Social engineering

Social engineering testing: will your team click on a phishing email?

Controlled phishing campaigns, vishing, smishing, BEC and physical social engineering tests realistically measure the resilience of your people and processes. Phishing simulation for companies from PLN 6,000 net, with a report, metrics and post-campaign training. Compliant with NIS2, DORA, ISO 27001 and KNF requirements.

  • 72%Report rate after the programme (up from 8%)
  • up to 80%Click rate reduction after a 12-month programme
  • 2–3 weeksFrom kick-off to the campaign report
  • 9Vectors: from email to walking into the office
vipentest · phishing campaign (sample)LIVE
  • FFinance DeptCorrective invoice 09/2026 — urgentclick
  • IIT SupportVerify your SSO account by tomorrowclick
  • AAnna K.FW: Corrective invoice — is this phishing?reported
  • BBoardAnnual bonuses — listclick
  • MMark Z.RE: Account verification — reporting to ITreported
64%resilience
kliknięciezgłoszenie
  • 500sent
  • 27%clicked
  • 11 minto first report
Attack vectors

Every way attackers try to deceive your employees: phishing, vishing, smishing, BEC, QR codes

From classic email phishing to deepfake vishing and quishing: VIPentest simulates every vector used by real-world adversaries today. Every scenario maps to a specific MITRE ATT&CK technique.

Mass Phishing (email)

Realistic email campaigns to the entire organisation: fake M365, Google Workspace, banking, courier and HR notifications. We measure click rate, submit rate and time-to-report.

MITRE T1566.002

Spear Phishing and Whaling

Targeted attacks against the CFO, CEO, finance, HR and administrators. Full OSINT, personalisation based on LinkedIn, calendar and recent media activity.

MITRE T1566.003

Vishing (telephone)

Simulated calls to helpdesk, reception, finance and sales. Vendor, auditor and IT staff pretexts. Also AI voice cloning for deepfake attacks against executives.

MITRE T1566.004

Smishing and Messengers

SMS, WhatsApp, Signal, Microsoft Teams. Fake bank, courier and delivery notifications, plus MFA verification requests, with rotating numbers and URL shorteners.

MITRE T1660

Business Email Compromise

CEO Fraud, fake invoice, change-of-bank-account. Forced wire transfers or payment data manipulation. Tests of Four Eyes procedures and callback approval in finance.

MITRE T1534

Physical Social Engineering

Tailgating, USB drop, impersonating the cleaning crew, a courier or an auditor. Tests of badge policies, visitor escorting and physical access controls.

MITRE T1200

Quishing (QR codes)

Fake QR codes placed in offices, car parks, printed correspondence and emails. Bypasses most secure email gateways and URL scanners.

MITRE T1656

MFA Fatigue and AiTM

Push bombing, Adversary-in-the-Middle with Evilginx2, session cookie theft. Demonstrates that MFA alone is insufficient without phishing-resistant FIDO2/WebAuthn.

MITRE T1621

Pretexting

Construction of a credible scenario and persona. Calls “from the central bank”, emails from a “new cloud vendor”, messages from a “colleague in another branch” with urgent requests.

MITRE T1598
Service scope

What exactly we test in a social engineering engagement

Full scope delivered according to the PTES Social Engineering methodology, mapped to MITRE ATT&CK techniques in Initial Access (TA0001) and Reconnaissance (TA0043). Each module can be run individually or as part of a coherent blended campaign. A phishing simulation tests your people and complements penetration testing services for applications and infrastructure; organisations with a SOC can run the same scenarios inside red teaming with a social engineering component.

Email phishing campaign — mass and targeted

Controlled, realistic email campaigns sent from dedicated VIPentest infrastructure. Brand cloning of Microsoft 365, Google Workspace, major UK and EU banks, couriers (DHL, UPS, FedEx, InPost) and internal client applications. Spam filter bypass with full legality and audit trail.

  • Login portal cloning: M365, Google, Okta, Azure AD, OneLogin, ADFS, client intranet: pixel-perfect copies with valid TLS certificates
  • SEG bypass: Verification of real-world performance of Microsoft Defender, Proofpoint, Mimecast, Barracuda. Identification of which phish types pass through
  • Full funnel tracking: Open rate, click rate, submit rate, MFA bypass rate, attachment executions, time-to-first-click, time-to-first-report
  • Real payloads: Macro documents in sandbox, OneNote / ISO / HTML smuggling, AiTM via Evilginx2 (with authorisation)
  • Multilingual: English (primary), Polish, German, Ukrainian, for multicultural organisations
  • Realistic branding: Typosquatted domains, IDN homograph, dedicated Let’s Encrypt certificates with OCSP stapling

Executive spear phishing (Whaling)

Specialised campaigns against CEOs, CFOs, board members, CISOs and personnel with critical access. APT-style adversary simulation: days of reconnaissance, hours of research per target, a precise pretext. Whaling typically has a 5 to 10 times higher success rate than mass phishing, requiring a separate training programme for C-level staff.

  • Deep OSINT: LinkedIn, X, conference calendars, podcasts, expert panels, financial reports, data breaches
  • Pretext construction: Investor, regulator, industry journalist, headhunter, event organiser, strategic client
  • Blended vector: LinkedIn message plus email plus phone plus online meeting: multi-week trust build-up
  • Deepfake voice samples: Model trained on CEO public appearances and CFO vishing simulation (with consent)
  • Calendar phishing: Fake Google Calendar / Outlook invitations with embedded links
  • Executive coaching: Individual 1-to-1 debriefing with every board member who failed

Vishing and telephone social engineering

Simulated phone attacks targeting the IT helpdesk, reception, finance departments, sales and customer hotlines. The most commonly neglected vector, despite helpdesk phone calls being the classic path to admin account password resets (Twitter 2020, MGM Resorts 2023, Cisco 2022).

  • Helpdesk password reset: Attempts to force the agent into resetting admin / VIP account passwords under an urgent pretext
  • MFA enrolment bypass: Forcing the addition of a “new” 2FA device to the victim’s account
  • Information harvest: Subtle extraction of information from reception, sales, finance: organisational schema, structure, contacts
  • CallerID spoofing: Displaying internal organisation numbers or vendor numbers (legally, with consent)
  • AI Voice Cloning: Simulated deepfake CFO/CEO demanding an urgent wire transfer (separate module, full legal consent)
  • Audit trail: Every call recorded (with consent of the campaign participant, the administrator), full transcript in the report

Smishing, WhatsApp, Signal, and Microsoft Teams

Messengers are far less protected today than email. Smishing can have a 5 to 10 times higher click rate than email phishing because the victim has no access to headers, hover previews or sandboxes. Attackers are massively migrating to SMS, WhatsApp and Teams.

  • SMS campaigns: SMS gateways with rotating numbers (PL, UK, DE), URL shorteners, geo-fenced delivery
  • WhatsApp Business: Verified business accounts with vendor/bank profiles, multimedia as bait
  • Signal and Telegram: 1-to-1 phishing with a fake recruiter, external project manager, business partner
  • Microsoft Teams External: Using accounts from another tenant to bypass filters (Storm-0324, Storm-0539 actors)
  • Push notification spam: Forcing erroneous MFA approval by flooding the employee with notifications
  • Dynamic URL rotation: Links that regenerate after scanner detection, content cloaking per region/UA

Business Email Compromise and CEO Fraud

BEC is the costliest cybercrime category in 2024-2026, with an average loss of 137,000 USD per incident (FBI IC3). Attackers impersonate the CEO, CFO, a vendor or a partner to extract a wire transfer or change account details. We test both the technical vector (spoofing) and the procedural one (Four Eyes, callback).

  • CEO Fraud: Email/SMS from the “CEO” during their travel: an urgent request for a “confidential transaction” transfer
  • Change of bank account: Fake vendor email about a change in the invoice payment account
  • Fake invoice: Sending a fraudulent invoice during a known billing period
  • Payroll diversion: “Employee” request to HR to change the salary payment account number
  • Conversation hijacking: Injection of a message into an existing conversation thread with a vendor (after prior compromise)
  • Procedure audit: Verification of Four Eyes, callback approval, verbal verification for amounts over the threshold

Physical social engineering — tailgating, USB drop, on-site pretexting

Physical presence at client premises is often the fastest path to data exfiltration. We test all layers of physical security: from reception through badges and visitor escorting to clean desk policies and physical access to server rooms.

  • Tailgating: Attempting to enter restricted zones behind an employee without a badge: pretext “forgot my card”, “I’m from service”
  • USB drop: Leaving branded USB drives (with tracked HTA / LNK documents) in car parks, reception, kitchens
  • On-site pretexting: Impersonating the cleaning crew, a courier, an ISO auditor, an air conditioning technician
  • Shoulder surfing: Attempts to observe passwords and screens with sensitive data in open spaces, cafes, airports
  • Clean desk audit: Verification that office spaces don’t leave passwords on sticky notes, PII documents or keys
  • Badge access bypass: RFID card cloning at 125 kHz / 13.56 MHz, NFC tests, basic lockpicking

Quishing, ClickFix, FileFix, and new 2025-2026 vectors

The threat landscape evolves every quarter. VIPentest regularly updates its scenario portfolio with the latest techniques observed in real attacks on clients across the EU and US. In 2025-2026, new vectors dominate that traditional training fails to address.

  • Quishing: QR codes in printed correspondence, car parks, emails: bypass of SEG and URL scanners
  • ClickFix / FileFix: Paste-to-run social engineering: a “press Win+R and paste” message on a fake website
  • Browser-in-the-Browser (BitB): Fake SSO windows rendered in an iframe inside a real website
  • Callback Phishing (TOAD): Email without links requesting a call to a call centre: combines email with vishing
  • AiTM phishing kits: Evilginx2, Tycoon 2FA, Mamba 2FA: real demo of MFA bypass and cookie theft
  • Deepfake video: Teams/Zoom meetings with a deepfake CFO/CEO (Arup Group 2024 case: 25M USD loss)

Security Awareness Programme — post-campaign training

The campaign alone is only a measurement: without a training programme, the click rate returns to baseline within 4-6 weeks. VIPentest delivers a comprehensive, continuous security awareness training for employees aligned with ISO/IEC 27001 Annex A.6.3, NIS2 and DORA requirements.

  • Just-in-time training: An employee who clicked lands within seconds on a 90-second microlearning analysing that specific scenario
  • Quarterly microlearning: 5-7 minute courses in EN/PL distributed via email, intranet, Microsoft Viva Learning, SAP Litmos
  • Role-based training: Separate tracks for the board, finance, HR, helpdesk, developers, sales
  • Gamification: Anonymous departmental leaderboards, badges for correct reports, quarterly rewards
  • Executive sessions: Dedicated workshops for the board: deepfake, BEC, OSINT on their own persona
  • Progress dashboard: Real-time metrics for the CISO, risk map per department, 12-month trend, export to compliance reports
Process

How the phishing campaign runs, step by step

A six-stage process aligned with PTES Social Engineering. Every stage ends with a checkpoint with the client’s designated person: full control, no surprises.

  1. 01
    Day 1-3

    Scoping and Rules of Engagement

    Scoping workshop with the CISO and business sponsors. We agree campaign objectives, permitted vectors (email/vishing/smishing/physical), exclusion lists (sick employees, pregnant staff, those on leave, sensitive departments), escalation channels and an emergency contact. Signing of SoW, NDA and Letter of Authorisation.

    ScopingRoE
  2. 02
    Day 4-7

    OSINT and Reconnaissance

    Full open-source reconnaissance: LinkedIn, corporate site, data breaches (Have I Been Pwned, BreachForums), email address formats, DNS records, deployed technologies (SPF/DKIM/DMARC, M365 vs Google, EDR), media activity of leadership, recent conferences, organisational structure. This forms the foundation for realistic pretexts.

    OSINTRecon
  3. 03
    Day 8-10

    Scenario design

    We construct 3-5 realistic pretexts adapted to the organisation’s context: cloud vendor, tax office, courier, business partner, IT helpdesk. We create landing pages, clone brands, purchase dedicated domains (typosquatted), and configure infrastructure with proper TLS, SPF and DMARC for the attack domains.

    ScenariosLanding pages
  4. 04
    Day 11-17

    Launch and monitoring

    Delivery in windows matched to the time zone and rhythm of the organisation, typically Tuesday through Thursday, 9:30 and 14:00. A real-time dashboard tracks opens, clicks, submitted credentials, attachment executions and time-to-report. Full readiness to immediately stop the campaign if an unforeseen situation arises.

    DeliveryMonitoring
  5. 05
    Day 18-20

    Controlled escalation

    Within the agreed scope, we use captured credentials to log into OWA, M365 and VPN. Verification of MFA bypass via AiTM, exfiltration of sample files from OneDrive/SharePoint, lateral movement attempts in the test environment. All under active client monitoring with a full audit trail.

    EscalationAiTM
  6. 06
    Day 21+

    Report, debriefing, training

    We deliver an Executive Summary with metrics, a results map per department (anonymous), a detailed scenario walkthrough with screenshots, technical recommendations (DMARC, MFA, SEG hardening, policies), a live debriefing with the board, and launch just-in-time training for employees who failed. After 90 days: an optional control campaign at a 30 percent discount.

    ReportDebriefing
Regulatory compliance

Social engineering testing required by NIS2, DORA and ISO 27001

Security awareness programmes and phishing resilience tests are today mandatory or strongly recommended by key regulations applicable in Poland and the European Union. If you need to check your wider obligations, start with a NIS2 and DORA compliance audit.

NIS2

EU Directive 2022/2555: mandatory security awareness training and testing for essential and important entities. PL implementation by 17.10.2024.

DORA

EU Regulation 2022/2554. For the financial sector: resilience testing under TLPT (Threat-Led Penetration Testing). Effective from 17.01.2025.

ISO/IEC 27001:2022

Annex A.6.3: requirement for an information security awareness, education and training programme. Applies to all certified organisations.

KNF Rec. D

Polish Financial Supervision Authority Recommendation D for banks: regular employee security awareness testing (minimum annually, more often recommended).

PCI DSS 4.0

Requirement 12.6: awareness programmes for all employees with access to cardholder data. Annual frequency.

GDPR

Article 32: adequate technical and organisational measures. Awareness programmes are one of the fundamental organisational measures.

HIPAA

Security Rule § 164.308(a)(5): Security Awareness and Training as an administrative safeguard for healthcare data in the US.

Cyber Insurance

Most cyber policies today require annual phishing campaigns and awareness programmes as a precondition of coverage.

Pricing

Social engineering testing pricing

The price depends on the number of employees, the number of scenarios and the channels used. Below are indicative net price ranges. We give an exact quote after a free scoping call.

CampaignScopeNet price
Email phishingup to 100 employees, 1 scenario, report with metricsfrom PLN 6,000
Multi-channelemail + vishing + smishing + QR codes, up to 1,000 peoplePLN 16,000–30,000
Physicalentering the office, tailgating, dropped USB mediaindividual quote

The ranges apply to typical scopes. Larger organisations, multiple locations or languages, and continuous 12-month programmes (quarterly campaigns, microlearning, dashboard) are quoted individually. All prices are net amounts in PLN. Included in the price: full OSINT, dedicated infrastructure, a report with metrics and recommendations in EN/PL, board debriefing, post-campaign training material for employees, 30 days of support, and results in the vulnerability management platform alongside the results of technical tests.

Results

What we measure and what you get in the report

A campaign without numbers is only an anecdote. Every report shows where the organisation is resilient, where it is not, and what to do about it.

Click rate and submit rate

How many people clicked the link and how many entered data on the landing page, broken down by department and location. This shows where training is most urgent.

Time to first report

How many minutes passed before someone reported the suspicious message to IT. This is the most important indicator: a company with a reporting reflex wins even at a high click rate.

Comparison with the benchmark

Your organisation’s result against other campaigns we have run in similar industries and company sizes, so you know whether the number is good or a red flag.

Training and technical recommendations

What to tell employees and what to set in your systems: email filters, DMARC, MFA, the reporting procedure. The report is ready to show to a NIS2 or ISO 27001 auditor.

Post-campaign training material

A short piece for employees showing what the campaign looked like and how it could have been recognised. The best moment to learn is the day after the test.

Results alongside technical tests

Campaign results go into the VIPentest vulnerability management platform next to the results of technical tests, so that human and technical risk sit in a single view.

Who it is for

Who social engineering testing is for

A phishing simulation for companies is ordered by organisations that process customer data, are subject to regulation, or want to build the reflex of reporting suspicious messages. Most often we work with:

Banks, fintech and financial institutions

Entities under DORA and KNF supervision: regular employee awareness testing, BEC and CEO Fraud simulations in finance departments, and whaling of the executive team. See phishing resilience testing for banks and fintech.

Software houses and SaaS

Technical teams tend to be confident about phishing: we test developers, DevOps and helpdesk, who have access to repositories, the cloud and administrative accounts.

E-commerce and retail

Shops and platforms holding card data and customer accounts: phishing campaigns aligned with PCI DSS, tests of customer service teams and payment-data change procedures.

Healthcare and public sector

Facilities and offices with sensitive data: tests of registration, reception and administration staff, plus physical social engineering inside buildings.

Essential and important entities under NIS2

Energy, transport, manufacturing, public administration and their suppliers: awareness training and phishing tests as part of the risk management required by NIS2.

Companies facing an audit or a continuous programme

Organisations preparing for ISO 27001 certification or a NIS2 audit that need proof of testing, and those building a security culture through quarterly campaigns and security awareness training for employees.

FAQ

Frequently asked questions about social engineering testing

Answers to the key questions we receive from CISOs, IT directors and executive boards considering a social engineering testing programme.

How much does a social engineering test and phishing campaign cost?

An email phishing campaign for up to 100 employees with one scenario and a report with metrics costs from PLN 6,000 net. A campaign for up to 500 employees with 2–3 scenarios and a landing page is PLN 9,999–16,000, and a multi-channel campaign (email, vishing, smishing, QR codes) for up to 1,000 people is PLN 16,000–30,000. Physical tests are quoted individually. Every quote includes full OSINT, dedicated infrastructure, a report in EN/PL, a board debriefing, post-campaign training material and results in the vulnerability management platform. We give an exact quote after a free scoping call.

How long does a phishing campaign take and how many people can be tested?

A standard one-off phishing campaign runs 2 to 3 weeks from kick-off to the final report. Week 1: scoping, OSINT, scenario design and infrastructure setup. Week 2: delivery and monitoring. Week 3: analysis, reporting, debriefing and training. The number of employees has minimal impact on the timeline: we test teams from 20 people (small software houses) to over 10,000 (banking groups). The recommended model is a continuous programme with quarterly campaigns and microlearning, which lets you measure the resilience trend, from a 25–35 percent click rate at the start to under 5 percent after four cycles.

Are social engineering tests legal and how do you protect employees?

Yes. Social engineering tests are fully legal when conducted by an authorised firm with written consent (Rules of Engagement). Before every campaign we sign an SoW, NDA and Letter of Authorisation defining the permitted vectors, exclusion lists (sick employees, pregnant staff, sensitive departments), escalation channels and stop procedures. We apply the “no naming and shaming” principle: reports show aggregate statistics and never name individuals in board-facing deliverables. Individual results are used solely to direct employees to training. Testing complies with GDPR (legitimate interest of the controller, Article 6(1)(f)), the Polish Labour Code and employer internal policies.

Which regulations require social engineering testing?

Social engineering tests are mandatory or strongly recommended by numerous regulations. NIS2 (EU Directive 2022/2555) requires awareness training for essential and important entities. DORA (EU Regulation 2022/2554) covers the financial sector and resilience testing under TLPT. KNF Recommendation D requires regular awareness testing in banks. ISO/IEC 27001:2022 (Annex A.6.3) requires an awareness programme, PCI DSS 4.0 (req. 12.6) requires awareness programmes for staff with access to cardholder data, and GDPR (Article 32) requires adequate organisational measures. Many cyber insurance policies also require annual phishing campaigns.

What metrics are included in a phishing campaign report?

The report contains a full set of operational and strategic metrics: click rate, submit rate, attachment open rate, report rate (a key maturity indicator), time-to-first-click, time-to-first-report, results broken down by department, location and role, the effectiveness of technical defences (SPF/DKIM/DMARC, Safe Links, Defender), MFA bypass success rate, and an Executive Summary with business risk and a 12-month awareness programme roadmap. Reports are delivered in English and Polish, in both executive and technical versions.

Is a 30 percent click rate high? What are the industry benchmarks?

The global average click rate for organisations without prior training is 27 to 34 percent (KnowBe4 2024, Proofpoint State of the Phish 2024). After the first year of a programme it drops to 13 to 18 percent, after the second to 6 to 10 percent, after the third to under 5 percent. In banks, fintech and technology, mature organisations reach 2 to 4 percent. More important than click rate is the report rate, the percentage of employees who actively reported the phishing attempt (target: over 70 percent). Spear phishing always produces a higher click rate, and this is not a programme failure but the nature of a specialised attack.

Do your tests cover AI deepfake, AI vishing, and MFA fatigue?

Yes. VIPentest updates its scenario portfolio in line with the current threat landscape. In 2026 the standard scope includes AI voice cloning and deepfake vishing (cloning of a CEO/CFO voice), MFA fatigue and push bombing, Adversary-in-the-Middle with session cookie theft, quishing (QR codes in offices, car parks and emails), callback phishing (TOAD), Microsoft Teams external phishing, Browser-in-the-Browser, and ClickFix / FileFix paste-to-run scenarios. Each vector can be run separately or as part of a blended campaign.

Will the click rate drop after the first campaign?

A single campaign without a training programme delivers a marginal, short-lived drop in click rate (the “wow” effect fades after 4–6 weeks). Sustained improvement requires a continuous programme: quarterly campaigns with increasing difficulty, microlearning, educational campaigns between tests, and security-culture support from leadership. VIPentest data from 12-month programmes shows an average click rate reduction of 65–80 percent, report rate growth from 8 percent to 72 percent, and time-to-report falling from 47 minutes to 4 minutes. The highest effectiveness comes from just-in-time training, which is 3–4 times more effective than a single annual compliance training.

What is social engineering testing and how does it differ from technical penetration testing?

Social engineering testing involves controlled simulations of attacks that exploit psychological manipulation rather than technical vulnerabilities. Unlike application or infrastructure penetration tests, the goal is not to exploit code but to verify the resilience of people and processes: whether an employee clicks a suspicious link, discloses a password over the phone, or lets a stranger into a restricted zone. According to the Verizon DBIR 2024 report, over 68 percent of security breaches begin with human compromise. A social engineering test delivers real metrics on click-through rates, incident reporting time and the maturity of your security awareness programme.

What social engineering vectors does VIPentest offer?

VIPentest delivers campaigns across the full spectrum: email phishing (mass and targeted), spear phishing and whaling, vishing (telephone social engineering), smishing (SMS and messengers), BEC and CEO Fraud, pretexting and physical social engineering (tailgating, USB drop), quishing (QR codes) and watering hole attacks. Each vector can be deployed individually or as part of a multi-channel blended campaign, and the portfolio is refreshed with new techniques such as AI voice cloning, MFA fatigue and callback phishing.

What tools and platforms do you use?

We use a mix of professional and proprietary tools tailored to campaign scale, including GoPhish, Evilginx2 and King Phisher (fully controlled, used only with authorisation), proprietary templates, dedicated infrastructure and typosquatted domains. For vishing we use VoIP with legal CallerID spoofing and Twilio; for smishing, SMS gateways with rotating numbers. Login portals are cloned with the Social-Engineer Toolkit (SET), HTTrack and our own templates for Microsoft 365, Google Workspace and Polish banks. Every technique is deployed strictly within the signed Rules of Engagement.

How do we technically protect the organisation against phishing?

Phishing defence is a multi-layered strategy. Email authentication: SPF, DKIM 2048-bit, DMARC set to reject, BIMI. Secure email gateway: Microsoft Defender for Office 365, Proofpoint, Mimecast. Endpoint: EDR (CrowdStrike, SentinelOne, Defender) and DNS filtering. Identity: phishing-resistant MFA (FIDO2/WebAuthn/passkeys), Conditional Access and blocking of legacy authentication. People: an awareness programme with quarterly campaigns, microlearning and a Report Phish button. Process: callback approval for payment-data changes, Four Eyes and a phishing incident-response playbook. The full architecture aligns with MITRE D3FEND and NIST CSF 2.0.

Ready to test your team’s resilience?

Get in touch and receive a free scoping consultation. Our experts will help you design the optimal phishing campaign and security awareness programme scope for your organisation.

  1. Enquiry confirmedWe reply within 24 h on business days and ask about the scope.
  2. Scoping call under NDAWe agree on goals, environment, dates and access.
  3. Quote and test planUsually the same day after the call. No commitment.
  • Report with metrics in EN/PL
  • Post-campaign training included
We reply within 24 h

Write to us: free quote and scoping consultation

Briefly describe who and how you want to test. We reply within one business day.

    I consent to the processing of my personal data by VIPentest sp. z o.o. in order to respond to my enquiry. Details in the Privacy Policy.

    No commitment. NDA before any scoping call.

    Social engineering testing · from PLN 6,000 netGet a quote