Social Engineering & Phishing Simulation

Phishing, vishing, smishing and physical engagements that test how your people, processes and technology hold up under real-world pressure. Built to teach, not to embarrass.

Last updated

What is a social engineering engagement?

A social engineering engagement is an authorised, controlled attack on the human layer of your security. The emails your staff open, the calls your help desk answers, the doors your visitors walk through. Ironbark Cyber runs the same pretexts a real adversary would, then turns the results into training and process fixes rather than a wall of shame.

What types of engagement do you run?

  • Phishing campaigns. Targeted email lures designed around your industry, your tooling and your specific risk scenarios, from broad awareness sweeps through to spear-phishing your highest-risk roles.
  • Vishing & smishing. Phone and SMS pretexts that test help-desk processes, MFA reset flows, and how staff respond when someone "from IT" calls in a panic.
  • Physical engagements. Tailgating, impersonation, lock-picking and access control bypasses to see how far a determined attacker can get past your front door.
  • Pretext development. Realistic, OSINT-driven pretexts that mirror what your real adversaries would actually try.
  • Red team blends. Social engineering combined with technical exploitation for a full-attack-chain assessment of detection and response.

How does the engagement run?

Rules of engagement come first: targets, channels, payload behaviour, escalation paths and what's strictly off limits. Once we go live, we keep your security team in the loop in real time so legitimate incidents don't get drowned out by simulated ones. As with every Ironbark Cyber engagement, the senior operator who scopes the work is the one who runs it.

Why teach instead of embarrass?

Because proving that humans can be fooled tells you nothing. They can, anyone can. The point is to give your people the muscle memory to recognise the next attempt, and to give your security team the data to harden the processes around them. The debrief builds skills; it doesn't name names.

What do we receive?

  • A clear, evidence-based report: what worked, what didn't, and where to invest next.
  • Campaign metrics in aggregate, click rates, credential submissions, escalations, without singling anyone out.
  • Process recommendations for the systems the pretexts actually stressed: help desk, MFA resets, physical access.
  • A debrief session for your team, focused on recognition skills rather than blame.

What does it cost?

Fixed-fee, quoted within one business day of a free scoping call. The price depends on channels, target count and whether the campaign blends into a broader red team.

FAQ

Frequently asked questions

How much does a social engineering engagement cost?

Social engineering engagements are fixed-fee, quoted within one business day of a free scoping call. The price depends on the channels in scope (email, phone, SMS, physical), the number of targets and whether the campaign blends into a broader red team. The quote never changes mid-engagement.

Will you name and shame the staff who click?

No. The point isn't to prove humans can be fooled. They can, anyone can. Ironbark Cyber reports results in aggregate, focuses the debrief on building recognition skills, and gives your security team the data to harden the processes around your people.

What is the difference between phishing, vishing and smishing?

Phishing is email-based social engineering, vishing uses phone calls, and smishing uses SMS. Real attackers mix all three, a text that primes the target for a call, or a call that "confirms" an email, so we test them the same way, against the processes they actually stress: help desks, MFA resets and urgent requests from "IT".

Can you run physical engagements?

Yes. Tailgating, impersonation, lock-picking and access control bypasses, under agreed rules of engagement with authorisation letters in hand. Physical testing shows how far a determined attacker gets past the front door, not just the firewall.

How do you avoid disrupting real security operations?

Rules of engagement are agreed up front, targets, channels, payload behaviour, escalation paths and what is strictly off limits. Once live, we keep your security team in the loop in real time so legitimate incidents don't get drowned out by simulated ones.

Contact

Talk to us

Tell us what you're trying to protect, secure or build. We'll come back with a plan.

Prefer to talk live? Book a call →

By submitting this form, you agree to our privacy policy.