Skip to content
Braincap
← Consulting & Security

Social engineering & phishing simulation

Controlled phishing and social-engineering simulations, with your consent: we measure how prepared your team is and where training is needed. Aggregated data only.

What is a social-engineering test?

A social-engineering test simulates, with your written consent, the techniques attackers use to fool people: e-mail phishing, pretexting, sometimes phone calls (vishing). The goal isn’t to “catch” anyone, but to measure how prepared your team is and to see exactly where training is needed.

Most successful attacks start with a person, not a technical vulnerability — that’s why this test matters.

What we include

  • Simulated phishing campaign — realistic messages sent to employees, with management’s consent.
  • Measuring the results — the click rate, the data-entry rate and, just as important, the reporting rate of suspicious messages.
  • Optional: pretexting / vishing — phone or direct-interaction scenarios.
  • Awareness session after the campaign, built on the real results.

How it works

  1. Consent and objectives — we agree the scenarios, scope and rules, in writing.
  2. Campaign preparation — we build realistic messages, adapted to your context.
  3. Running the campaign — we send the simulations and collect the data.
  4. Reporting — aggregated results and recommendations.
  5. Training — an awareness session for the team.

What you get

  • A report with aggregated results — click and reporting rates, without exposing individual employees.
  • Training recommendations — based on what the campaign showed.
  • An awareness session for the team.

Ethics and confidentiality

The test is carried out only with the organisation’s written consent. Results are a learning tool, not a way to punish: we report aggregated data, not a “wall of shame”. The goal is a better-prepared team, not culprits.

Frequently asked questions

Is it legal and ethical? Yes — it runs with the organisation’s written consent and under clearly agreed rules.

Do you expose individual employees? No. We report only aggregated results; the objective is training, not punishment.

What do you measure? The click rate, the data-entry rate and the reporting rate of suspicious messages.

How much does it cost? We provide an estimate on request, based on scope.

Need this service?

Write to us or call directly. A person answers, not a form.