Skip to content
TheoSec

03Ongoing · Human-crafted

Your staff can spot
a template. That's the problem.

Most phishing simulation platforms send the same generic emails to every client. Staff learn to recognise the simulation, not the attack. Every campaign here is written from scratch using your real business context — because that is exactly what the people targeting you are doing.

  • Email, SMS, voice and social channels
  • Pretexts built from your real business context
  • Teachable-moment training on failure
  • Monthly reporting and trend analysis

//The argument

A test everyone passes teaches nobody anything.

Template-based simulations produce a comfortable statistic and very little else. Staff quickly learn the tells — the odd sender domain, the stock imagery, the same four scenarios on rotation — and start passing a test rather than developing judgement.

A real attacker researches your suppliers, mirrors your internal tone, times the approach for your month-end, and references a project that genuinely exists. Nothing about that is generic.

If the simulation is easier than the real thing, the number it produces is worse than useless — it is falsely reassuring.

This engagement

  • Written by hand for your organisation
  • Pretexts built from real OSINT about your business
  • Email, SMS, voice and social channels
  • Difficulty escalates as your people improve
  • Teachable-moment training at the point of failure

Template platforms

  • Same library sent to every customer
  • No knowledge of your suppliers or processes
  • Email only, in most cases
  • Static difficulty, recognisable within weeks
  • A training video queued for next quarter

01Campaign types

Six pretexts, mixed to match your risk.

Which of these run, and how aggressively, is agreed with you up front. Some organisations want the full range; others rule out voice or executive impersonation entirely.

Credential harvesting

Convincing sign-in pages for the platforms your staff actually use, delivered through whichever channel is most plausible for the pretext.

Malicious attachments

Safe but realistic invoices, contracts and CVs that test whether your attachment-handling procedures survive contact with a busy Tuesday.

Business email compromise

Urgent requests appearing to come from an executive or a trusted supplier. Tests authority verification — the control most often skipped under time pressure.

Spear phishing

Highly targeted approaches built from OSINT about specific individuals, their projects and their working relationships.

Supplier impersonation

Requests to change banking details or approve access, arriving from a partner your finance team recognises by name.

Vishing & smishing

Voice and SMS approaches, often chained with email to build a pretext across channels the way real operators do.

02How a programme runs

Continuous, adaptive, and never quite the same twice.

  1. 01

    Discovery

    We learn how your organisation communicates — your suppliers, your tone, your internal processes, your busy periods.

  2. 02

    Craft

    Campaigns are written by hand for your specific context. Not selected from a template library and find-replaced.

  3. 03

    Deploy

    Campaigns run across the agreed channels while we track clicks, submissions and — most importantly — reports.

  4. 04

    Teach

    Anyone who falls for it gets an immediate, blame-free explanation of what they missed, at the moment it will actually land.

03Ethics

Testing people is not the same as tricking them.

Social engineering testing done carelessly damages trust and makes your security culture worse. These are the rules we work to, and they are not negotiable.

Never punitive
Results identify where training is needed, not who to discipline. If leadership wants a list of people to punish, we are the wrong supplier.
No credentials captured
Submitted passwords are never stored. The simulation records that a submission happened, never what was typed.
Off-limits pretexts
No fake redundancies, bonuses, medical results or bereavements. Cruelty is not rigour, and it poisons the programme.
Reported as a win
Reporting rate matters more than click rate. A workforce that reports quickly beats one that simply clicks less.
Aggregate reporting
Findings are reported by department and trend. Individual results stay between the person and the training that follows.

Next step

Find out how your people really do.

A first campaign gives you an honest baseline — usually a more uncomfortable one than the platform you are using now has been reporting.

daniel@theosec.com · +27 63 484 1051