DeepBlocker / Products / 01 · Assess
RED TEAM · PRODUCT 01

Assess

We try to scam your team with a cloned voice, then hand you a scored report of exactly who was fooled and where your process broke.

In one sentence
You pay us to attack your own staff with AI voice-fraud calls, so you find the weak point before a real criminal does, and get a document that proves you checked.
What it is
A testa controlled attack, not software you install
Who it is for
Any organisationwith phone-based workflows
Direction
Inboundcalls coming at your staff
Status
Available nowsellable today, no new tech

How it works

A short, contained engagement. Nothing is installed on your systems. We agree the rules of engagement, run the attack, and debrief.

01

Scope & consent

We agree in writing which lines and which staff are fair game, and clone a voice your team would trust: a director, a known client, a partner. We pick the attack from a library of chains modelled on documented breaches, or build one to your threat model. Everything is authorised by you upfront.

02

The red-team agent calls

Our AI agent phones your staff over a real telephone line and attempts a realistic fraud: a payment instruction, a data request, a password reset. It adapts live to what the person says, and we can split your team across two angles, urgency versus friendliness, to see which one lands.

03

We record what happened

Who challenged the caller, who complied, who escalated, who transferred money in the test. You watch each call live, one control halts every campaign at once if you ever need it, and every call is logged with a sealed, tamper-proof record.

04

Scored report & fixes

You receive a readiness score, a breakdown of where the process failed, and specific, prioritised fixes: the verification steps and callbacks that would have stopped it.

One call, or a patient chain

A real attacker rarely tries once. They make several calls, each one friendlier and more informed than the last, until the ask finally lands. We can run that same chain against your team, so you see the whole attack and not a single lucky shot.

CALL 1 · FIRST CONTACT
A friendly recon call
The caller asks a few harmless questions and picks up a name, a system, a schedule. Nothing about it feels like an attack.
CALL 2 · DAYS LATER
A rapport call
The same caller follows up, sounds familiar, and earns one small yes. The target agrees without thinking twice.
CALL 3 · THE ASK
The exploitation call
Armed with what it learned and the trust it banked, the caller asks for the code, the reset or the payment.
The caller remembers every conversation and builds on it, and it can carry that memory from one quarter’s campaign into the next, exactly like a real criminal working the same target over months. Your report shows which call in the chain broke your people, and how to break the chain earlier.

See what your defense would catch, in the same run

Assess grades your people. But every simulated call is also replayed through DeepBlocker's own voice detector, so in one engagement you learn both where the humans broke and how much a machine layer would have added.

STEP 1 · THE ATTACK
We place the cloned call
A synthetic voice attacks your staff over a real telephone line, the same as a criminal would.
STEP 2 · THE DETECTOR
We replay it through our own sensor
The identical recording is scored by the DeepBlocker detector that powers Shield and Detect.
STEP 3 · THE UPLIFT
You see the catch rate
The report shows how many of these calls a machine layer would have flagged as fake before they reached a human.
Your people are graded on their own, independently. This catch rate is separate: it shows exactly what a detection layer would add on top, the uplift you would get from Shield on the line or Detect in your stack. Assess finds the gap. Those close it.

What you walk away with

The deliverable is a document, not a dashboard. It is built to be shown to people who ask hard questions.

Readiness score
A single figure your board understands, blending how your people did with what our detector would catch, tracked over time.
Failure map
Exactly which staff, lines and steps let the attack through.
Which angle worked
The A/B result: the pretext your team was most likely to fall for, so training hits the real weakness.
Defense catch rate
How many of the simulated calls our own detector would have flagged, the machine uplift on top of your people.
Prioritised fixes
The specific process changes that close each gap.
Sealed evidence pack
Tamper-proof records, mapped to the controls your regulator, board and insurer ask about.
Why this is defensible: an assessor must be independent from the defenses it grades. We sell no system sitting inside your infrastructure, so we can test honestly, the way a building inspector checks a house without selling houses.

Pricing

Start with a one-off assessment. The value compounds when you make it recurring, because the attacks change every quarter and a report from twelve months ago proves nothing.

One-off assessment
£9k-22k
single engagement · scoped by size
  • Full red-team attack across agreed lines
  • Scored report and prioritised fixes
  • One sealed evidence pack
Recurring · evidence subscription
£2.5k-4k
per quarter, per firm
  • Fresh attack every quarter with new tactics
  • Versioned evidence pack, updated each cycle
  • Trend line for your board and insurer
  • Locked methodology, comparable over time
Why firms make it recurring: attacks change every quarter, and a report from twelve months ago proves nothing. A versioned evidence pack, refreshed each quarter, is what your board, insurer and regulator want to see at renewal.