One Engine. Every Channel They Use.
OSES™ is the only simulation engine that runs voice, video, live avatars, and messaging as one coordinated campaign.
Everything below is a capability of the same platform: AI spear vishing that holds a live conversation, avatars that join the meeting and answer questions, CEO impersonation on the channels your finance team trusts, voicemail drops with a working callback line, and standard email phishing when that is the right tool. The simulation does not stop at a click. It follows the request into the process behind it: the callback, the approval, the transfer.
Fully managed and external. No integration, no agents, nothing installed.
What almost nobody else can run
Six capabilities that separate an orchestrated simulation from a phishing test. Every one of them is live, interactive, and two-way.
An autonomous voice agent that researches the target, places the call, and holds a real conversation. It handles objections, escalates pressure the way a real caller would, and never reads from a script. If the call is not answered it leaves a voicemail, then answers the callback itself.
A synthetic executive who joins the call as a participant and responds in real time. Not a recording playing on a screen. It answers questions, handles pushback, and holds the pretext at the exact moment a target tries to verify who they are talking to.
Voice and video likeness built from publicly available material, delivered on the channels your finance and executive assistants already trust. Consent from the individual and named approvers are captured before anything is generated.
A voicemail placed directly into the mailbox without the phone ever ringing, in a cloned or scripted voice, with a callback number that is staffed by the agent. It is the highest-credibility opener there is, because the target initiates the contact themselves.
Channels that hand off to each other. A voicemail lands, a text references it, a calendar invite arrives from the same identity, and a video call confirms it. Testing one channel at a time misses the mechanic that makes modern social engineering work, which is the sequence itself.
A click is where a phishing test ends. It is where the consequential part of a real incident starts. We follow the request into the callback, the second approver, the vendor bank change, and the helpdesk reset, and report on whether the procedure held.
Everything OSES™ can run
The complete list, grouped by surface. Scope the whole thing or take one group at a time. Each capability is tagged to the stage of the spine it serves: measure risk, train for what you find, prove it changed.
Voice & Telephony
Where most orchestrated attacks begin, and where detection performs worstAutonomous voice agents that converse, adapt to objections, and pursue the ask without an operator on the line.
Voicemail delivered straight to the mailbox with no ring, seeding a pretext the target then acts on themselves.
The inbound line is answered by the agent, in character, so a callback is a test rather than a dead end.
A consented likeness built from short public samples, used for calls, voicemail, and meeting audio.
Calls into the service desk that push for a reset, an enrollment change, or a remote session.
Outbound presentation controlled to match the identity being simulated, including internal-looking extensions.
Cloned voice submitted against the verbal checks and knowledge-based questions your agents rely on.
The call establishes trust, then moves the target to a link, a portal, or a document to complete the action.
Calls and voicemail in the languages your workforce actually answers the phone in.
Video & Live Impersonation
Interactive media tests whether people comply while being talked toA synthetic participant that joins Teams, Zoom, or Meet and responds in real time to whatever is said.
The authority figure your approval chain is built to defer to, appearing on the channel they normally use.
Recorded synthetic video delivered by email, chat, or shared drive when a live session is not the right vector.
A supporting cast on the call, because a room full of colleagues agreeing is what breaks a person's resistance.
The invite itself is the lure, arriving from a spoofed organizer and landing in the place people trust by default.
Recordings and transcripts of what was said and agreed, for the debrief and for the board pack.
Email, Messaging & Web
The email gateway is the one channel with mature defenses. We run it, and everything around itClassic campaigns at population scale on sender infrastructure we control, for baseline and compliance cycles.
Lures generated per target rather than per campaign, from that person's actual role, relationships, and public footprint.
Internal chat carries assumed trust and almost no filtering, which makes it the softest written channel in the building.
Direct messages and channel posts from an identity your people have no habit of questioning.
Mobile-first sequences that land outside every control your security team owns.
The channel executives actually answer quickly, and the one no gateway inspects.
Quishing that moves the target from a monitored corporate device to an unmonitored personal one.
Recruiter, supplier, and peer personas that open a relationship before they ever make an ask.
When a target writes back with a question, the agent answers it and keeps the thread alive.
Branded portals and login flows that record the attempt without ever storing a usable secret.
Documents and files that measure whether they were opened, enabled, and actioned, with no live payload.
Lookalike domains and sending infrastructure we own and operate, so nothing touches your tenant.
Orchestration
The part competitors describe as a roadmap itemOne scenario running across several channels in a deliberate order, from a single scenario definition.
Each step references the last, so the second contact arrives already half-believed.
What happens next depends on what the target did, including going quiet or pushing back.
Up to 150 simultaneous live voice sessions, so voice covers everyone rather than a sample.
Delivery constrained to agreed business hours, time zones, and blackout periods.
The same scenarios run openly as a practice exercise when the goal is rehearsal rather than assessment.
Targeting & Pretext
A generic lure tests nothing. Context is what makes a simulation landThe public footprint an attacker would build from: leadership, structure, suppliers, events, and exposed material.
Which chains actually move money or access, so the simulation targets the ones that matter.
Scenarios written to survive scrutiny inside your specific organization, not a template with your logo on it.
Finance, HR, IT, executive assistants, and the front line each get the scenario that is credible for them.
Vendors, auditors, and partners are the identities least likely to be challenged and most likely to be spoofed.
A tested library to start from, and bespoke scenarios when your risk does not look like anyone else's.
Process & Identity Controls
What we test after the click, where the loss actually happensWhether the threshold and the approval rule hold when someone senior applies pressure in real time.
Whether anyone actually calls the number on file, or the number the caller supplied.
Whether the second signature is a real check or a formality performed under urgency.
The single most profitable request in business email compromise, run end to end against your process.
The reset and enrollment workflow that has become the primary route into large enterprises.
The human side of onboarding and verification, where synthetic identity meets a person making a judgment call.
Synthetic candidates through remote interviews and onboarding, the route behind the fraudulent worker problem.
Whether an urgent request for elevated access gets the scrutiny the policy says it gets.
Whether sensitive records get shared with a convincing caller who has no right to them.
Detection & Response
Whether anything in the stack saw it, and what happened nextCoverage in the seams between tools, where voice, chat, and mobile activity generate no alert at all.
How long from first contact to somebody telling security, measured across the whole population.
What the security team did once it arrived, and whether the response matched the runbook.
Training
Training on the procedure that failed, not a library of generic modulesShort content delivered while the experience is still fresh, tied to exactly what the person just did.
Finance, HR, IT, and executives get the red flags that apply to their workflow, not a shared deck.
Courses generated from your own engagement data, your policies, and your approval chain.
Packaged for the platform you already run, or delivered on ours if you would rather not touch it.
Let people argue with the deepfake instead of watching a slide about one, and adapt the session as they go.
Facilitated exercises on your incident process, with a live avatar in the room and an opt-in clone of a leader's voice.
Measurement & Reporting
Organizational findings. No named individuals, no leaderboardsYou scored X and your sector scores Y. That comparison, against organizations sharing your threat model, is the deliverable.
A single index built from channel, scenario, and control inputs, repeatable across cycles to show real movement.
Whether the money moved, the access was granted, or the detail was changed, including scenarios where no click exists.
Where the procedure held and where it gave way, written as fixes to specific controls.
Evidence mapped to NIS2, DORA, and ISO 27001, plus documentation for cyber insurance requirements.
The result in a format a board accepts, with the full audit trail of scope, consent, and execution behind it.
Delivery & Governance
How it runs, and the rails it runs onWe design, run, and debrief the entire engagement. Your team approves scope and reads the findings.
Your security team builds and runs simulations directly, with tailoring controlled by your people rather than ours.
Nothing installed, no agents, no tenant access. The engagement runs entirely outside your environment.
Scope, channels, population, windows, named approvers, and stop conditions agreed and signed before anything runs.
No voice or video likeness is generated without written consent from the individual and sign-off from your approvers.
Generated voice and video are handled on a zero retention basis, and your engagement data is yours to pull.
How an OSES™ engagement runs
OSES™ stands for Orchestrated Social Engineering Simulation. Five stages, one dataset, and a result that is comparable the next time you run it.
Every engagement runs under signed authorization with named approvers, agreed windows, and documented abort conditions. Client names never appear in our public material. For the systems-side variant that submits synthetic media through liveness, KYC, and voice authentication controls, see deepfake penetration testing, and for the deepfake-specific simulation program see deepfake simulation.
Five programs, one platform
Most organizations buy awareness training, red teaming, deepfake simulation, tabletop exercises, and orchestrated campaigns separately. OSES™ runs all of it on one dataset.
Orchestrated, not single-channel
Everyone tests email. Some test voice. Almost nobody runs them as one sequence where each contact makes the next one more believable. That sequence is the thing real attackers use, so it is the thing a simulation has to reproduce.
Live and two-way, not pre-rendered
Recorded media tests whether someone watches. Live agents and avatars test whether they comply while being talked to, questioned, and pushed. That is a different measurement, and it is the one that predicts an incident.
Measured past the click
Click rate stopped being a useful number the moment attacks moved to channels with no link in them. We measure the action: the approval given, the reset performed, the detail changed, the transfer authorized.
Where a single approval carries real loss
Organizations where one convincing call, one approved invoice, or one helpdesk reset is a material event.
Real scenarios, real findings
A cloned voiceprint submitted against verbal verification controls, and what it revealed about the step-up path behind them.
Read the case study Agentic AIAutonomous agents driving synthetic media generation and delivery end to end, with no human operator in the loop.
Read the case studyCommon questions
What is OSES™?
OSES™ stands for Orchestrated Social Engineering Simulation. It is the engine every capability on this page runs on. Rather than firing one channel at a time, OSES™ coordinates voice, video, messaging, and calendar into a single sequence built from your organization's real context, then carries the findings straight into training and reporting on the same dataset.
How many channels can run inside one simulation?
Twelve, and they can all reference each other. A voicemail drop lands, a text refers to it, a calendar invite arrives from the same identity, and a live avatar joins the call to close it out. Each step borrows credibility from the one before it, which is the mechanic a single-channel test cannot reproduce.
What is AI spear vishing?
A voice agent that researches the target, places the call, holds an unscripted conversation, adapts to objections, leaves a callback voicemail if nobody answers, and then answers the callback itself. Because no human operator sits on each line, a voice simulation can cover an entire population instead of a sample.
Can you impersonate our CEO?
Yes, with written consent from that individual and named approvers on the engagement. Executive likeness is built from publicly available material, used only inside the agreed scope and window, and the generated voice and video are handled on a zero retention basis.
Do you still run standard email phishing?
Yes. Email remains part of the toolkit and runs on our own sender infrastructure with landing pages, attachment simulation, and agentic reply handling when a target writes back. The difference is that email is treated as one channel in a sequence rather than the entire program.
Do we have to integrate anything?
No. Everything runs external to your environment with no software installed, no agents deployed, and no tenant access required. If you want engagement data inside your own tooling, results are available through an API.
How are results reported?
At the organizational level. Reporting covers action rates rather than clicks alone, where the process held and where it gave way, report rate and time to first report, and how the result compares against your own vertical. There are no named individuals and no department leaderboards.
How is scope and authorization controlled?
Every engagement runs under signed authorization with agreed scope, channels, target population, windows, named approvers, and documented abort conditions. Likeness consent is captured separately before any voice or video is built, and the full audit trail is part of the deliverable.
See the engine run against your organization
Thirty minutes. We walk through a real OSES™ engagement, scenario design through findings, and you decide whether your process would have held.
Partner and white label routing is handled separately through our partner program.
