RINP // CYBERSECURITY SERVICES
Penetration Test · Social EngineeringWe measure risk in the human layer through recognition and reporting behavior.
Through controlled simulations, we measure how employees recognize suspicious messages and report them through the right channel. We assess reporting time and the escalation flow. We turn the results into a process, training, and technical control plan.
- Recognition and reporting behavior is measured on a per-segment basis.
- Reporting time, correct channel use, and the escalation flow are assessed together.
- Process, training, and technical control findings are prioritized along with their owners.
3 signals
- 01
Reporting Rate
The reporting reflex
- 02
Time to Report
Reaction speed
- 03
Correct Escalation
Process performance
Not who fell · measurement
What this service is, and is not
- It measures the resilience of the human layer through controlled social engineering scenarios run under written authorization.
- Beyond click data, it assesses recognition, reporting time, correct channel use, and escalation behavior.
- It turns verified process findings into a remediation plan across training, process, and technical control areas.
- It is not an exercise that singles out individuals or is used for performance evaluation.
- It does not deliver awareness training on its own; the measurement results determine the necessary training and control steps.
- Separate from the initial-access scenario within Red Team scope, it focuses on measuring the behavior and process of the human layer program.
Scope and boundaries
- Email phishing campaign and QR-based scenarios (core channels)
- Target audience, segment and wave plan; scenario design and rules of engagement (RoE)
- Measurement and reporting/escalation flow validation; effectiveness observation of related security controls
- Optional SMS phishing pilot and voice phishing pilot (as an add-on)
- Segment- and persona-based risk distribution; benchmarking (Deep Review and above)
- Measurement report, executive summary and a fix-priority work list under process + training + technical control
- Closure assessment; optional post-fix validation wave
- Decision support for management + an actionable work list for the technical team (two-layer delivery)
- 'Who fell?' framing, shaming language or click-rate-only reporting
- Awareness formality only or LMS-license distribution only
- Real credential abuse, account takeover or persistence attempts
- Physical intrusion, USB drops and office-entry scenarios
- Unauthorized third-party interaction or operational service disruption
- Psychologically harmful manipulation or personal shaming content
- Human-Layer Initial-Access Package (the initial-access vector tied to a Red Team scenario); a separate scope
- Written authorization, target audience and content approval are clarified before testing.
- An incident-time contact, stop criterion and test window are fixed.
- HR, legal, IT and SOC coordination is completed before the campaign.
- If there is a crisis, layoff, merger or legal-sensitivity period, discovery - not an automatic price - applies.
- The starting price is an approximate budget; the final proposal is given once channel, wave, approval speed and execution constraints are clear.
- Written authorization, target audience and segment list
- A content-approval mechanism and communication-language guide
- Existing reporting channels, the reporting process and report-phish flow information
- An incident-time contact, test window and stop criterion
- Optional: brand materials, sample communications, LMS/SCORM integration info (improves pricing)
The exercise is run under written authorization, an approved target audience, content sign-off, stop conditions, and a live incident contact line.
How we work: six steps from scoping to the retest wave
Scope & rules of engagement
Written authorization, target audience, ethical and legal boundaries, channel policy, content approval, sending infrastructure, test window and stop criterion are confirmed; the decision pressure is clarified.
Scenario design
The target audience, segment and wave plan are set; the scenario set (email + QR core; SMS and voice pilot/add-on) is designed with the brand-adaptation level and persona set.
Safe setup & measurement infrastructure
Sending infrastructure, measurement pixels, reporting-channel integration, segment separation and control-effectiveness observation points are brought online under written rules of engagement.
Controlled campaign execution
We run the approved waves within the rules of engagement and collect signals for recognition, reporting time, correct channel use, and escalation.
Analysis & reporting
We assess the measurements on a per-segment basis and consolidate process findings and control effectiveness in the executive summary and technical report.
Remediation plan and retest wave
We prioritize the process, training, and technical control steps along with their owners; once the client has applied these steps, we run a retest wave within the appropriate scope.
What we deliver
Executive summary
- Human layer view: summarizes results for recognition, reporting time, and escalation.
- Segment distribution: shows which groups need support first.
- Retest result: shows the change in behavior after the client has applied the controls.
Measurement report and action plan
- Measurement report: covers reporting rate, reporting time, correct channel, and escalation results.
- Process findings: describes the verified breakdowns in the reporting and escalation flow.
- Remediation plan: lists the process, training, and technical control steps along with their owners.
- Campaign records: document the target audience, wave plan, rules of engagement, and scenarios.
Optional outputs
- Post-fix validation wave (within 60 days): roughly 35% of the initial fee, with a minimum.
- Improvement workshop (90 minutes): sharing results and calibrating the training plan together.
- LMS/SCORM integration or report-phish integration: license cost is reflected as a separate line.
Leadership sees which human layer risk will be addressed first. The relevant teams track the process, training, and technical control steps.
Decision profile
- Duration
- 2–4 weeks, scope-proportional
- Depth
- Reporting reflex & escalation
- Delivery
- Management + technical
- Channel
- Email · QR core; SMS · voice pilot
- Best for
- New wave / human-layer program need
Which is the right start, and when?
These three approaches do not produce the same evidence object. Starting without knowing the difference wastes time and budget chasing the wrong proof.
| Criterion | ÖnerilenSocial Engineering Simulation | Human-Layer Initial-Access Package | Awareness Training only (LMS) |
|---|---|---|---|
| Decision question | Do the human layer, reporting flow and control effectiveness truly hold? | Does initial access open from the human layer in a Red Team scenario? | Did employees see the awareness topic in training? |
| Primary evidence object | Reporting rate, time-to-report, correct-escalation rate, process friction | A validated initial-access vector via the human layer and entry to the attack path | Training completion %, certificate, view time |
| Ideal trigger | Human-layer program need, reporting-reflex measurement, regulatory readiness | A human-layer initial-access extension in a goal-driven Red Team scenario | An annual awareness program or onboarding-wave training |
| Wrong match | Confusing human-layer program measurement with attack-path execution | Expanding a human-layer measurement need into a Red Team scenario | Substituting training completion % for measuring the reporting reflex |
One example of decision clarity
Anon case
New release wave: is the human layer resilient by evidence?
A financial institution gave us the scope to measure how employees recognize suspicious messages and report them through the right channel. We clarified the target segments, content sign-off, and stop conditions with the relevant teams.
The controlled campaign surfaced two process findings in reporting time and correct channel use. We reported the results at the segment and process level, without evaluating individuals.
We delivered the executive summary and a remediation plan across process, training, and technical control areas. After the client updated the reporting flow, the retest wave we ran confirmed the improvement in reporting behavior.
What this case produced
- Reporting behavior was measured at the process and segment level rather than the individual level.
- Two process findings in the reporting flow were verified.
- The applied change was measured with a retest wave.
Let's clarify your human-layer scope together
In this form we clarify the target audience, the channels, content sign-off, the test window, and the behaviors to be measured.
Frequently asked questions
The exercise is not used to evaluate individuals. Results are handled at the segment, process, and control level; the goal is to improve reporting behavior.
Click data alone is not considered sufficient. Reporting rate, reporting time, correct channel, and escalation behavior are measured together.
The standard scope covers email and QR scenarios. SMS and voice calls can be added as separate scope with the appropriate authorization and preparation.
Written authorization, the target audience, content sign-off, legal and HR coordination, the reporting channel, and stop conditions must be shared before the exercise.
The executive summary, a segment-based measurement report, process findings, and a remediation plan are delivered.
After the client updates the processes and controls, a retest wave can be run. The change is reported using the same measurements.
Related services and add-ons
If your need extends beyond human-layer program measurement, open the right bridge here.
Modular Red Team Simulation
If the focus is an attack path that starts with the human-layer vector and crown-jewel impact, the Modular Red Team Simulation (Human-Layer Initial-Access Package) is the right start.
PT-5Continuous Penetration Testing
If the focus is rhythm-based human-layer measurement and closure visibility, Continuous Penetration Testing can be taken together with the human-layer module.
PT-1Application Security Penetration Test
If the focus is business-flow validation where the human vector intersects the application surface, the Application Security Penetration Test is the right start.
// PT-4 · DISCOVERY
Let's clarify the target segments, the measurement scope, and the campaign boundaries together.
In the discovery call, we determine the channels, target groups, approval flow, and expected measurement set together.