Skip to content

About Pretext8

Pretext8 was developed and is maintained by a cyber security practitioner with extensive hands-on experience across offensive social engineering and defensive security governance, risk, and assurance. That experience includes repeated social engineering engagements using physical access, impersonation, phishing, vishing, pretexting, and other manipulation techniques to test how effectively organisations resisted attempts to influence staff, bypass process, obtain access, and exploit trusted relationships.

Across those engagements, successful attacks repeatedly depended less on defeating technical security controls than on understanding how people interpreted legitimacy, authority, urgency, familiarity, and obligation in the workplace. This work provided direct insight into how convincing pretexts are built, how manipulation is adapted to different roles and workplace contexts, how trust is established across channels, and how small pieces of organisational information can be combined to make a request appear legitimate.

Those observations became the foundation of Pretext8 and shaped its central premise:

Legitimacy is established, not assumed.

Pretext8 brings the attack and defence perspectives together. It examines how social engineering operates across people, processes, technology, physical environments, and organisational relationships, then provides structured ways to understand exposure, review defensive capability, and assess the controls intended to resist manipulation.

Pretext8 provides a practical foundation for organisations seeking to understand how manipulation succeeds and strengthen the conditions that make it harder to achieve.

Busy office reception area with people moving through an access-controlled entrance while a receptionist handles a phone call