For organisations
Your security does not end at the edge of your network.
- Technical controls protect systems.
- People still make decisions.
- Public information provides context.
Principia Works helps organisations understand how those three things meet.
The problem is often context.
Consider a request involving a supplier payment.
- The supplier exists.
- The project is real.
- The executive named in the message genuinely approves these payments.
- The executive is attending an event that morning.
- The recipient really does work with them.
Nothing about the request feels random.
That is exactly why it deserves a verification process.
Social engineering works best when the request fits the environment around it. Our work helps organisations understand that environment before somebody else uses it against them.
One message, three people
Nothing about the request feels random.A thirty-second call ends it.
1Personal assistant receives
+264 81 ••• ••90
~Chief Executive · not in contacts
Pay Dune Line today please. In meetings all day, can't talk.09:12
Their account changed, details below. Thanks09:12
Right name, real supplier, plausible timing.
2Assistant acts
Fwd: Urgent from the CEO
Please action this today. He is in meetings and can't take calls.
Forwarded as urgent
Chief Executive
“That wasn't me. Don't pay anything.”
Called back on a known number
The request is passed on with added urgency.The check uses nothing the message supplied.
3Finance officer
Account ••• 4471 changed today
Supplier details unchanged
No system was touched. The money has gone.Nothing lost, and the attempt is on record.
Three ways we can help.
Understand your public exposure
An Exposure Assessment looks at what someone outside the organisation can learn about your people, relationships, documents and public footprint.
Exposure AssessmentPrepare your people
Security Awareness Training helps staff recognise how social engineering works and what to do when a request deserves verification.
Security Awareness TrainingInvestigate a question
Principia Intelligence provides structured OSINT research for authorised security, fraud, due-diligence and investigative questions.
Principia Intelligence
Our training philosophy
People still need to work after the session ends.
- The objective is not to teach employees that every link is dangerous.
- It is not to make finance suspicious of every supplier.
- It is not to make executives afraid of using WhatsApp.
The objective is to help people recognise when context, urgency, authority or an unusual change means they should verify before acting.
That is a much more useful skill than memorising a list of warning signs.
Built around your environment.
Where appropriate, we learn enough about the organisation to understand:
- Who carries authority
- Which roles are publicly visible
- What information the organisation publishes
- Which relationships are visible externally
- Which communication channels matter
- Where verification or approval processes are important
That context makes training more relevant.
It can also reveal exposure the organisation did not realise it had.
For leadership.
Executives and public-facing leaders often have larger public footprints because visibility is part of their role.
That does not mean they should stop speaking publicly.
It means the organisation should understand what that visibility reveals.
Exposure Assessments can be conducted for relevant leaders where the appropriate permission and scope are in place. Personal findings are handled according to the arrangements agreed before the work begins.
When training is not the answer.
Not every problem is an awareness problem.
- A phishing campaign may need investigation.
- A technical vulnerability may require a penetration tester.
- A live compromise may require incident response.
- A legal issue may require a lawyer.
If another service is more appropriate, we will say so.
Start with what is actually happening.
Tell us about the organisation, what prompted the enquiry and what you are trying to improve or understand.