Services / Vishing simulation
Your firewall will not answer the phone.
We call your people using pretexts built from real reconnaissance, aimed at the paths attackers actually walk: the help desk, the reset request, the approval prompt. Then we tell you which procedure was missing, not which person failed.
Every pretext is approved by you in writing before a single call is placed.
What we test
The reset path first. It is where the real ones go.
The breaches that made headlines this year did not defeat multifactor authentication. They called someone and asked for it. So we start where they start.
Primary targets
- Password reset and MFA re-enrollment, target number one
- Whether a one-time code gets read aloud to a confident stranger
- Whether an unrequested push notification gets approved
- Whether a remote access session gets set up on request
- Whether account details get confirmed to an unverified caller
Pretext families
- Internal IT support, using your own naming conventions
- Vendor support, generic role only, never a named individual
- New employee needing access before a deadline
- Executive urgency, with the executive's consent on file
- Follow-up call after a phishing email, when run as a paired campaign
Departments we point it at
- Help desk and internal IT
- Front office and reception
- Accounts payable and finance
- Anyone with administrative rights in a core system
- Sales and service floors where phone contact is constant
What we measure
- Compromise rate by department, never by name
- Time to compromise, from hello to code
- Report rate, and how long reporting took
- Whether anyone verified through a channel your side initiated
- Whether a second attempt succeeded after the first was refused
How a campaign runs
You approve every word before we dial.
Authorization and stop contact
Signed rules of engagement naming the scope, the calling window, the departments in play, and one person who can end the campaign with a single call.
Pretext build and approval
We write each scenario as a script and send it for sign-off. Anything you veto does not run. If you want a pretext softened, we soften it.
Calibration
One call to a designated plant on your side. Confirms audio, confirms what your staff see on the display, confirms our scoring before anything real happens.
Live calling
Human callers, defined pace, live logging. No autodialers, no synthetic voices impersonating real people. If a call goes somewhere it should not, we end it ourselves and tell you why.
Readout, procedure, retest
A live debrief, a written verification standard your team can adopt the same week, and a retest once it is in place so the improvement is documented rather than assumed.
Limits
Deception is the method. It is not the ethic.
You are authorizing us to lie to your staff. That only works if the limits are written down.
No real people, ever
No government agencies, no law enforcement, no bank you use, no named individual at a real vendor. Generic roles only. Third parties do not get dragged into your test.
No recording by default
Consent laws differ by state and your employee has not consented to anything. We score from live notes and call logs. If you want recordings, it goes in the agreement and your counsel approves it first.
No voice cloning of your executives
We can demonstrate the threat with a consenting executive as a training exercise. We will not run it live against your staff. The liability is not worth the lesson.
Results are aggregate
Rates by department and the procedural gap behind each one. Our contract bars results from being the sole basis for discipline, because a test that gets someone fired teaches everyone else to stay quiet.
Refusing is a pass
Being firm, unhelpful, or blunt with our caller is the correct outcome. We score the procedure, not the personality.
Customers are out of scope
We call employees at business numbers during business hours. We do not call customers, personal phones, or anyone outside the authorized roster.
Common questions
Before you scope it.
Is this legal?
Yes, when it is authorized in writing by someone with authority to consent for the organization, and when it stays inside the limits above. That authorization is the entire foundation of the engagement, which is why we will not start without it and why we ask for an owner or officer signature rather than an IT manager's.
Will you tell us who failed?
No, and you should not want us to. You get department-level results and the exact procedural gap each successful call exploited. If an individual needs coaching, your leadership handles that from the pattern, not from our list.
What if someone reports the call to the police?
That is a good outcome for your security posture and a planned-for outcome in our process. Your stop contact is notified immediately, our callers carry authorization documentation, and we brief a designated contact before the campaign so it can be resolved in minutes.
How many calls are in a typical engagement?
Twenty to fifty for a targeted assessment, concentrated on the roles that matter. Volume is not the point. A hundred calls to a sales floor tells you less than fifteen well-built calls to the people who can reset a password.
Do we need the OSINT engagement first?
Not required, but it changes the quality substantially. Without reconnaissance we are calling with generic pretexts. With it we are calling with your vendor's name, your help desk's nickname, and a real deadline, which is what an actual attacker would do.
How often should we run it?
Once to establish where you stand, a retest after remediation, then annually or semiannually. Anything more frequent and staff start recognizing the pattern rather than the tactic.
Request a scope
Tell us who answers the phone.
We come back with a scope, a fixed price, and the authorization paperwork you would need to sign. No obligation to run it.
Or call 888.788.ZERO
An Espyonaj engagement is delivered by Nwaj Tech.
We reply within one business day. Nothing runs without a signed authorization.