Email Phishing
Controlled messages, links, attachments, credential simulations, reporting behavior, repeat interactions, and training-focused observations.
Human Risk Assessment
TruSec designs controlled phishing, telephone, and approved physical scenarios to evaluate whether employees follow verification procedures when an attacker uses urgency, authority, familiarity, or technical pretexts.
Service Overview
Security awareness training is important, but organizations also need evidence of how personnel respond during realistic interactions.
A user may recognize a suspicious email but still disclose information during a convincing phone call, approve an MFA prompt, bypass a visitor procedure, or follow instructions from someone claiming to be IT support.
TruSec works with authorized engagement contacts to develop scenarios that reflect the organization’s environment, policies, terminology, and risk objectives. Safeguards, data handling, escalation, and employee protections are defined before testing begins.
Assessment Coverage
Each channel can be tested independently or combined into a coordinated campaign.
Controlled messages, links, attachments, credential simulations, reporting behavior, repeat interactions, and training-focused observations.
Pretexts involving IT support, security events, business requests, vendors, executives, or familiar operational topics.
Testing whether users disclose passwords, one-time codes, reset information, or approve unexpected authentication prompts.
Evaluation of callback procedures, identity verification, help-desk escalation, payment changes, and sensitive information requests.
Approved attempts involving visitor controls, tailgating, pretexting, restricted areas, or document exposure when included in scope.
Sanitized examples, annotated red flags, audience-specific observations, and practical recommendations for corrective awareness efforts.
How the Engagement Works
Select channels, targets, pretexts, success criteria, exclusions, data handling, and emergency contacts.
Build realistic but controlled content and infrastructure aligned to the organization’s environment.
Record user actions, verification behavior, escalation, reporting, and meaningful process failures.
Provide aggregate results, targeted observations, training recommendations, and a follow-up testing strategy.
Deliverables
Reporting emphasizes trends, control failures, and practical training priorities while handling individual results according to the agreed rules.
Common Questions
Yes. Combining channels can reveal whether a user who resists one approach is still vulnerable to a coordinated or more personal pretext. Email, telephone, and approved physical scenarios can also be tested independently when a narrower assessment is preferred.
Testing can simulate credential submission without retaining or using real passwords. Exact handling is defined in the rules of engagement and is designed to minimize the collection, storage, and exposure of sensitive information.
Typically, only authorized engagement contacts know in advance. The organization determines notification, employee-relations requirements, labor or legal considerations, and how individual results may be used.
Yes. Recommendations are tied to the behaviors and process failures observed during the exercise. TruSec can also provide sanitized examples, annotated red flags, role-specific observations, and a follow-up testing strategy to help measure improvement.
Targets are selected with authorized client contacts based on the engagement objectives. The sample may include a broad cross-section of employees or focus on departments, locations, roles, or personnel with elevated access and data-handling responsibilities.
Yes. Scenarios can reflect the organization’s vendors, terminology, workflows, technologies, and risk concerns. Pretexts may be tailored for executives, finance, human resources, clinical staff, customer service, information technology, or other approved groups.
Yes. Testing can evaluate identity verification, password-reset procedures, callback requirements, escalation, account recovery, MFA handling, and requests involving sensitive or operational information.
Reporting rules are agreed upon before testing. Results can be presented in aggregate or, when authorized, by individual, role, department, or location. Access to detailed results is limited to approved recipients, and reports emphasize corrective action rather than unnecessary employee exposure.
Yes. Executives, finance personnel, administrators, help-desk staff, and users with privileged access may be assessed through separate scenarios and success criteria that reflect their access, authority, and likely threat exposure.
Follow-up testing is most useful after corrective training and process improvements have had time to take effect, commonly at least three months later. Periodic testing can then use new pretexts, channels, departments, and request types to measure sustained improvement.
Related Services
Share the number of targets, preferred channels, business locations, risk scenarios, training objectives, and desired testing window.