Services
Partners
Use cases
Clients
Company
Contact
FRENDE

Social engineering campaigns

Measure human and organisational resilience against the manipulation techniques attackers actually use — within an ethical and legally sound framework. It is the link that technical cybersecurity does not cover.

Social engineering

Test the human link.

Realistic, ethical campaigns — phishing, vishing, QR codes, physical intrusion — to measure how your teams react and to target cybersecurity awareness where it matters.

PhishingVishingQuishingPhysical intrusion
Social engineering campaign: one lure, many employees, one click HUMAN FACTOR Lurebait1 clickYOUR EMPLOYEES
Services

Services in detail

Phishing

Targeted or broad phishing campaigns, measuring open, click and compromise rates.

Vishing

Phone-based approaches to test procedures and employee vigilance.

Quishing

QR code phishing, exploiting the trust placed in physical and digital media.

Rogue USB devices

Planted media to assess reflexes when faced with unknown devices.

Physical intrusion

Attempts to enter premises without authorisation: tailgating, bypassing access controls and on-site reconnaissance.

What you get

Deliverables & approach

  • Realistic, ethical scenarios
  • Measurable, actionable indicators
  • Targeted awareness recommendations
  • Legal framework and consent strictly respected
Request a quote
Frequently asked questions

Frequently asked questions

Not individually, or the measurement is worthless. But the campaign is never covert: it is authorised in writing by management, and its framing — general notice to staff, consultation of employee representatives where required — is decided with you before launch. What makes a campaign ethical is not the absence of surprise, it is the existence of a clear mandate and known rules.

No. We report collective indicators — open, click and credential-entry rates, broken down by population or entity — never a list of names handed to management. A social engineering campaign measures how well a system works, not one person's mistake. Treating it otherwise would make it counterproductive, and hard to defend under employment and data protection law.

Nothing punitive. A high click rate points to a flaw in the arrangements — reporting that is too cumbersome, no clear signals, a validation procedure that can be bypassed — rather than a flaw in people. The result is there to target awareness where it is missing and to fix what makes the lure credible. The indicator that matters in the end is not the click rate but the reporting rate: only that one shows the alert chain works.

Let's talk about your scope.

A campaign is designed with you, respecting employment law and privacy, as part of your cybersecurity programme. Let's talk it through.