SV-03 · Social engineering
Phishing & Smishing Simulations
Realistic email and mobile-message campaigns that measure how well people and processes recognize, report, and escalate suspicious messages.
01 Overview
Why this engagement
A click is not the most important number. What matters is whether suspicious messages get reported, how fast the report reaches the right people, and what they do with it.
These simulations measure that full chain — people, process, and technical controls — and turn the results into improvements that stick.
Questions it answers
Do employees report suspicious messages — or just ignore them?
How fast does a report reach the security team, and what happens next?
Would our help desk verify a caller or message before acting on it?
02 Method
How the engagement runs
5 controlled phases. Each one ends with a concrete output you can review before the next begins.
Phase 1: Set objectives and safeguards
We agree the audience, channels, learning goals, exclusions, emergency contacts, and exactly which data may be collected and retained.
OutputCampaign charter
Phase 2: Design the scenario
I prepare realistic but proportionate email or SMS pretexts. Landing pages, sender infrastructure, and data handling are reviewed and approved before launch.
OutputApproved pretexts and infrastructure
Phase 3: Run the simulation
Messages go out in controlled windows. Campaign health and unexpected impact are monitored throughout. Credentials are not collected by default.
OutputCampaign telemetry
Phase 4: Measure the response
Beyond click rates, I measure reporting behavior, help-desk handling, security-team escalation, mail and mobile controls, and time to investigate.
OutputResponse timeline
Phase 5: Report and improve
Anonymized metrics, a response timeline, and control observations become targeted recommendations for training and process.
OutputReport and improvement plan
03 Scope
What can be assessed
Campaign types are chosen to match the agreed learning goals.
- Broad phishing
- Targeted spear-phishing
- Smishing (SMS)
- Reporting workflows
- Help-desk verification
- Escalation paths
04 Safeguards
Participant protection
Simulations exist to build resilience, not to catch people out. Participants are protected by design.
- No-shame approach to results
- Aggregated, anonymized reporting
- No credential collection by default
- Minimum necessary data, limited retention
- Stop conditions available at every stage
// Primary deliverable
A report built to be acted on
Every engagement ends with a detailed written report — readable by leadership, precise enough for engineers — followed by a technical readout and an optional executive debrief.
- Executive campaign summary
- Anonymized behavior and reporting metrics
- Detection and escalation timeline
- Control and process observations
- Targeted awareness recommendations
// More services