Test the decision gate. Protect the people inside it.
The purpose is to measure whether a defined request, escalation or verification process holds—not to embarrass employees. Channels, target groups, pretexts, data capture, success criteria and stop conditions are approved before execution.
REQUEST → SCOPE → AUTHORIZE → KICKOFF → EXECUTE
Each boundary is tested independently, then examined as part of the complete path.
- 01REQUEST
- 02VERIFY
- 03ESCALATE
- 04DECIDE
- 05RECOVER
PROCESS EVIDENCE / PEOPLE PROTECTED
ASSESSMENT BOUNDARY
What is being assessed?
The engagement boundary is defined by systems, identities, workflows and restrictions—not only a list of URLs or assets.
- Phishing and spear-phishing scenarios
- Credential-harvesting simulations where explicitly authorized
- Selected verification and escalation processes
- Defined target groups or role cohorts
- Email, identity and reporting controls supporting the scenario
- Awareness or process gaps evidenced by the exercise
What Botnet tests.
Coverage follows reachable trust decisions and agreed risk, with destructive or disruptive actions excluded unless explicitly authorized.
Request
A defined action or disclosure aligned to the approved scenario.
Pretext control
Only narratives, identities and channels documented in the Rules of Engagement.
Verification
Whether the intended independent checks are practical and followed.
Escalation
How suspicious activity is reported and routed.
Technical gate
Email, identity or access controls included in the scenario.
Recovery
Notification, evidence minimization and closeout after the exercise.
How the work progresses.
- 01
Purpose
Define the control question and smallest useful target population.
- 02
Approve
Agree legal, HR, privacy, channel and evidence boundaries.
- 03
Prepare
Create controlled infrastructure, pretexts and emergency process.
- 04
Execute
Run only approved interactions within defined windows.
- 05
Protect
Minimize collected data and avoid individual blame.
- 06
Improve
Report process-level evidence and targeted recommendations.
EVIDENCE + ACTION
What the customer receives.
- Scenario and control-objective summary
- Aggregate outcome and process observations
- Anonymized/minimized evidence as agreed
- Verification and escalation gaps
- Recommended control and training changes
- Stakeholder readout and closeout record
Evidence over assumption.
01Control-focused, not employee-focused
02Explicit privacy and evidence minimization
03Scenario tied to a defined business process
04Closeout designed to improve verification and escalation
Before scoping.
Are individual employees named in the report?
The reporting model is agreed in advance. Reporting is designed to remain process-focused with personal data minimized.
Can credential harvesting be simulated?
Yes, only when explicitly authorized and supported by an approved handling plan. The exact capture and evidence boundaries are defined in the Rules of Engagement.
Does this include physical intrusion, USB drops or vishing?
No. Those techniques are not offered on this public service page.
Define the target, constraints and required evidence.
An assessment request starts a scoping conversation. It does not authorize testing. Work proceeds only after scope acceptance, executed authorization/SOW and kickoff.