Social Engineering & Phishing Assessment
Social engineering phishing assessment across Europe. We test whether your people can be tricked into letting an attacker in. Fixed price, no blame.
A social engineering phishing assessment tests the target no firewall protects: your people. Technology fails predictably, but a well-crafted email, a confident phone call or a friendly face at reception can talk a trained employee into handing over the keys, and that’s how most real breaches actually begin.
You can spend a fortune on security tooling and still lose everything because one person clicked a link and typed their password into a convincing copy of your login page. Attackers know this, which is why phishing and pretexting remain their favourite way in. We run the same techniques against your organisation, safely and under agreement, so you learn where the human layer bends before someone with worse intentions finds out for you.
What a social engineering phishing assessment covers
Social engineering is broader than email. It’s any manipulation that gets a person to act against the organisation’s interest, and a real attacker uses whichever channel works on the day. We test the ones relevant to you.
Realistic, not a canned template
The generic “your mailbox is full” template teaches employees nothing, because a real attacker wouldn’t send it. We research your organisation first, build pretexts around genuine context, a plausible supplier, a current project, an internal system by name, and craft emails good enough to fool people who “know better”. A test that’s easy to spot flatters your numbers and protects no one.
Measuring behaviour, not catching people out
The aim is data, not a naming-and-shaming exercise. We measure who opened, who clicked, who entered credentials and, crucially, who reported it and how fast. That reporting rate matters as much as the click rate, because an organisation where the third recipient raises the alarm is in a very different position from one where nobody does.
How we run the assessment
Every campaign is planned with you, launched from dedicated infrastructure, and run under a clear agreement that protects both your people and your data. Nothing malicious ever touches a target machine; captured credentials go into an encrypted store and are never used beyond proving the point.
Reconnaissance and pretext design
We build an open-source intelligence picture of your organisation the way an attacker would: employee names and roles from LinkedIn, email formats, technologies you mention publicly, suppliers, and any credentials already exposed in past breaches. From that we design pretexts that fit your world, because relevance is what makes people click.
Campaign delivery
We register look-alike domains, configure sending infrastructure to pass basic email authentication where realistic, and launch in controlled waves so we don’t overwhelm your mail systems or your helpdesk. Landing pages mirror your real login experience closely enough to be convincing, and every interaction is logged with a timestamp.
MFA is not a magic shield
Many clients assume multi-factor authentication makes phishing irrelevant. It doesn’t. Real-time relay pages capture the second factor as the user enters it, and MFA-fatigue attacks simply push prompts until a tired employee taps “approve”. Where you allow it, we demonstrate these safely so you see that MFA raises the bar without closing the door.
Vishing and physical pretext
Where the scope includes it, we call. A confident voice claiming to be from IT, a supplier chasing an invoice, or a new starter locked out of an account can extract more than any email. Helpdesks that reset passwords or MFA on the strength of a name and a plausible story are a common and serious finding.
Analysis and reporting
When the campaign closes we analyse the numbers and the narrative: click and submission rates by department, time-to-report, which pretexts worked and why, and what an attacker would have achieved with the credentials captured. Then we brief you, and we keep the tone constructive so the outcome is a stronger workforce, not a frightened one.
The attacks we simulate
Phishing is a family, not a single technique, and the right mix depends on who you are and who targets you. We match the simulation to the threats your sector genuinely faces.
Bulk phishing
The wide net: a plausible message sent to much of the workforce to measure baseline susceptibility and reporting. It answers the simplest and most important question, what proportion of your staff click and enter credentials on a decent lure, and gives you a number to improve against.
Spear-phishing and whaling
Here we go narrow and deep, targeting a handful of high-value people such as finance approvers, executives and system administrators with heavily researched, personalised messages. These are the attacks that lead to real money moving or privileged access being handed over, so a single success here matters far more than a dozen bulk clicks.
Business email compromise
We simulate the invoice-redirection and payment-request fraud that costs European businesses more than almost any other cybercrime. The test probes your payment-approval process directly: whether a convincing email really can move funds without an out-of-band check, and where that process needs a hard stop.
Reply-chain and thread-hijack lures
Modern attackers don’t send cold emails, they inject into existing conversations, replying within a real thread from a look-alike address so the message inherits the trust of everything above it. We reproduce this to test whether your people spot the switch when the context looks entirely genuine.
Want this tested on your own systems?
Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.
Why the human layer keeps failing
People aren’t stupid, and blaming them misses the point. They’re busy, they trust colleagues and suppliers, and attackers exploit exactly the instincts that make an organisation function. Understanding why the failures happen is the first step to fixing them.
Urgency and authority
An email that appears to come from the CEO demanding an urgent payment bypasses careful thought, because questioning authority under time pressure feels risky. Business email compromise built on this single lever costs European companies enormous sums every year, and it needs no malware at all.
Context and familiarity
A message referencing a real project, a genuine supplier or a system your staff use daily lowers everyone’s guard. The more an attacker knows about you, and open sources reveal a great deal, the more convincing the lure and the higher the click rate.
Process gaps at the helpdesk
The service desk exists to be helpful and unblock people quickly, which makes it a prime target. Without strict identity verification, a caller with a name and a story can get a password reset or an MFA re-enrolment, and that single act can hand over an account.
What you get
Numbers you can track over time, a clear picture of the risk, and practical steps that actually reduce it.
Metrics and executive summary
Click rate, submission rate, report rate and time-to-report, broken down by department and role, with a plain-language summary for leadership on what an attacker would have achieved and how you compare to where you should be.
Technical detail and evidence
The pretexts used, the infrastructure, screenshots of landing pages, and a step-by-step account of what captured credentials would have opened up, tied to real impact rather than abstract risk.
Awareness recommendations and retest
Specific, prioritized recommendations covering training, technical controls such as email authentication and phishing-resistant MFA, and helpdesk process. A follow-up campaign later measures whether the changes moved the numbers, which is the only proof that matters.
Debrief for the security team
We walk your team through the campaign in a working session: which lures landed, why they worked, and what a defender should have seen at each stage. Many of the most useful fixes come out of this conversation, from tightening an email rule to rewriting the helpdesk’s identity-verification script, and it turns a set of raw numbers into a concrete, funded plan the team genuinely owns.
Compliance and standards
Social engineering testing supports several frameworks and, increasingly, is expected as part of a mature programme.
ISO 27001, SOC 2 and PCI DSS
ISO 27001 Annex A control 6.3 covers information-security awareness, education and training, and auditors like to see it tested rather than merely delivered. SOC 2 expects evidence that awareness controls work, and PCI DSS 4.0 requirement 12.6 mandates a security-awareness programme that phishing simulation directly supports.
DORA and NIS2
For regulated entities, DORA and NIS2 both emphasise the human element of resilience and staff awareness. A documented, repeated social engineering programme is strong evidence that you take it seriously and measure it.
Pricing
Cost scales mainly with headcount and the channels in scope. A single email campaign to a modest workforce sits at the entry level; adding vishing, physical pretext and multiple waves raises it. Here is the typical shape.
| Engagement | What’s included | Timeline | Price |
|---|---|---|---|
| Email essentials | Single tailored phishing campaign to up to ~100 staff, credential-harvest landing page, full metrics report | 1–2 weeks | from €1,500 |
| Standard programme | Multi-wave phishing plus spear-phishing of key roles, MFA-relay demonstration, larger headcount, exec and technical reporting | 2–3 weeks | €2,500–€6,000 |
| Multi-channel | Phishing, vishing and smishing combined, helpdesk pretext testing, detailed behavioural analysis | 3–4 weeks | €5,000–€12,000 |
| Awareness add-on | Follow-up retest campaign and tailored staff-training material to measure improvement | with any tier | from €900 |
| Custom / large workforce | Thousands of staff or many locations, scoped after a call | on scoping | custom |
Every engagement is fixed-price, quoted after a free 20-minute scoping call, with no hourly surprises and a follow-up campaign available. Get a fixed quote
FAQ
How much does a social engineering phishing assessment cost?
How long does a campaign take?
Will you name and shame the employees who fall for it?
Doesn’t MFA make phishing pointless?
Is this safe, and what happens to captured passwords?
Can you test phone calls and physical entry too?
Does this satisfy ISO 27001 or PCI DSS awareness requirements?
How do we prove our staff are getting better?
Related services
Any organisation whose staff handle money, data or access requests: finance teams exposed to business email compromise, companies with large or distributed workforces, helpdesks that perform password and MFA resets, and any business that has invested in awareness training and wants to know whether it actually changed behaviour.
Security you can prove
The same standard on every engagement, big or small.
Evidence, not opinions
Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".
Humans over scanners
Certified engineers find the logic flaws and chained attacks automated tools walk straight past.
Fixed price, free retest
You know the cost up front, and verifying the fix is part of the deal — not a second invoice.
Ready to lock this down?
Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.