SecureBlockLog in
All servicesSocial Engineering

Measure your human risk layer before attackers exploit it.

Targeted spear-phishing, MFA fatigue, vishing, and pretext campaigns — consent-based exercises that quantify your exposure and give your team real training data.

Consent-based alwaysRole-targeted campaignsAwareness reporting included
What we test

Full coverage, tested by hand.

Every assessment is led by an OSCP- or CREST-certified tester — not a scanner with a human proofreading the output.

Targeted spear-phishing

OSINT-driven campaigns crafted to your employees, roles, and current company events — the way real threat actors target organisations, not generic mass-phishing.

MFA fatigue & push abuse

Test whether MFA push notification fatigue attacks succeed against your employee base, with response rates segmented by department and role.

Vishing (voice phishing)

Phone-based pretexting scenarios — IT helpdesk impersonation, executive fraud, and vendor credential requests — to test voice-channel resilience.

Awareness metrics & reporting

Click rates, credential submission rates, and reporting rates segmented by department and role — actionable data for your security awareness programme.

Methodology

How we run the engagement.

A structured process that ends with a report you can hand directly to your auditor.

1
Consent & scoping

Engagement rules agreed in writing: target list, campaign types, start/end window, and out-of-scope individuals.

2
OSINT & pretext development

Build realistic pretexts from public information: LinkedIn, company website, press releases, and event calendars.

3
Campaign execution

Phishing waves deployed in controlled phases. Real-time dashboard shows click, credential, and reporting metrics.

4
Debrief & training data

Full report with per-department breakdown, scenario recreations, and recommended training materials.

Sample findings

The kind of issues we find.

Real finding types from past engagements — titles and targets anonymised.

highCVSS 7.2SB-SE-001
34% of employees submitted credentials in spear-phishing campaign
Finance & HR departments (87 targets)Week 1
Remediation — Deploy targeted security awareness training for high-click departments. Enforce phishing-resistant MFA (FIDO2) for all users.
highCVSS 6.8SB-SE-002
Helpdesk reset password without verifying caller identity
IT Helpdesk — 3 of 5 calls succeededWeek 1
Remediation — Implement a callback verification procedure for all password resets. Require out-of-band identity confirmation through HR system.
mediumCVSS 5.0SB-SE-003
MFA push fatigue accepted by 12% of targeted users
18 users received repeated push notificationsWeek 2
Remediation — Enable number matching and additional context in MFA push notifications. Consider FIDO2 hardware keys for privileged accounts.
FAQ

Questions about this service.

Still unsure? Ask an engineer in chat — not a sales rep.

Senior leadership is informed; individual employees are not, to ensure realistic results. Post-test we recommend a transparency communication.

Know where you stand before your auditor does.