same map and hand it to you. The report is deliberately uncomfortable to read, because the point is to show the finished pretext rather than a list of abstract risks. It also comes with the practical part: what to remove, what to change and what simply cannot be hidden and must be defended procedurally instead.

  • Employee, org chart and reporting line reconstruction
  • Exposed credentials, documents and metadata discovery
  • Vendor, supplier and partner relationship mapping
  • Infrastructure, subdomain and shadow IT footprint
  • Social media and personal exposure review for key roles
  • Three fully written pretexts your organisation would likely fall for
  • Prioritised reduction plan for what can realistically be removed
Offensive Security
03

Vishing Service

A live human on the phone, working the target the way a fraud crew does.

Trained operators run real-time, adaptive voice-phishing calls against your help desk, finance team and reception - no robocalls, no fixed script, nothing scripted enough to spot.

Live operatorsReal-time adaptationHelp desk & financeFull call logging

Automated vishing tools give themselves away: a flat voice, a script that cannot handle a follow-up question, a caller who goes silent when pushed back on. We do not use them. Every call is run by a trained operator who has done the reconnaissance, built a pretext specific to the role being called, and can improvise when the target asks something unexpected - exactly what the crews targeting your organisation actually do. Calls are scoped and authorised in writing before a single number is dialled, and every outcome is logged so the pattern across your organisation, not just one embarrassing call, is what reaches the report.

  • Pretext design from real reconnaissance on the target department
  • Live, human-led calls to help desk, finance, reception and other high-value roles
  • Real-time adaptation to pushback, verification questions and gatekeeping
  • Call-by-call outcome logging: compromised, resisted, escalated
  • Immediate coaching for anyone who released information or access
  • A written record of exactly what was said and what was given up
04

Phishing Service

Measures what a click rate cannot.

Targeted email campaigns built from real reconnaissance on your organisation, scored on reporting speed and repeat failure rather than a single click-through number.

Role-based pretextsCredential-harvest simsReporting-rate trackingRepeat-failure ID

A click rate tells you almost nothing useful: it does not say who reported the email, who forwarded it to a colleague, or who fell for the same pretext twice. We run campaigns built the way a real attacker builds one - from your actual vendors, your actual org chart, your actual recent press - and measure what predicts a real compromise: how fast it was reported, whether credentials were entered, whether the same person is repeatedly the first to act. The result is a picture of where your reporting culture is strong and where a well-written email still walks straight through.

  • Role-based pretexts drawn from live OSINT on your organisation
  • Credential-harvest and malicious-attachment simulation waves
  • Business-relevant lures: invoices, HR notices, IT and vendor requests
  • Per-recipient and per-department reporting-rate tracking
  • Repeat-failure identification for targeted follow-up coaching
  • A report that separates who reported it, who ignored it and who acted on it
05

SMiShing Service

The channel with no spam filter and the most trust.

SMS-based phishing simulations test the channel your staff trust the most and defend the least - delivery texts, MFA prompts, and messages that look like they came from IT.

Sender-ID scopedMFA-prompt luresCallback-style textsMobile coaching

Almost nothing filters text messages, and almost everybody opens one within minutes. That combination makes SMS a favourite for MFA-fatigue and help-desk-reset attacks, and it is usually the one channel security awareness training never touches. We run SMS campaigns scoped to your authorised number ranges, testing delivery-notification lures, spoofed IT and HR messages, and the callback-style texts that ask somebody to ring a number rather than click a link - a variant built to slip straight past link-scanning tools.

  • SMS pretext design covering delivery, IT, HR and MFA-prompt lures
  • Sender-ID and shortlink scenarios scoped and authorised in advance
  • Link-based and callback-style ('ring this number') scenarios
  • Mobile-specific coaching delivered on the device the failure happened on
  • Outcome logging by department and role
  • A written record of every message sent and every response received
06

Callback Phishing

The email opens the door, the phone call walks through it.

Coordinated campaigns that chain email, voice and SMS the way real extortion crews run them - an urgent message followed by a very calm phone call that finishes the job.

Email-to-call handoffCross-channel scoringEscalation-path testingFull chain timeline

The attacks causing the largest losses right now rarely stay inside one channel. An email arrives about a subscription charge or a failed delivery, and it asks the target to call a number rather than click a link - the number connects to a live operator who talks the victim into installing something or handing over access. We run the same chain, with the same handoff between channels, so you can see whether your controls catch the pattern rather than just the individual message. It is the scenario most awareness programs have never actually tested, because it needs both an email infrastructure and a live calling operation to run properly.

  • Multi-channel scenario design chaining email, SMS and live calls
  • Telephone-oriented pretext handoff, matched to real extortion and fraud patterns
  • Cross-channel outcome scoring, not scored channel by channel
  • Escalation-path testing: does anyone flag the pattern across channels
  • Full timeline of the chain, from first message to final outcome
  • Coaching aimed at the handoff moment specifically
07

Adversarial Simulation

Every channel, at once, the way a motivated attacker actually runs it.

A holistic engagement spanning OSINT, phishing, vishing, SMiShing and physical access - testing your network, your facilities and your people as one connected target.

OSINT-ledMulti-vectorPhysical accessFull attack narrative

A single-channel test answers a narrow question. This answers the real one: if a competent, motivated attacker spent two weeks studying your company and was free to use any channel that worked, how far would they get? We build the campaign from live reconnaissance and run it across every vector we operate individually - email, phone, SMS, cloned voice, deepfake video, and physical entry where it is in scope - chained together the way an actual intrusion would be. The output is not a set of channel scores. It is a single narrative of exactly how somebody got from a LinkedIn profile to a badge on your floor or a wire transfer, and the specific point in that chain where a control would have stopped it.

  • Reconnaissance and pretext development from live OSINT
  • Chained multi-vector campaign: email, voice, SMS and video
  • Physical pretexting and tailgating where authorised and in scope
  • Full attack narrative with evidence, timeline and control gaps
  • A single point-of-failure map across every channel used
  • Executive debrief walking through exactly how the chain worked
08

Security Assessment

One test, every angle, before you commit to a program.

A combined diagnostic - reconnaissance plus real vishing, phishing and SMiShing sampling - giving you one sweeping view of where you are exposed before deciding what to fix first.

OSINT baselineMulti-vector samplingCross-vector comparisonPrioritised next step

Most organisations do not know which vector to worry about first. This answers that in one engagement: we run the same OSINT baseline behind every attack, then sample real vishing, phishing and SMiShing scenarios against a representative slice of your organisation - enough to show where the pattern breaks, without the commitment of a full program. It is the fastest way to see the shape of your exposure across every channel at once, and it is usually where a first engagement with us starts.

  • OSINT baseline across your organisation's public attack surface
  • Sampled vishing, phishing and SMiShing runs across representative teams
  • Cross-vector comparison: where the pattern holds and where it breaks
  • Prioritised list of which vector to address first, and why
  • Executive summary written for a board, not just a security team
  • A clear scope and estimate for any program that follows
09

AI & Deepfake Social Engineering

Test what a cloned voice and a synthetic face can actually get past you.

Authorised voice-cloning and live deepfake video call scenarios, showing whether your verification habits survive contact with the exact thing they are meant to survive.

Voice cloningDeepfake video callsVerification stress testFull audit trail

Everyone has heard that voice cloning and deepfake video exist. Almost nobody has been on a call with one, which is the actual gap: knowledge does not change behaviour under pressure, rehearsal does. We build a synthetic voice or a live face-replacement scenario from consented source material, run it against the specific people who authorise payments or reset access, and see whether the verification protocol on paper survives contact with a voice that sounds exactly right. Every scenario runs under written authorisation, an agreed target list, consent controls on the source material, and a complete audit trail - this is the one area where the line between test and real deception has to be drawn precisely.

  • Consented collection and cloning of source voice material
  • Live cloned-voice call scenarios against finance and executive-adjacent roles
  • Live deepfake video-call impersonation on a real meeting platform
  • Stress test of your existing out-of-band verification protocol
  • Written authorisation, consent controls and full audit trail as standard
  • Executive-specific scenario design where leadership is the target
10

Training, Seminars & Workshops

Sessions people talk about afterwards.

Live on-site and remote sessions, executive briefings, tabletop exercises and developer training - built around demonstrations rather than slides.

On-site & remoteExecutive briefingsTabletop exercisesDeveloper training

We open sessions by cloning a volunteer's voice on stage, because nothing on a slide changes behaviour the way that does. From there the content is practical: the six psychological levers every attacker uses, how each one feels from the inside, and the specific verification habits that defeat them. Formats run from a ninety-minute all-hands to a multi-day program for security champions, and every session is built around your industry, your systems and the pretexts your staff will genuinely encounter.

  • All-hands awareness sessions with live attack demonstrations
  • Executive and board briefings on AI-enabled fraud
  • Deep-dive workshops for finance, HR and IT service desk
  • Crisis tabletop exercises for leadership teams
  • Secure development and secure design training for engineers
  • Security champions program design and enablement
  • Recorded modules and materials for onboarding reuse

Do not guess how manipulable your people are.

Start with a free thirty-minute call - we talk through where you stand and what a program would actually look like, before you commit to anything.

Book a free call