Skip to content
Domain · Human Factor

Social Engineering & Awareness

The human factor treated as attack vector — and as a pillar of defense. Controlled campaigns and a continuous program, integrated on a single page.

Overview

We combine controlled social engineering campaigns with a continuous security culture program. We don't measure declared knowledge — we measure real behavior. Credible pretexts, real-time curation, micro-training at the moment of the click, and objective metrics per squad and profile.

Each engagement begins with an intelligence phase (corporate OSINT, risk profiles, and plausible pretexts), executes controlled waves through relevant channels (email, voice, SMS, and physical), and closes with a joint review between security, HR, and internal communications — converting learning into policy, process, and training.

Everything included

Phishing — corporate email campaigns
Spear Phishing — C-Level and critical areas
Vishing — voice social engineering
Smishing — SMS and corporate messaging
Physical pretext — tailgating and physical access
Awareness tracks by profile
Periodic simulations and indicators per squad
Module 01 · Human Offensive

Social Engineering Tests

Five vectors to measure real human factor resilience — from the subtlest email to physical tailgating. Credible pretexts, real-time curation, and executive report by area, profile, and channel.

Email · Volume

Phishing

Mass corporate email campaigns with credible pretexts — credentials, invoices, HR, and IT — calibrated by profile and area.

C-Level · Single target

Spear Phishing

Highly targeted operation — unique pretext, deep OSINT, and timing — to validate leadership and critical areas resilience.

Voice · Service

Vishing

Voice social engineering — service, vendor, or leadership pretexts — with ethical recording and protocol adherence metrics.

SMS · Messaging

Smishing

SMS, WhatsApp, and corporate messaging with short-links and urgent pretexts — delivery, bank, or IT — measuring the click reflex outside the desktop.

Tailgating · Physical

Physical Pretext

Tailgating, fake vendor, and unauthorized access to restricted areas — to validate visitor policies, badges, and team vigilance.

Module 02 · Continuous Program

Awareness and Culture

Continuous program that moves the real indicator — not just declared knowledge. Tracks by profile, periodic simulations, and objective metrics by area, squad, and channel.

By profile · By area

Profile-based Tracks

Segmented content by risk profile and function — customer service, finance, development, leadership, and operations — with micro-lessons, real cases, and track evaluation.

Monthly · Quarterly cadence

Periodic Simulations

Controlled waves of phishing, vishing, and smishing on a continuous cadence — with micro-training at the moment of the click and learning curve per employee.

KPIs · Culture

Metrics & Culture

Objective indicators per squad and area — click, report, response time, and policy adherence — with executive review ritual and cultural activation plan.

Ready to get started?

In a 30-minute conversation, we’ll design the right scope for your context — from a targeted campaign to a continuous security culture program.

Contact Us