A · Assessment
Social engineering and phishing testing.
People are the most targeted part of any organisation. We test the human layer with realistic phishing and social-engineering campaigns, and help your team get better at spotting them.
Why it matters
Most breaches start with a person, not a server: a convincing phishing email, a phone call, a tailored message. You can have strong technical controls and still be one click away from an incident. Testing the human layer shows you where the real risk is.
How we do it
We run realistic, agreed campaigns, including phishing and other social-engineering techniques, scoped to be safe and useful. We measure how people respond, identify the gaps, and turn the results into targeted training rather than blame.
- Phishing simulation
- Pretexting
- Awareness training
What you get
- Scoped, realistic campaigns
- Phishing and human-layer testing
- Response and click-through analysis
- Findings by team and risk
- Targeted awareness training
- A plan to build a security culture
Frameworks & rigor
Named standards, real rigor.
We work to the standards your auditors and customers recognise, and certified practitioners do the work on every engagement.
Team credentials: OSCP · CISSP · CISA · CEH · ISO 27001 Lead Auditor.
Why Singahi
What you get with Singahi.
One team, end to end
Compliance, assessment and managed security from one partner that grows with you.
Credentials on the actual team
OSCP, CISSP, CISA, CEH and ISO 27001 Lead Auditor, on every engagement.
AI-assisted and manual
Automation for scale, with people for the judgment that actually matters.
Built to prove it
Evidence your customers, investors and regulators recognise.
FAQ
Questions, answered
Isn't this just sending fake phishing emails?
Will this embarrass our staff?
What happens after the test?
Can you test more than email?
How do you keep it ethical?
Across the lifecycle
Related services.
- Assessment
Red / Blue / Purple team
Adversary simulation: emulate APT groups
- Assessment
Penetration testing
AI-assisted & manual: web, mobile, API, network, thick client
- Managed
SOC / SIEM / MDR
24/7 monitoring, detection & response
- Assessment
Security maturity assessment
Score your posture against SAMM / CMMC
- Managed
EDR / XDR
Endpoint detection & response
- Managed
vCISO
Fractional security leadership
Derisk. Build Trust.
Prove your security. Close the deal.
Tell us what's prompting this, whether a questionnaire, an audit deadline or an investor ask. We reply within four business hours.