Most serious breaches don't start with an exploit, they start with a message, a call, or someone walking through a door they shouldn't have reached. We run phishing, vishing, smishing and physical intrusion campaigns that test how your people actually respond under pressure, not how they answer a training quiz.
Email-based pretexts, from broad awareness tests to targeted spear-phishing.
Phone-based social engineering, including high-pressure pretexts like urgent payment or M&A requests.
Text-message based attempts, exploiting the same urgency on a channel with less scrutiny.
Attempts to talk or follow a way into premises that should be restricted.
Technical controls stop a lot. They don't stop a convincing phone call from someone who sounds exactly like they should be trusted. Real attackers know this, and they use it: a fabricated urgent payment request, a caller impersonating IT, a pretext built around a real event like a merger or a system migration.
If a campaign catches someone, that is evidence of a gap in process or training, not a reason to single out the individual. Reporting is aggregated by team, not by name.
Not whether staff can recite a policy, but what they actually do when a plausible, well-timed pretext lands in their inbox or on their phone.
The goal is never to catch people out. It's to find out, before a real attacker does, whether your organisation's process would hold up against a genuinely convincing attempt.
What is in scope, what is off-limits, and how anything sensitive discovered along the way is handled.
A campaign built around scenarios realistic to your organisation and sector, not a generic template.
Executed across the agreed channels, whether email, phone, text or in person.
Aggregated results by team and department, with the patterns that actually matter for training.
Targeted awareness activity where the results show it is genuinely needed, not a blanket annual module.
CounterPhish isn't only about testing your own people. When a genuine phishing site or campaign is found impersonating your organisation or your customers, we can pursue disruption and takedown of the malicious infrastructure itself.
Phishing is a simulated attack by email, vishing by phone call, and smishing by text message. All three exploit the same weakness: a person being placed under pressure to act quickly without verifying who is really asking.
No. Reporting is aggregated by team and department to show genuine behavioural patterns. The purpose is to fix the gap, not to blame the person who was targeted, since a well-crafted pretext is designed to catch almost anyone.
When a real phishing site or campaign is found impersonating your organisation, CounterPhish can pursue takedown of the malicious infrastructure, not just simulate the same attack internally.
Yes. Physical social engineering tests whether a determined visitor can talk or follow their way into premises they should not have access to, complementing the digital campaigns.
Behaviour drifts the same way technical configuration does. Most organisations run campaigns on a recurring cycle rather than as a single annual exercise, so improvement can actually be measured over time.
Engagements are scoped individually, with clear rules of engagement agreed up front. Tell us what you're trying to protect, and we'll design a campaign that actually answers the question.
Confidential, no obligation, and scoped around your organisation.