Social engineering

Social engineering penetration testing and phishing simulations

Attackers often find it easier to trick a person than to break a firewall. We test how your staff, help desk and front desk respond to realistic phishing, phone and in-person pretexts, then help you fix the processes that let an attacker through.

  • Phishing, vishing and physical pretexting
  • Scenarios built around your organization
  • Findings aimed at processes, not blaming people
Professional working at a computer from home

Human-led testing

Run by certified ethical hackers as part of our pen testing practice

Email to phone to front door

Test every channel an attacker would use

Built for improvement

Results feed training, controls and tabletop exercises

Support engineer with a headset at her desk

Why test people

A social engineering assessment shows where trust can be abused

Most serious incidents involve a person somewhere in the chain. Someone opens a convincing attachment, approves an unexpected MFA prompt, resets a password for a caller who sounds right or holds a door for a stranger with a clipboard. Technical controls help, but they do not replace a process people follow under pressure.

A social engineering assessment tests those moments safely. We agree on goals, targets and limits with you, run realistic scenarios and report what worked, what did not and why. The aim is to strengthen verification steps, reporting habits and email security controls, and to give your training program real examples to work from.

Test types

Phishing testing, vishing and more

How it works

How a social engineering engagement runs

1

Set goals and limits

We agree on objectives, targets, channels, off-limits topics and who inside your organization knows the test is happening.

2

Build scenarios

We research what an outsider could learn about your organization and design pretexts that match your real risks.

3

Run the campaign

Our testers carry out the approved scenarios, tracking responses and stopping immediately if anything goes outside the agreed limits.

4

Report and improve

You get results by channel and group, the process gaps behind them and specific changes to controls, procedures and training.

What you get

Deliverables from a social engineering assessment

  • Agreed rules of engagement and scenario plan
  • Results by channel, department and scenario
  • Analysis of reporting behavior and response time
  • Process and control gaps behind each success
  • Recommended changes to verification procedures
  • Executive summary for leadership
  • Example lures you can use in awareness training
  • Optional retest to measure improvement

Technologies

Email security platforms our team supports

We test and tune the email protection you already run, and can help adjust it based on what our campaigns reveal.

Email security

  • Avanan / Check Point Harmony
  • Microsoft security services

Email and identity

  • Microsoft 365
  • Exchange
  • Microsoft Entra ID
  • Okta

These are platforms our engineers support, not partnerships. See all technologies we support.

FAQ

Social engineering testing questions

It is an authorized test of how your people and processes respond to manipulation. Testers use phishing emails, phone calls, text messages or in-person pretexts to try to obtain credentials, access or information, then report which controls and procedures held and which did not.

A phishing simulation tests one channel, usually email, often on a recurring basis to measure awareness. A social engineering assessment is broader and more targeted, combining email, phone and physical techniques to reach a specific objective, the way a real attacker would.

Our reports focus on groups, processes and controls rather than naming individuals, unless you ask otherwise. The goal is to fix verification steps and training, not to embarrass staff.

Cost depends on the channels included, the number of targets or campaigns, whether physical testing is in scope and how much custom research each scenario needs. We scope it on a call and give you a fixed quote.

Many organizations run phishing simulations several times a year so awareness stays current, with a broader social engineering assessment annually or after major changes such as a new help desk process. You can add either to a PTaaS schedule.

Security awareness and testing support requirements in frameworks such as SOC 2, HIPAA, PCI DSS, CMMC and NIST, and cyber insurers often ask about phishing training. Our reports provide evidence of testing and follow-up.

Book a scoping call

See how your people and processes hold up

Tell us which channels and teams you want tested. We’ll design scenarios and send a fixed quote.

  • Scenarios built around your real risks
  • Rules of engagement agreed before testing

Prefer email? Write to [email protected] or call (858) 712-0040.

Send us a message