SV-03 · Social engineering

Phishing & Smishing Simulations

Realistic email and mobile-message campaigns that measure how well people and processes recognize, report, and escalate suspicious messages.

01 Overview

Why this engagement

A click is not the most important number. What matters is whether suspicious messages get reported, how fast the report reaches the right people, and what they do with it.

These simulations measure that full chain — people, process, and technical controls — and turn the results into improvements that stick.

Questions it answers

  1. Do employees report suspicious messages — or just ignore them?

  2. How fast does a report reach the security team, and what happens next?

  3. Would our help desk verify a caller or message before acting on it?

02 Method

How the engagement runs

5 controlled phases. Each one ends with a concrete output you can review before the next begins.

  1. Phase 1: Set objectives and safeguards

    We agree the audience, channels, learning goals, exclusions, emergency contacts, and exactly which data may be collected and retained.

    OutputCampaign charter

  2. Phase 2: Design the scenario

    I prepare realistic but proportionate email or SMS pretexts. Landing pages, sender infrastructure, and data handling are reviewed and approved before launch.

    OutputApproved pretexts and infrastructure

  3. Phase 3: Run the simulation

    Messages go out in controlled windows. Campaign health and unexpected impact are monitored throughout. Credentials are not collected by default.

    OutputCampaign telemetry

  4. Phase 4: Measure the response

    Beyond click rates, I measure reporting behavior, help-desk handling, security-team escalation, mail and mobile controls, and time to investigate.

    OutputResponse timeline

  5. Phase 5: Report and improve

    Anonymized metrics, a response timeline, and control observations become targeted recommendations for training and process.

    OutputReport and improvement plan

03 Scope

What can be assessed

Campaign types are chosen to match the agreed learning goals.

  • Broad phishing
  • Targeted spear-phishing
  • Smishing (SMS)
  • Reporting workflows
  • Help-desk verification
  • Escalation paths

04 Safeguards

Participant protection

Simulations exist to build resilience, not to catch people out. Participants are protected by design.

  • No-shame approach to results
  • Aggregated, anonymized reporting
  • No credential collection by default
  • Minimum necessary data, limited retention
  • Stop conditions available at every stage

// Primary deliverable

A report built to be acted on

Every engagement ends with a detailed written report — readable by leadership, precise enough for engineers — followed by a technical readout and an optional executive debrief.

  • Executive campaign summary
  • Anonymized behavior and reporting metrics
  • Detection and escalation timeline
  • Control and process observations
  • Targeted awareness recommendations
View a sample report

// More services

Related engagements

All services

Start searching

Enter keywords to search projects and pages.