Challenges We Solve
You test controls, not adversaries
Your annual test proves the perimeter holds against a scanner. It tells you very little about whether your helpdesk would reset an MFA token for a confident caller at 4pm on a Friday.
Your board asks a question you cannot answer
'Could what happened to them happen to us?' Control maturity scores and compliance certificates do not answer it. Only a live simulation does
Regulated testing moves slower than attackers
Formal frameworks are rigorous and valuable, but the scoping cycle can run for months. Adversary tradecraft shifts in weeks, and you need something that keeps pace between formal assessments.

Your people are the control under test
Identity, helpdesk process, and single sign-on now sit on the critical path to your most sensitive services. Your team faces attackers who understand that better than most assurance programmes do.
What is threat intelligence-led social engineering?
A time-boxed red team engagement built on current threat intelligence, aimed at one question and one question only: can a determined adversary using today's tactics reach remote code execution or privileged access in your environment?
Claranet builds each engagement from the tradecraft we can evidence in the most recent significant breaches. We track what public reporting, vendor threat intelligence, and our own testing experience tell us about how these groups actually operate, then we replicate that tradecraft against your organisation under written authorisation.
This is a red team engagement, not a purple team exercise. We do not sit alongside your defenders and narrate. We behave as an adversary would, because the only honest test of whether a malicious actor can get in is to see whether one can. Your detection and response capability is measured by what it does when nobody has told it to expect anything.
The scope is deliberately agile. We are not attempting to replicate a full-scope regulatory exercise, and this is not a CBEST engagement. We assess your organisation against the latest tactics, techniques, and procedures (TTPs) with a single defined outcome, and we stop the moment we achieve it.
- Board-level assurance
A clear, evidenced answer to whether your organisation would have withstood the attack pattern currently in the headlines.
- Current tradecraft, not last year's playbook.
Our methodology is refreshed against each significant breach as intelligence becomes available.
- Agile scope, fast to stand up
Weeks to mobilise, not quarters, so you can respond to a shift in the threat landscape while it still matters.
- Contained by design
One objective, a hard stop on achieving it, and no disruption to live services.
Where we stop
One objective. A hard boundary.
The sole outcome we pursue is remote code execution or privileged access into in-scope services. Once we are there, we stop. We do not exfiltrate customer data, we do not deploy destructive tooling, and we do not persist beyond the agreed window. The value is in proving the path exists and evidencing every step of it, so you can see the changes to training and process that's needed to secure your business against such attacks.
Technical capabilities
Every engagement is assembled from a live intelligence picture, then executed by our red team under strict rules of engagement.
Threat intelligence baselining
We build a target-relevant threat profile from open source reporting, vendor intelligence, and breach analysis. Where a recent incident is relevant to your sector, we map the reported tradecraft and derive testable techniques from it.
Reconnaissance and target development
Open source intelligence against your organisation, its people, and its supply chain. We map the identity estate, helpdesk and joiner-mover-leaver processes, exposed services, and the individuals an adversary would realistically approach.
Social engineering execution
Voice phishing, helpdesk impersonation, MFA reset manipulation, and credential capture infrastructure, replicating the approaches described in reporting on recent financial services and enterprise intrusions.
Infrastructure and staging
Dedicated, isolated attack infrastructure. Look-alike authentication portals, command-and-control staging, and session handling, all built for the engagement and decommissioned on completion.
Execution and escalation
Where a foothold is achieved, we escalate towards the agreed objective: remote code execution or privileged access. Every action is logged with timestamps so your team can reconstruct the full attack path afterwards.
Evidence and board reporting
A technical report for your security team and a separate board-ready narrative. Both trace the route taken, the decision points where the attack could have been stopped, and the specific changes that would have stopped it.
How the engagement runs
Authorisation comes first, always. We do not begin any activity against your organisation until written approval is in place from an authorised signatory.
- Senior stakeholder briefing
A working session with your CXO group, general counsel, and where appropriate, board members. We set out the objective, the boundaries, the legal position, and what will and will not happen.
- Permission from all relevant parties
Where third parties, cloud providers, or outsourced functions fall inside the target path, permission is obtained from each of them before that path is used.
- Written approval to proceed
An authorised signatory in your organisation signs the rules of engagement and the authorisation to test. Nothing starts without it.
- Reconnaissance on targets
Intelligence-led target development against the agreed scope, producing the attack plan and the pretexts we intend to use.
- Staging
Attack infrastructure is built, tested, and readied. Pretexts are rehearsed and the control gate with your authorised contact is confirmed.
- Execution on systems
The simulation runs against the agreed objective. On achieving remote code execution or privileged access, we stop, secure the evidence, and stand the infrastructure down.
- Report and board assurance
Findings, attack path, and remediation priorities, delivered in a form your board can act on and your security team can implement.
Built for regulated and global organisations
The service is optimised for sectors where an intrusion is a regulatory event as much as a technical one, and where the board carries personal accountability for the answer.
Why these sectors, now
Reuters, drawing on Google threat intelligence data, reported that operators had built credential-harvesting sites aimed at employees of a number of major private equity, asset management, and financial services firms. The targeting shift is documented, not hypothetical.
Complements formal testing
This engagement sits alongside, not instead of, regulator-mandated frameworks. It fills the gap between formal cycles, when tradecraft has moved on and your last full-scope assessment is aging.
Evidence for the board and the regulator
The output is a defensible record that your organisation commissioned a live simulation of current adversary behaviour, understood the result, and acted on it.
Accreditations & partnerships
Our offensive security practice operates under recognised industry accreditation.




Related services
Threat intelligence-led social engineering works hardest as part of a wider offensive and defensive programme.
CREST Penetration Testing Services
Actionable, risk-focused intelligence on the security of your assets and environments.Continuous Security Testing
Non-stop security testing to identify vulnerabilities and assess their severity as fast as they emerge.Managed Detection and Response
24/7, SOC-managed detection and response to protect your estate and lower the impact of attacks.Ready to get started?
If your board has asked whether the last headline breach could have happened to you, we can help you answer it with evidence rather than opinion. A scoping conversation takes an hour and commits you to nothing.
