Offensive security assessments

Phishing Assessment Methodology

A phishing assessment measures how an organisation's people, processes, and technical

Why it matters

A phishing assessment measures how an organisation's people, processes, and technical controls stand up to social-engineering attacks. The goal is to improve resilience, not to embarrass employees, so scope, consent, and care matter at every step.

How we test it

Our operators follow a structured checklist for this topic, adapted to your API surface and authentication model.

Testing approach

  • Explicit written authorization is mandatory, including approved targets, timing, and
  • Agree what is out of scope (e.g. credential capture vs. just click tracking, home
  • Handle any captured data securely and delete it after reporting.
  • Coordinate with the blue team / IT so a real incident is not confused with the test.
  • Reconnaissance (OSINT): identify the organisation's email format, public employees, technologies, and themes that make a believable pretext
  • Pretext design: craft a scenario aligned to the test goal (credential harvest, attachment execution, MFA fatigue, etc.)
  • Keep it realistic and ethical
  • Infrastructure setup: register a look-alike domain, configure mail authentication (SPF/DKIM/DMARC) to maximise deliverability, and stand up a landing page / payload host

What we look for

  • Explicit written authorization is mandatory, including approved targets, timing, and
  • Agree what is out of scope (e.g. credential capture vs. just click tracking, home
  • Handle any captured data securely and delete it after reporting.
  • Coordinate with the blue team / IT so a real incident is not confused with the test.
  • Reconnaissance (OSINT): identify the organisation's email format, public employees, technologies, and themes that make a believable pretext
  • Pretext design: craft a scenario aligned to the test goal (credential harvest, attachment execution, MFA fatigue, etc.)
  • Keep it realistic and ethical
  • Infrastructure setup: register a look-alike domain, configure mail authentication (SPF/DKIM/DMARC) to maximise deliverability, and stand up a landing page / payload host