Services Who We Are Resources Success Stories Contact Speak to a consultant
Social Engineering

Find out how your people actually respond.

Most serious breaches don't start with an exploit, they start with a message, a call, or someone walking through a door they shouldn't have reached. We run phishing, vishing, smishing and physical intrusion campaigns that test how your people actually respond under pressure, not how they answer a training quiz.

POWERED BY COUNTERPHISH · counterphish.co.uk
PHISHING

Email-based pretexts, from broad awareness tests to targeted spear-phishing.

VISHING

Phone-based social engineering, including high-pressure pretexts like urgent payment or M&A requests.

SMISHING

Text-message based attempts, exploiting the same urgency on a channel with less scrutiny.

PHYSICAL

Attempts to talk or follow a way into premises that should be restricted.

Why this matters

A well-crafted pretext is designed to catch almost anyone

Technical controls stop a lot. They don't stop a convincing phone call from someone who sounds exactly like they should be trusted. Real attackers know this, and they use it: a fabricated urgent payment request, a caller impersonating IT, a pretext built around a real event like a merger or a system migration.

IT'S NOT ABOUT ONE PERSON

If a campaign catches someone, that is evidence of a gap in process or training, not a reason to single out the individual. Reporting is aggregated by team, not by name.

IT MEASURES BEHAVIOUR

Not whether staff can recite a policy, but what they actually do when a plausible, well-timed pretext lands in their inbox or on their phone.

The goal is never to catch people out. It's to find out, before a real attacker does, whether your organisation's process would hold up against a genuinely convincing attempt.

How a campaign runs

Designed, run, measured, and fed back into training

01

Scope and agree rules of engagement

What is in scope, what is off-limits, and how anything sensitive discovered along the way is handled.

02

Design the pretext

A campaign built around scenarios realistic to your organisation and sector, not a generic template.

03

Run the campaign

Executed across the agreed channels, whether email, phone, text or in person.

04

Report on behaviour, not individuals

Aggregated results by team and department, with the patterns that actually matter for training.

05

Feed findings into training

Targeted awareness activity where the results show it is genuinely needed, not a blanket annual module.

Beyond simulation

Active phishing disruption and takedown

CounterPhish isn't only about testing your own people. When a genuine phishing site or campaign is found impersonating your organisation or your customers, we can pursue disruption and takedown of the malicious infrastructure itself.

Common questions

What people ask before running a campaign

What is the difference between phishing, vishing and smishing?

Phishing is a simulated attack by email, vishing by phone call, and smishing by text message. All three exploit the same weakness: a person being placed under pressure to act quickly without verifying who is really asking.

Will individual staff be named or singled out if they fail?

No. Reporting is aggregated by team and department to show genuine behavioural patterns. The purpose is to fix the gap, not to blame the person who was targeted, since a well-crafted pretext is designed to catch almost anyone.

What is active phishing disruption and takedown?

When a real phishing site or campaign is found impersonating your organisation, CounterPhish can pursue takedown of the malicious infrastructure, not just simulate the same attack internally.

Do you test physical intrusion as well?

Yes. Physical social engineering tests whether a determined visitor can talk or follow their way into premises they should not have access to, complementing the digital campaigns.

How often should we run a campaign?

Behaviour drifts the same way technical configuration does. Most organisations run campaigns on a recurring cycle rather than as a single annual exercise, so improvement can actually be measured over time.

Get started

Find out how your people would really respond

Engagements are scoped individually, with clear rules of engagement agreed up front. Tell us what you're trying to protect, and we'll design a campaign that actually answers the question.

Book a scoping call with our team

Confidential, no obligation, and scoped around your organisation.

+44 20 7862 3837 [email protected] counterphish.co.uk