Social engineering within agreed limits
Mail, telephone and the way in through the door, with limits fixed beforehand. The report describes what happened and names nobody.
The route through people goes past the technology
Technical measures hold against technical attacks. A call from the supposed IT department, a mail with a plausible invoice, or someone in overalls at reception goes around them.
We test those routes within limits agreed beforehand: which pretexts are allowed, which areas stay out of scope, and when we stop. The result describes what happened, not who did it.
Every pretext starts with open research, OSINT: names, roles, responsibilities, current projects, the pattern of the email addresses. The more precise that is, the more credible the call, and the more honest the exercise.
Mail, telephone and the way through the door
The mail tests whether a request gets acted on without anyone checking back. The call tests whether someone has to identify themselves on the phone before having a password reset. The visit tests whether an unknown person with a work order and a high-vis vest gets as far as the server room.
Every route ends at an agreed limit. We take no data with us, we report where we would have got to, and we name nobody. Who clicked a mail is of no importance to the report; that no check-back was provided for anywhere is the finding.
How an exercise runs
The limits decide the value of the exercise, not the day itself. They are fixed in writing before the first call goes out.
Fix the limits
Which routes are allowed, which areas stay out of scope, which pretexts are ruled out, and when we stop. The works council sits at this table, and the undertaking not to evaluate on individuals is written into the engagement.
Open research
Names, roles, responsibilities, current projects, the pattern of the email addresses. That is the same work an attacker does, and it determines which pretext is credible at all.
The attempt
Mail, telephone and the way in on foot, in the agreed order. Every step is logged, every one ends at the agreed limit, and we take no data with us.
Write-up
What gets described is procedures and safeguards, not people. The finding is not who clicked but that at some point no check-back was provided for.
Common questions about social engineering
The simulation is the repeatable mass send with a rate and a learning effect. Social engineering is targeted, uses the telephone and the way in on foot as well, and works with pretexts cut for your organisation. To begin with, the simulation is the better step.
It belongs at the table before anything starts. We do not evaluate on individuals and deliver no lists of names. That undertaking is written into the engagement, and the works council can check it.
Then the test worked. Recognising practised attackers is luck or suspicion. A procedure that requires a check-back does not depend on the day someone is having.
Certifications and memberships.
Talk to us.
A first conversation usually takes 30 minutes. We look at where you stand and tell you frankly whether we are the right partner.