04Ongoing · Human-crafted
Nobody falls
for templates.
Most phishing simulation platforms send the same generic emails to every client. Staff learn to recognise the simulation, not the attack. Every campaign here is written from scratch using your real business context — because that is exactly what the people targeting you are doing.
- Email, SMS, voice and social channels
- Pretexts built from your real payment relationships
- Support-desk and approval-process testing
- Teachable-moment training at the point of failure
//The argument
A test everyone passes teaches nobody anything.
Template-based simulations produce a comfortable statistic and very little else. Staff quickly learn the tells — the odd sender domain, the stock imagery, the same four scenarios on rotation — and start passing a test rather than developing judgement.
A real attacker researches your suppliers, mirrors your internal tone, times the approach for your month-end, and references a project that genuinely exists. Nothing about that is generic.
If the simulation is easier than the real thing, the number it produces is worse than useless — it is falsely reassuring.
This engagement
- Written by hand for your organisation
- Pretexts built from real OSINT about your business
- Email, SMS, voice and social channels
- Difficulty escalates as your people improve
- Teachable-moment training at the point of failure
Template platforms
- Same library sent to every customer
- No knowledge of your suppliers or processes
- Email only, in most cases
- Static difficulty, recognisable within weeks
- A training video queued for next quarter
01Campaign types
Six pretexts.
Which of these run, and how aggressively, is agreed with you up front. Some organisations want the full range; others rule out voice or executive impersonation entirely.
Credential harvesting
Convincing sign-in pages for the platforms your staff actually use, delivered through whichever channel is most plausible for the pretext.
Malicious attachments
Safe but realistic invoices, contracts and CVs that test whether your attachment-handling procedures survive contact with a busy Tuesday.
Business email compromise
Urgent requests appearing to come from an executive or a trusted supplier. Tests authority verification — the control most often skipped under time pressure.
Spear phishing
Highly targeted approaches built from OSINT about specific individuals, their projects and their working relationships.
Supplier impersonation
Requests to change banking details or approve access, arriving from a partner your finance team recognises by name.
Vishing & smishing
Voice and SMS approaches, often chained with email to build a pretext across channels the way real operators do.
02How a programme runs
Never the same twice.
- 01
Discovery
We learn how your organisation communicates — your suppliers, your tone, your internal processes, your busy periods.
- 02
Craft
Campaigns are written by hand for your specific context. Not selected from a template library and find-replaced.
- 03
Deploy
Campaigns run across the agreed channels while we track clicks, submissions and — most importantly — reports.
- 04
Teach
Anyone who falls for it gets an immediate, blame-free explanation of what they missed, at the moment it will actually land.
03The other half
A test nobody learns from is just a statistic.
Simulation tells you where you stand. Training is what moves it. Both are included, because either one alone reliably fails.
At the moment of failure
Anyone who falls for a campaign gets an immediate, blame-free explanation of exactly what they missed — delivered while it still stings enough to stick.
Demonstrated, not described
Live sessions where attacks are performed in front of the room. Watching a password fall in nine seconds changes behaviour in a way a bullet point never has.
Pitched by audience
General staff, technical teams and executives get different sessions. Executives face different attacks and deserve to be told so.
Measured honestly
We track reporting rate, not just click rate. A workforce that reports fast beats one that merely clicks less, and only one of those survives a real attack.
Modules cover phishing and email, passwords and MFA, data protection under GDPR and POPIA, remote work, social engineering defence, and incident reporting. Sessions run 60–90 minutes over video, tailored before delivery rather than read from a deck.
04Ethics
Testing people is not the same as tricking them.
Social engineering testing done carelessly damages trust and makes your security culture worse. These are the rules we work to, and they are not negotiable.
- Never punitive
- Results identify where training is needed, not who to discipline. If leadership wants a list of people to punish, we are the wrong supplier.
- No credentials captured
- Submitted passwords are never stored. The simulation records that a submission happened, never what was typed.
- Off-limits pretexts
- No fake redundancies, bonuses, medical results or bereavements. Cruelty is not rigour, and it poisons the programme.
- Reported as a win
- Reporting rate matters more than click rate. A workforce that reports quickly beats one that simply clicks less.
- Aggregate reporting
- Findings are reported by department and trend. Individual results stay between the person and the training that follows.
→Next step
Find out how your people really do.
A first campaign gives you an honest baseline — usually a more uncomfortable one than the platform you are using now has been reporting.
daniel@theosec.com · +27 63 484 1051