Smishing: we measure who hands over data from a personal phone
The SMS lands on the mobile, not in the corporate inbox. Our team designs, sends and reports the exercise: this is not the platform campaign builder.
How we run it
We define who is sent to and on which number base. We ask for explicit authorization, exclusion rules and the window in which the exercise is valid. Without that list there is no send: the SMS channel is not improvised and is not used as an open trial.
We write the SMS for your operation: shift, logistics, bank, HR. We do not clone an email into one hundred and sixty characters. If the scenario needs a landing, we build it to capture the gesture, not a real secret. The tone is local and the lure is auditable afterwards.
We fire in the agreed window, at the volume and cadence of the scope. We log who tapped, who replied and who reported. There is no self-service panel to resend the same text halfway through: the exercise has an owner on our side.
We deliver results by area and, when the roster allows, by person. The close-out includes which training follows and what must not be read as a disciplinary ranking. The data enters the program; it does not sit in a loose spreadsheet.
Why SMS does not belong in the same bucket as email
Because the perimeter the SOC already paid for does not cover a pocket. The employee who has no Outlook in the warehouse still has a phone. The “your parcel could not be delivered” or “confirm your shift” notice does not pass the mail…
What you get
A closed exercise, not access to the platform campaign builder.
Signed scope
Universe, window, pretext and exclusions in writing before the send. It serves audit and lets security and legal speak the same language.
SMS channel execution
A professional send on authorized numbers. It is not a shot from the product console and not a marketing experiment.
Report by area
Who tapped, who handed data over, who reported. Cut by area and, if the roster is clean, by role. No filler regional rates.
Close-out into the program
A contextual training recommendation and a rule not to use the result as a sanction. The simulations module remains the home of native campaigns.
What we need from you
An authorized number list, with an exclusion rule (personal numbers if legal so decides, out-of-scope areas, third parties). A security counterpart who can validate the pretext… We also need to know what the simulations module already covers and what it does not. If the goal is “trying the campaign assistant”, this is not the service. If the goal is…
How it fits the program
Professional smishing does not replace email campaigns or native QRishing. It is a bounded exercise that adds evidence for a channel the product does not operate alone. Results can be read next to the index and inbox…
Often contracted alongside this one
Questions about professional smishing
Is this the same as building a campaign on the platform?
Can you use personal numbers from the roster?
Does the mail filter see these messages?
Does it include WhatsApp?
Is there a published price?
Measure the channel the mail filter never sees
If your operation lives on the phone, the program cannot end in the inbox. Let’s talk universe and window.
Full catalog on Services