The problem is often context.

Consider a request involving a supplier payment.

  • The supplier exists.
  • The project is real.
  • The executive named in the message genuinely approves these payments.
  • The executive is attending an event that morning.
  • The recipient really does work with them.

Nothing about the request feels random.

That is exactly why it deserves a verification process.

Social engineering works best when the request fits the environment around it. Our work helps organisations understand that environment before somebody else uses it against them.

One message, three people

Nothing about the request feels random.A thirty-second call ends it.

1Personal assistant receives

Right name, real supplier, plausible timing.

2Assistant acts

Fwd: Urgent from the CEO

To: Finance · 09:14

Please action this today. He is in meetings and can't take calls.

Forwarded as urgent

CE

Chief Executive

mobile · saved contact

00:28

“That wasn't me. Don't pay anything.”

Called back on a known number

The request is passed on with added urgency.The check uses nothing the message supplied.

3Finance officer

Dune Line ConstructionN$ 184 500.00

Account ••• 4471 changed today

Payment released · 09:31
Dune Line ConstructionN$ 184 500.00

Supplier details unchanged

Not paid · number reported 09:16

No system was touched. The money has gone.Nothing lost, and the attempt is on record.

One believable message, three people, no system touched.One phone call, thirty seconds, nothing lost. That is what training changes.

Three ways we can help.

  • Understand your public exposure

    An Exposure Assessment looks at what someone outside the organisation can learn about your people, relationships, documents and public footprint.

    Exposure Assessment
  • Prepare your people

    Security Awareness Training helps staff recognise how social engineering works and what to do when a request deserves verification.

    Security Awareness Training
  • Investigate a question

    Principia Intelligence provides structured OSINT research for authorised security, fraud, due-diligence and investigative questions.

    Principia Intelligence

Our training philosophy

People still need to work after the session ends.

  • The objective is not to teach employees that every link is dangerous.
  • It is not to make finance suspicious of every supplier.
  • It is not to make executives afraid of using WhatsApp.

The objective is to help people recognise when context, urgency, authority or an unusual change means they should verify before acting.

That is a much more useful skill than memorising a list of warning signs.

Built around your environment.

Where appropriate, we learn enough about the organisation to understand:

  • Who carries authority
  • Which roles are publicly visible
  • What information the organisation publishes
  • Which relationships are visible externally
  • Which communication channels matter
  • Where verification or approval processes are important

That context makes training more relevant.

It can also reveal exposure the organisation did not realise it had.

For leadership.

Executives and public-facing leaders often have larger public footprints because visibility is part of their role.

That does not mean they should stop speaking publicly.

It means the organisation should understand what that visibility reveals.

Exposure Assessments can be conducted for relevant leaders where the appropriate permission and scope are in place. Personal findings are handled according to the arrangements agreed before the work begins.

When training is not the answer.

Not every problem is an awareness problem.

  • A phishing campaign may need investigation.
  • A technical vulnerability may require a penetration tester.
  • A live compromise may require incident response.
  • A legal issue may require a lawyer.

If another service is more appropriate, we will say so.

Start with what is actually happening.

Tell us about the organisation, what prompted the enquiry and what you are trying to improve or understand.