Key Service Activities
Onsite test services include:
- Pre-engagement setup with client (includes project planning, scope, defining rules of engagement, information gathering)
- Spoof emailing (if applicable)
- Onsite testing for:
- Employee security and privacy policy awareness and adherence
- Proper disposal of sensitive data
- Access privileges
- Sensitive area security
- Device/system compromise
- Technical preventive and detective controls
- Violation reporting
- Present preliminary findings to client core team through exit interview
Remote test services include:
- Pre-engagement setup with silent (includes project planning, scope, defining rules of engagement, information gathering)
- Remote social engineering (dependent on the scope)
- Computer-based testing through email spoofing and phishing simulation
- Phone-based – pretext call testing (dependent on the scope)
Test Results
Test results (for both on-site and remote engagements) are provided in an extensive report containing:
- Project overview
- Social engineering test methodology
- Executive summary
- Business and technical risks and recommendations
- Details and exposure of vulnerabilities
- Recommendations and counter measures
- Appendix examples
Options
Options (for both on-site and remote engagements):
- On-demand generation of reports for audit, board and technical staff
- Training material provided in an extensive recorded ‘Flash’ module
- Automated learning management system and training management (includes access to security awareness training content)