Home / FAQ
Questions
Frequently asked questions.
The questions we are asked before an engagement. If yours is not here, ask it directly — we answer plainly, including when the answer is that we are not the right fit.
Authorisation and scope
Who has to authorise a test?
Someone with the authority to grant it — normally a CISO, CTO or an executive who owns the systems in scope. We require the authorisation in writing, naming the targets, the exclusions and the stop conditions. See the authorization policy.
Do you test third-party systems?
Not without their permission. Cloud providers, SaaS vendors and suppliers each have their own authorisation requirements, so they are either excluded or you obtain permission first and we confirm it in writing before starting.
What if you find something critical mid-engagement?
We notify your named contact immediately, by the agreed channel, rather than saving it for the report. For critical findings affecting production safety we may pause testing until you have decided how to proceed.
Will an engagement disrupt our operations?
We plan for it. Destructive tests are excluded by default, timing windows are agreed, and any technique carrying operational risk is discussed with you before it is used.
Social engineering
What does a social engineering engagement involve?
An authorised campaign against an agreed population, using voice, email, text and — where in scope — physical approaches. Results are captured per target, per pretext and per channel, against a baseline. See social engineering.
Will our staff be humiliated?
No, and we will not run a campaign designed to embarrass individuals. Reporting is aggregated by role and department, with individual results handled confidentially and used for targeted training rather than blame.
How is personal data handled during a campaign?
Under the data handling agreement signed before testing: minimum necessary collection, agreed retention, defined storage location, and deletion at the end of the engagement. See the privacy policy.
Operations Center and response
Is the Operations Center really staffed around the clock?
Yes — 24 hours a day, 7 days a week, 365 days a year. Our security analysts monitor your network and workstations for internal and external threats across that coverage.
Can you contain a threat without our approval?
Only to the extent you have agreed in advance. Containment authority is defined during onboarding — which actions analysts may take unilaterally, and which require a call. Whatever we agree, it is written down before monitoring starts.
What does the 30-minute containment figure cover?
Isolation and mitigation of a confirmed threat by the Emergency Response Team — containing the spread rather than completing the full investigation, which takes longer and is reported separately.
Forensics and research
What happens to malware you recover?
It goes to our internal R&D department to be reverse engineered and analysed. The holistic understanding of the threat and malware is what allows for infrastructure hardening and advanced threat detection. See security research.
Can the investigation support legal or insurance processes?
We capture evidence in a forensically sound manner and document the chain of custody, and we can produce a report suitable for insurers or counsel. We are not a law firm and do not provide legal advice; where litigation is likely, tell us at the start so evidence handling is planned accordingly.
Training
What certifications do you offer?
Ethical Social Engineering, Defensive Social Engineering and Advanced Persistent Threat. All are instructor-led and scenario-driven.
Can you run a private cohort for our team?
Yes. Any certification can be delivered privately, and we will tailor the scenarios to your environment and sector.
Do you teach techniques that could be misused?
We teach the technique and the boundary together. Authorisation, scope, consent and data handling are assessed as part of the course, and participants who cannot work within them do not pass.
Ask us something not covered here.
Send the question directly. If it needs a technical answer rather than a sales one, it goes to an operator.