Technical controls only cover part of your attack surface. We test the human layer through phishing campaigns, vishing calls, and physical access attempts, scoped and consented in advance.
Results are reported in aggregate — click rates, reporting rates, what worked — without naming or shaming any individual employee. The goal is a better security awareness program, not a blame list.