PHISHING & SOCIAL ENGINEERING

CREST-Accredited Phishing Assessment and Social Engineering for UK Businesses

Phishing assessment goes beyond annual click-rate metrics. We deliver realistic adversary-mode phishing campaigns: AI-generated lures, MFA-fatigue testing, OAuth phishing, vishing, smishing, and physical pretext attacks. CREST methodology, sector-specific TTPs, executive-tier scope.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved provider
12
Phishing attack vectors
Free
Retest included
24h
Scope to active testing
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOne
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonCo-Founder, Cellori
WHY IT MATTERS
74%

of breaches involve a human element. Phishing assessment tests the layer your scanners can’t reach.

Click-rate metrics measure awareness. Adversary-mode phishing measures resilience.

Most “phishing assessments” send a templated email, count clicks, and produce a percentage. That’s awareness training, not security testing. It doesn’t reveal whether your MFA holds up against real OAuth-consent phishing, whether your SOC catches a vishing-driven help-desk handover, or whether a sector-targeted lure compromises your finance team.

Our phishing assessment runs adversary-mode campaigns: AI-generated lures based on current threat-actor TTPs, MFA-fatigue testing, OAuth-consent phishing for cloud account compromise, vishing (voice phishing) of help-desk and finance, smishing (SMS phishing) targeting executives, and where authorised, physical pretext attacks.

Reports satisfy ISO 27001 A.6.3 awareness-training requirements, FCA Operational Resilience scenario evidence, and provide CISO-ready findings on cultural and process gaps.

12 PHISHING ATTACK VECTORS

What We Test in Phishing Assessment

Multi-channel adversary mode. Modern TTPs. Sector-specific lure design.

01

Email Phishing

Targeted spear-phishing with sector-aware lures. Domain spoof / look-alike. Payload, credential harvest, or pretext-only.

02

OAuth Consent Phishing

Modern cloud account takeover via fraudulent OAuth consent. Bypasses MFA. Targets Microsoft 365 / Google Workspace.

03

MFA Fatigue

Repeated MFA push notifications until user accepts. Tests SOC alerting and user awareness of MFA bombing patterns.

04

Vishing (Voice)

Help-desk impersonation, finance-team payment-fraud calls, IT-team password-reset requests. Pretext, recorded if authorised.

05

Smishing (SMS)

Executive SMS phishing, mobile MFA reset attempts, banking-style mobile lures. Particularly effective against C-suite.

06

Physical Pretext

Office tailgating, USB drop, courier impersonation, RFID badge cloning, dropbox device deployment. Authorised in writing.

07

Whaling / BEC

Business Email Compromise targeting CFO, finance team, treasury. Wire-fraud lure design, supplier impersonation, M&A pretexts.

08

AI-Generated Lures

LLM-generated phishing lures matching real adversary writing style. Tests resilience against polished modern phishing not flagged by basic filters.

09

Domain Spoofing & Lookalike

Typosquat domain registration, IDN homoglyph attacks, look-alike Microsoft / Google portals, email-spoofing without DKIM/DMARC.

10

Adversary-in-the-Middle (AitM)

Evilginx-style AitM attacks against MFA. Captures session tokens. Bypasses TOTP / push MFA. Defeats by FIDO2 / hardware keys only.

11

Supply Chain Phishing

Pretexts simulating compromised suppliers, M&A counterparties, regulators. Tests cross-organisational trust assumptions.

12

SOC Detection Validation

Coordinates campaign with your SOC for blue-team measurement. SOC alerts, ticket queue, response time, communication-cascade quality.

FOUR-PHASE METHODOLOGY

Phishing Assessment: From Threat Profile to Cultural Insight

Sector-aware threat profiling. Multi-channel campaign delivery. SOC-coordinated for blue-team measurement.

01

Threat Profile

Sector-specific adversary profiling, target list approval, scope/depth/legal sign-off, white-team contact list, get-out-of-jail letter.

02

Lure Development

AI-aware lure design, pretext development, infrastructure setup (domains, mail servers, AitM proxies, voice numbers).

03

Campaign Execution

Multi-channel campaign delivery over agreed window. Real-time dashboard for white team. SOC-coordinated for detection metrics.

04

Report & Briefing

Click-rate, credential-capture rate, MFA-bypass rate, vishing-handover rate, SOC detection latency, executive briefing on cultural gaps.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a fixed Phishing Assessment quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonCo-Founder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

24h reply CREST tester Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Phishing Assessment Reports Mapped to Every Framework

Phishing assessment evidence accepted across compliance frameworks where social-engineering resilience is a control requirement.

ISO 27001 A.6.3

Awareness training and human-element control evidence. ISO 27001:2022 periodic awareness requirement.

SOC 2

Human-element and security-awareness Trust Services Criteria evidence.

PCI DSS

Security-awareness and anti-phishing control evidence.

FCA Operational Resilience

Social-engineering scenario evidence for regulated firms.

NHS DSPT

Social-engineering resilience evidence for the Data Security and Protection Toolkit.

Cyber Insurance

Phishing-resilience evidence underwriters accept.

PRICING

Transparent Phishing Assessment Pricing

All tiers include sector-specific threat profiling and SOC-coordinated delivery. Price varies by scope, channel breadth, and target population.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
Free retests, no time limit
Free rescheduling
No cancellation fees
24-hour scope to active testing
Live findings to client portal
Executive + technical report
60-min walkthrough call
Letter of attestation
EMAIL CAMPAIGN
£3,000–£6,000
Depends on app complexity

Single-channel email phishing, up to 500 targets, sector-aware lures, basic SOC coordination. Typically 2-3 week delivery.

Get a fixed quote
ENTERPRISE / RED-TEAM ADJUNCT
£15,000+
Depends on app complexity

All channels including physical pretext, full BEC plus supply-chain campaigns.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Actually Get

What distinguishes our service from automated scans and box-tick competitors.

What You Get From Phishing Assessment

Multi-channel adversary-mode campaign, sector-aware lure design, SOC detection metrics, cultural-gap analysis, executive briefing.

AI-Aware Lure Design

Modern phishing uses AI-generated content. Our lures match real-world adversary quality, not 2015-era Nigerian-prince templates.

OAuth + AitM Testing

MFA bypass via OAuth consent plus Evilginx AitM. Tests modern attack patterns most awareness platforms cannot reproduce.

SOC-Coordinated Metrics

SOC detection latency, ticket-queue triage quality, communication cascade: measured alongside user-side metrics.

UK CREST + IASME + ISO 27001 + ISO 9001

Independently accredited. UK-based phishing operators. Reports accepted by FCA, NCSC, ISO auditors, and cyber insurers.

Cultural-Gap Analysis

Beyond click-rate. A CISO-ready read on the cultural and process gaps the campaign exposed, with an executive briefing.

FAQ

Frequently Asked

What is a phishing assessment?

A phishing assessment is a controlled simulation of phishing and social-engineering attacks against your organisation. Modern assessments go beyond email click-rate metrics to include vishing, smishing, OAuth consent phishing, MFA fatigue, and physical pretext attacks, measuring both user awareness and SOC detection.

How is your assessment different from a phishing-awareness platform?

Awareness platforms (KnowBe4, Proofpoint Security Awareness, etc.) deliver continuous low-fidelity phishing for training. Our assessment is adversary-mode: high-fidelity, sector-aware, multi-channel campaigns matching real threat-actor tradecraft. Use both: awareness platforms for ongoing training, our assessment for periodic resilience testing.

How long does a phishing assessment take?

Email-only campaign: 2-3 weeks (1 week setup, 1-2 weeks campaign). Multi-channel campaign: 3-5 weeks. Enterprise / red-team-adjunct campaign: 6-8 weeks including physical pretext component.

How much does phishing assessment cost in the UK?

Email-only £3,000-£6,000. Multi-channel (most commonly commissioned) £6,000-£15,000. Enterprise / red-team adjunct £15,000+. UK day rates for CREST + social-engineering specialists are £1,100–£1,400 per day.

Do you test MFA bypass via OAuth phishing?

Yes. OAuth consent phishing is the modern cloud account takeover vector: bypasses MFA entirely because the user grants legitimate-looking app permissions. Particularly effective against Microsoft 365 and Google Workspace tenants. Our assessment includes this if requested.

Do you test against MFA fatigue?

Yes. MFA-fatigue (push-notification spamming until the user accepts) is a real-world TTP behind the 2022 Uber breach and many subsequent incidents. We test MFA-bombing patterns, conditional-access policy effectiveness, and SOC detection of unusual MFA-prompt volume.

Do you do vishing (voice phishing)?

Yes. Vishing is particularly effective against help-desks, finance teams, and executive assistants. We deliver vishing as part of multi-channel campaigns: pretext development, recorded calls (where authorised), and post-campaign analysis of phone-handling resilience.

Do you do physical pretext attacks?

Yes, with extensive written authorisation. Physical pretexts include tailgating, USB drops, courier impersonation, RFID badge cloning, and dropbox-device deployment. Always paired with a “get-out-of-jail” letter for operators and pre-approved time windows.

Will phishing assessment damage employee trust?

No, when delivered well. We coordinate closely with HR and internal-comms teams. Post-assessment communications focus on collective improvement, not individual blame. Many of our clients see improved employee engagement on security topics after assessment.

Will assessments trigger our SOC?

Yes, by design. We coordinate with your SOC team to measure detection latency, triage quality, and communication cascade. SOC blue-team metrics are as important as user-side click-rate metrics. Some clients run “blind” SOC scenarios where the SOC team isn’t pre-warned.

Are your operators UK-based?

Yes. All phishing operators are UK-based. SC-cleared operators are available for public-sector and regulated-financial engagements where vetting is required.

Do you sign NDAs?

Yes. Standard NDA before any threat-profile or target-list discussion. We operate under a project-specific master agreement that includes target-list IP protection, post-engagement data destruction, and white-team confidentiality.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed Phishing Assessment quote in 24 hours

A CREST-certified social-engineering specialist will contact you within one business day with a fixed price, a realistic timeline, and the named consultant. No sales pipeline.