Home/Services/Social Engineering & Phishing Assessment
security service

Social Engineering & Phishing Assessment

Social engineering phishing assessment across Europe. We test whether your people can be tricked into letting an attacker in. Fixed price, no blame.

Manual, expert-ledEvidence-based findingsFree remediation retest

A social engineering phishing assessment tests the target no firewall protects: your people. Technology fails predictably, but a well-crafted email, a confident phone call or a friendly face at reception can talk a trained employee into handing over the keys, and that’s how most real breaches actually begin.

You can spend a fortune on security tooling and still lose everything because one person clicked a link and typed their password into a convincing copy of your login page. Attackers know this, which is why phishing and pretexting remain their favourite way in. We run the same techniques against your organisation, safely and under agreement, so you learn where the human layer bends before someone with worse intentions finds out for you.

What a social engineering phishing assessment covers

Social engineering is broader than email. It’s any manipulation that gets a person to act against the organisation’s interest, and a real attacker uses whichever channel works on the day. We test the ones relevant to you.

Targeted email phishing with realistic, sector-specific pretexts
Spear-phishing of named executives and finance staff
Credential-harvesting pages and MFA-fatigue simulation
Vishing: pretext phone calls to helpdesk and staff
Smishing: SMS-based lures and second-factor interception
USB-drop and physical pretext where you include them

Realistic, not a canned template

The generic “your mailbox is full” template teaches employees nothing, because a real attacker wouldn’t send it. We research your organisation first, build pretexts around genuine context, a plausible supplier, a current project, an internal system by name, and craft emails good enough to fool people who “know better”. A test that’s easy to spot flatters your numbers and protects no one.

Measuring behaviour, not catching people out

The aim is data, not a naming-and-shaming exercise. We measure who opened, who clicked, who entered credentials and, crucially, who reported it and how fast. That reporting rate matters as much as the click rate, because an organisation where the third recipient raises the alarm is in a very different position from one where nobody does.

How we run the assessment

Every campaign is planned with you, launched from dedicated infrastructure, and run under a clear agreement that protects both your people and your data. Nothing malicious ever touches a target machine; captured credentials go into an encrypted store and are never used beyond proving the point.

Reconnaissance and pretext design

We build an open-source intelligence picture of your organisation the way an attacker would: employee names and roles from LinkedIn, email formats, technologies you mention publicly, suppliers, and any credentials already exposed in past breaches. From that we design pretexts that fit your world, because relevance is what makes people click.

Campaign delivery

We register look-alike domains, configure sending infrastructure to pass basic email authentication where realistic, and launch in controlled waves so we don’t overwhelm your mail systems or your helpdesk. Landing pages mirror your real login experience closely enough to be convincing, and every interaction is logged with a timestamp.

MFA is not a magic shield

Many clients assume multi-factor authentication makes phishing irrelevant. It doesn’t. Real-time relay pages capture the second factor as the user enters it, and MFA-fatigue attacks simply push prompts until a tired employee taps “approve”. Where you allow it, we demonstrate these safely so you see that MFA raises the bar without closing the door.

Vishing and physical pretext

Where the scope includes it, we call. A confident voice claiming to be from IT, a supplier chasing an invoice, or a new starter locked out of an account can extract more than any email. Helpdesks that reset passwords or MFA on the strength of a name and a plausible story are a common and serious finding.

Analysis and reporting

When the campaign closes we analyse the numbers and the narrative: click and submission rates by department, time-to-report, which pretexts worked and why, and what an attacker would have achieved with the credentials captured. Then we brief you, and we keep the tone constructive so the outcome is a stronger workforce, not a frightened one.

1–3
weeks for a full multi-wave campaign
100%
bespoke pretexts, no off-the-shelf templates
No
blame culture: the goal is learning, not gotchas

The attacks we simulate

Phishing is a family, not a single technique, and the right mix depends on who you are and who targets you. We match the simulation to the threats your sector genuinely faces.

Bulk phishing

The wide net: a plausible message sent to much of the workforce to measure baseline susceptibility and reporting. It answers the simplest and most important question, what proportion of your staff click and enter credentials on a decent lure, and gives you a number to improve against.

Spear-phishing and whaling

Here we go narrow and deep, targeting a handful of high-value people such as finance approvers, executives and system administrators with heavily researched, personalised messages. These are the attacks that lead to real money moving or privileged access being handed over, so a single success here matters far more than a dozen bulk clicks.

Business email compromise

We simulate the invoice-redirection and payment-request fraud that costs European businesses more than almost any other cybercrime. The test probes your payment-approval process directly: whether a convincing email really can move funds without an out-of-band check, and where that process needs a hard stop.

Reply-chain and thread-hijack lures

Modern attackers don’t send cold emails, they inject into existing conversations, replying within a real thread from a look-alike address so the message inherits the trust of everything above it. We reproduce this to test whether your people spot the switch when the context looks entirely genuine.

Get a fixed quote

Want this tested on your own systems?

Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.

Get a fixed quote

Why the human layer keeps failing

People aren’t stupid, and blaming them misses the point. They’re busy, they trust colleagues and suppliers, and attackers exploit exactly the instincts that make an organisation function. Understanding why the failures happen is the first step to fixing them.

Urgency and authority

An email that appears to come from the CEO demanding an urgent payment bypasses careful thought, because questioning authority under time pressure feels risky. Business email compromise built on this single lever costs European companies enormous sums every year, and it needs no malware at all.

Context and familiarity

A message referencing a real project, a genuine supplier or a system your staff use daily lowers everyone’s guard. The more an attacker knows about you, and open sources reveal a great deal, the more convincing the lure and the higher the click rate.

Process gaps at the helpdesk

The service desk exists to be helpful and unblock people quickly, which makes it a prime target. Without strict identity verification, a caller with a name and a story can get a password reset or an MFA re-enrolment, and that single act can hand over an account.

What you get

Numbers you can track over time, a clear picture of the risk, and practical steps that actually reduce it.

Metrics and executive summary

Click rate, submission rate, report rate and time-to-report, broken down by department and role, with a plain-language summary for leadership on what an attacker would have achieved and how you compare to where you should be.

Technical detail and evidence

The pretexts used, the infrastructure, screenshots of landing pages, and a step-by-step account of what captured credentials would have opened up, tied to real impact rather than abstract risk.

Awareness recommendations and retest

Specific, prioritized recommendations covering training, technical controls such as email authentication and phishing-resistant MFA, and helpdesk process. A follow-up campaign later measures whether the changes moved the numbers, which is the only proof that matters.

Debrief for the security team

We walk your team through the campaign in a working session: which lures landed, why they worked, and what a defender should have seen at each stage. Many of the most useful fixes come out of this conversation, from tightening an email rule to rewriting the helpdesk’s identity-verification script, and it turns a set of raw numbers into a concrete, funded plan the team genuinely owns.

Compliance and standards

Social engineering testing supports several frameworks and, increasingly, is expected as part of a mature programme.

ISO 27001, SOC 2 and PCI DSS

ISO 27001 Annex A control 6.3 covers information-security awareness, education and training, and auditors like to see it tested rather than merely delivered. SOC 2 expects evidence that awareness controls work, and PCI DSS 4.0 requirement 12.6 mandates a security-awareness programme that phishing simulation directly supports.

DORA and NIS2

For regulated entities, DORA and NIS2 both emphasise the human element of resilience and staff awareness. A documented, repeated social engineering programme is strong evidence that you take it seriously and measure it.

Pricing

Cost scales mainly with headcount and the channels in scope. A single email campaign to a modest workforce sits at the entry level; adding vishing, physical pretext and multiple waves raises it. Here is the typical shape.

Engagement What’s included Timeline Price
Email essentials Single tailored phishing campaign to up to ~100 staff, credential-harvest landing page, full metrics report 1–2 weeks from €1,500
Standard programme Multi-wave phishing plus spear-phishing of key roles, MFA-relay demonstration, larger headcount, exec and technical reporting 2–3 weeks €2,500–€6,000
Multi-channel Phishing, vishing and smishing combined, helpdesk pretext testing, detailed behavioural analysis 3–4 weeks €5,000–€12,000
Awareness add-on Follow-up retest campaign and tailored staff-training material to measure improvement with any tier from €900
Custom / large workforce Thousands of staff or many locations, scoped after a call on scoping custom

Every engagement is fixed-price, quoted after a free 20-minute scoping call, with no hourly surprises and a follow-up campaign available. Get a fixed quote

FAQ

How much does a social engineering phishing assessment cost?
It starts from €1,500 for a single tailored email campaign and scales mainly with headcount and the channels included, such as vishing or physical pretext. You get a fixed quote after a free scoping call.
How long does a campaign take?
A single phishing campaign runs 1–2 weeks including planning and reporting, and multi-channel programmes with vishing and several waves take 3–4 weeks. Reconnaissance and pretext design are the parts that take real care.
Will you name and shame the employees who fall for it?
No. We report numbers by department and role, not by individual, and the whole exercise is framed as learning. A blame culture just teaches people to hide their mistakes, which is the opposite of what you want.
Doesn’t MFA make phishing pointless?
No. Real-time relay pages capture the second factor as it’s entered, and MFA-fatigue attacks push prompts until someone approves one. We demonstrate this safely so you can see why phishing-resistant MFA and awareness both matter.
Is this safe, and what happens to captured passwords?
It’s safe by design. No malware touches any device, and any credentials submitted go into an encrypted store used only to prove impact, then destroyed. Everything runs under a written agreement and NDA.
Can you test phone calls and physical entry too?
Yes, where you include them. Vishing calls to staff and the helpdesk, smishing by SMS, and physical pretexts such as posing as a visitor or dropping USB devices can all be part of the assessment. You choose the channels.
Does this satisfy ISO 27001 or PCI DSS awareness requirements?
Yes. The programme and its metrics support ISO 27001 Annex A awareness controls, SOC 2, and PCI DSS 4.0 requirement 12.6 for a security-awareness programme. Tell us your framework and we shape the reporting to it.
How do we prove our staff are getting better?
By retesting. As a European social engineering and phishing company, we run a follow-up campaign after your training and controls change, so you can compare click and report rates over time. Measured improvement is the only evidence that counts.

Related services

Who needs this

Any organisation whose staff handle money, data or access requests: finance teams exposed to business email compromise, companies with large or distributed workforces, helpdesks that perform password and MFA resets, and any business that has invested in awareness training and wants to know whether it actually changed behaviour.

why safetybis

Security you can prove

The same standard on every engagement, big or small.

Evidence, not opinions

Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".

Humans over scanners

Certified engineers find the logic flaws and chained attacks automated tools walk straight past.

Fixed price, free retest

You know the cost up front, and verifying the fix is part of the deal — not a second invoice.

500+
assessments delivered
<30min
incident first response
12k+
infections removed
98%
fixed within one retest
$ safetybis quote --service "Social Engineering & Phishing Assessment"

Ready to lock this down?

Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.

get in touch

Tell us what you're running

Scoping is free. We reply within one business day, and under 30 minutes for active incidents.