Deutsch

Offensive Services

Social Engineering

Technology can be hardened. People can only be prepared. A social engineering assessment tests how your organisation reacts when somebody asks politely instead of breaking in — and provides the basis for learning from it.

01

What we test

We reproduce how attackers actually operate: not with a generic bulk email, but with whatever is publicly discoverable about your company. Job adverts reveal the software in use, LinkedIn the reporting lines, a press release the moment at which an invented urgency sounds plausible.

  • Phishing: targeted emails built from publicly available information
  • Spear phishing: individual recipients in key roles, with a fitting pretext
  • Vishing: phone calls in the name of IT support, auditors or the management board
  • Smishing: text messages applying pressure to act, sent to company mobiles
  • Physical access: testing reception, badge rules and how visitors are escorted
  • Baiting: prepared USB media left where they are meant to be found
A massive, otherwise unbroken concrete wall. One narrow door stands slightly ajar, cool light falling from it onto the floor.

How we proceed

That last point matters to us. A test that leaves nothing behind but a click rate improves nothing — it creates mistrust. Every assessment therefore ends with a debrief for the workforce showing how the attack could have been recognised. Making that permanent is what the Security Awareness Training is for.

  1. 01

    Agreement

    objectives, limits and escalation routes are settled in writing beforehand

  2. 02

    Reconnaissance

    analysis of publicly accessible sources on the company and its staff

  3. 03

    Execution

    the agreed scenarios, within agreed time windows

  4. 04

    Analysis

    rates per scenario and department, without naming individuals

  5. 05

    Follow-up

    training on exactly the patterns that worked

What you receive

  1. 01

    A report with rates by scenario, department and over time — anonymised

  2. 02

    Example attack chains including the pretexts actually used

  3. 03

    An assessment of the technical safeguards

    mail filtering, reporting route, response time

  4. 04

    Concrete recommendations, separated into technology, process and training

  5. 05

    On request, a repeat measurement after six to twelve months

02

A social engineering assessment touches on personal rights and on employee representation. We work exclusively on the basis of a written engagement, settle the scope with your data protection officer and works council, and as a matter of principle do not analyse results per person. No result of our test is suitable as grounds for disciplinary measures — and that is deliberate.

03

When it is worth doing

Ahead of an ISO 27001 certification, as recurring evidence under NIS2, after an actual incident, or when a merger brings two security cultures together. Alongside it, Penetration Testing examines the technical side, and Red Teaming both in combination.

Offensive Services

More in this area

Penetration Testing

Authorised attacks on your systems — black, white or grey box, external and internal. With findings ranked by severity …

View

Vulnerability Scanning

Outer skin, internal network, web applications and cloud checked continuously against CVE — rated against your situatio…

View

Red Team Operations

Six to eight weeks against one agreed objective — technology, people, buildings. What is measured is your detection, no…

View

Contact

Reputation takes years. Destruction takes seconds.

Talk to us before somebody else does. The first conversation is free and we reply the same business day.