What We Do
The Process
Latest Posts
[Advisory]TIBER-EU and DORA: What Financial Institutions Need to Understand Before the Notification Arrives
[Advisory]NIS2 Compliance in Portugal: Evidence Over Documentation
[Technical Research]Killing EDR visibility at the kernel: BYOVD
[Technical Research]ACL Abuse Havoc, a BOF toolkit for AD ACL exploitation via Havoc C2
Most breaches start with a click
Most breaches start with a person clicking something they should not. We replicate the exact techniques attackers use, from weaponised attachments and credential harvests to fake phone calls and impersonation, to find out who falls for it and help them get better.
Get StartedA one-hour awareness video does not prepare anyone for a well-crafted spear phishing email. Our campaigns are based on real attacks seen in the wild. Same techniques, same pressure, same psychology.
Learn MoreWe write each email by hand to match the lures, sender profiles, and payload delivery methods that threat groups are actually using against your sector right now. No templates.
We use publicly available information about your employees and executives to craft targeted emails. The same reconnaissance and lure building process a real attacker would use.
We call your employees with a convincing story and test whether they will hand over credentials, reset MFA, or do something they should not.
SMS campaigns that look like delivery notifications, IT alerts, or authentication prompts, the same lures modern phishing operators rely on.
We try to walk through your front door. Tailgating, impersonating vendors, dropping USB sticks in common areas. Testing whether your physical security holds up.
Attack Channels
Weaponised attachments, credential harvest pages, domain spoofing. Written by hand to match real campaigns.
Phone calls impersonating IT support, executives, or vendors. Testing whether employees hand over credentials or bypass controls.
Delivery notifications, authentication prompts, IT alerts. The same lures mobile-first phishing operators rely on.
Tailgating through the front door, impersonating contractors, dropping USB sticks in common areas. Testing your physical controls.
4
Channels Covered
Custom
Lures
Ongoing
Campaign Cycles
Measurable
Results
How It Works
Publicly available information about your organisation: email formats, employee roles, internal jargon, vendor relationships. Exactly like an attacker would.
We run the campaigns manually across whatever channels make sense for your threat profile: email, SMS, phone calls, or physical access attempts.
We track clicks, credential submissions, and response times. Every interaction is logged so you can see exactly where the risk is, without exposing personal data.
High-risk employees get targeted training, then we test again to see if it worked. Multiple campaigns over time build habits that stick.
Case Study
First campaign: 38% click rate. By the third, 11%. OFFCEPT's reporting showed exactly where the risk concentrated, which made it easy to justify keeping the programme running.
Director of Information Security
Multi-Site Healthcare Group
We run phishing campaigns built from the same playbooks attackers are using right now. Emails, phone calls, SMS, physical access. Find out who clicks before someone with worse intentions figures it out.
Get Started