Skip to content
Security incident? Call: +48 732 059 711
Social engineering

Test the human firewall

Spear phishing, vishing, physical intrusion. A full red-team assessment of the human layer — with a report the board will actually read.

Who is it for?

  • Financial institutions
  • Executives and C-level
  • High-value-target organisations
  • Companies preparing for NIS2 audit
  • Organisations after a failed phishing simulation
What you get

Outcomes

Realistic attack simulation

Not a generic phishing test — a targeted spear-phishing campaign against specific high-value roles, with custom pretexts.

Vishing (voice phishing)

Phone-based attacks on IT support, finance and HR. We test real-world BEC and helpdesk-bypass scenarios.

Physical intrusion (optional)

Tailgating, badge cloning, reception bypass — we try to reach the server room without an invitation.

Board-ready storyline

The report reads like a story — attack timeline, decisions, failures, lessons. Perfect for board communication.

Immediate re-training

Anyone who clicked or disclosed information gets a same-day educational follow-up.

NIS2 / DORA evidence

Documented evidence of social engineering testing — required under NIS2 and DORA.

How we work

Red-team methodology

  1. 01

    Rules of engagement

    Targets, out-of-scope people, safety rules, white team (who knows), escalation contact.

  2. 02

    OSINT & pretext design

    We build realistic pretexts from public information — LinkedIn, company website, leaked data, social media.

  3. 03

    Execution

    Spear phishing waves, vishing calls, optional physical intrusion. Everything logged and evidenced.

  4. 04

    Report & debrief

    Report in 7 business days + live board debrief. Immediate re-training for affected employees.

FAQ

Frequently asked questions

Is this legal? Is it safe?
Yes. We sign a full Rules of Engagement with you and work with a named internal sponsor. Every action is logged and evidenced.
Won't this demoralise employees?
No — we never name and shame. Feedback is private, educational and supportive. Done right, it raises morale and reporting rates.
How big is the target group?
Usually 20–200 people for spear phishing, 5–20 for vishing. Physical intrusion is usually 1–2 sites.
How long does it take?
3–4 weeks end-to-end: 1 week OSINT, 1–2 weeks execution, 1 week report.
Do we need HR and legal approval?
Yes — we help you prepare the internal approval, including works council if relevant.

Plan a social engineering test

30-minute scoping call, we propose targets, pretexts and schedule.