Human Risk · Social Engineering Defense
Social engineering, not zero-days, is how most organizations are breached.
Attackers do not break modern device encryption. They bypass it by convincing an employee to hand over credentials, approve a push notification, or click a link. We assess how exposed your team is, and we close the gap.
The problem in numbers
Security budgets concentrate on technical controls. The data says the threat is human.
74%
of breaches involve a human element
4–10 hrs
attacker time to compromise one target
15 min
to deploy FIDO2 keys across a team
How the attacks actually work
Four techniques account for the majority of successful intrusions. None of them require exploiting software.
Phishing & Spear Phishing
Setup: 20–60 min
Impersonation of a trusted service — Microsoft, Google, your bank, your CEO. The victim types credentials into a cloned login page. The attacker replays the session cookie. Defense: FIDO2 hardware keys, which are cryptographically bound to the real domain and cannot be replayed.
SIM Swapping
2–6 hrs per target
The attacker calls the carrier with stolen personal data and ports the victim's number to a new SIM. SMS-based 2FA and password resets are then intercepted. Defense: Remove SMS as a second factor entirely. Move to TOTP apps or hardware tokens. Add a port-out PIN with the carrier.
Vishing (Voice Phishing)
15–45 min call
A caller claims to be IT, the fraud department, or a colleague. They create urgency and ask the victim to install remote access software or read out a one-time code. Defense: Policy that no credential or code is ever shared over an unsolicited call. Out-of-band verification for any IT request.
The attacker already has the password. They spam push notifications until the victim approves one out of frustration or confusion. Defense: Number matching, rate limiting on push attempts, and FIDO2 keys that require physical presence.
What we deliver
A human risk assessment that produces findings your security team can act on.
Phishing simulation
Realistic campaigns against your team using the same pretexts attackers use. We measure click rate, credential submission rate, and reporting rate — then deliver targeted training.
MFA hardening
We audit your current authentication stack and produce a migration plan from SMS and push to TOTP and FIDO2, prioritized by account sensitivity.
Incident response support
If an employee is already compromised, we guide containment: session revocation, credential rotation, evidence preservation, and coordination with legal and HR.
Awareness program
A training curriculum built around the specific techniques your team actually fails against, updated quarterly as attacker tradecraft evolves.
Engagement scope. A typical human risk assessment runs two to three weeks. Deliverables include a findings report mapped to the techniques above, a prioritized remediation roadmap, and a briefing for your security leadership. Pricing is on the pricing page.
Discuss an assessment
If you want to know how exposed your team actually is, we can tell you in a 30-minute call.