Skip to content
Service 06

Social Engineering

Phishing, vishing, and pretexting campaigns run as a controlled test of your people, your process, and your ability to detect them.

Phishing, vishing, and everything in between

Social engineering is the opening move in a large share of the breaches that make the news. It bypasses the perimeter entirely, because it does not attack your technology — it asks one of your people for the keys, plausibly, at a moment when saying yes is the path of least resistance.

Brackish tests your organization against these attacks under controlled conditions, with agreed rules of engagement and a defined escalation path.

What we test

Phishing. Targeted email campaigns using pretexts built from what an attacker could actually learn about your organization, rather than a generic template.

Vishing. Voice-based pretexting against help desks, reception, and staff, to establish what an attacker can obtain or arrange over the phone.

Pretexting and in-person approaches. Where in scope, we test more than the inbox — a plausible visitor at reception, a call that sets up a drop. The building itself, as a dedicated target, is physical penetration testing. On a red team either thread is usually one part of a larger objective rather than a day of its own.

What we measure

The interesting numbers are not the ones that make a good slide. We report:

  • How many people engaged with the pretext, and how many reported it
  • How long it took from first interaction to first internal report
  • Whether the reporting path worked as documented when someone used it
  • What an attacker would have gained had the campaign been real

That last point matters most. A captured credential that hits multi-factor authentication and a monitored login alert is a very different outcome from one that opens a mailbox, and only one of them is worth acting on urgently.

What you receive

A campaign report covering the pretexts used, the aggregate response, the detection and escalation timeline, and specific recommendations for both technical controls and process. We do not name individuals unless you specifically require it.

Common questions

Social Engineering — what clients ask

Will you name the employees who fall for it?
Only if you ask us to, and we would advise against it. Naming individuals turns a test of your process into a disciplinary exercise, and the immediate result is that people stop reporting mistakes. We report aggregate rates, the pretexts that worked, and how quickly your team detected and escalated.
Is a click rate a useful measure?
On its own, not really. Click rate is easy to move with training and easy to game with a soft pretext, and it says nothing about what happens next. The numbers worth tracking are the report rate, the time from first click to first report, and whether a credential capture actually led anywhere.
How often should this run?
More often than once a year, and with varying pretexts. An annual test produces a compliance artifact and a spike of caution that fades in weeks. A regular cadence with genuine variety measures something closer to how your organization behaves on an ordinary day.

Strengthen your defenses.

Tell us what you need tested. We’ll come back with scope, timeline, and a fixed price.

Request a quote