Skip to content
AttackVector

Will someone hand over the keys?

Social engineering test

A social engineering test measures how your people respond to realistic deception: phishing emails, voice calls, text messages, and in-person pretexts. It produces rates you can act on and shows which pretexts actually work against your organization.

Point in timeTargets: PeopleTypically 2 to 4 weeks including reconnaissance and campaign waves

What you get

  • Click, credential, and report rates by team
  • Which pretexts work against your organization
  • Awareness training built from real results

Overview

Technology can be locked down while a single phone call opens the door. We run controlled phishing, voice phishing, and other pretext campaigns to measure how your team responds under realistic pressure, then turn the results into training that sticks.

Scope

What is typically in scope. The final list is agreed with you before testing starts.

  • Email phishing campaigns with credential capture or payload delivery
  • Voice phishing against help desk, finance, or executive assistants
  • SMS and messaging platform pretexts
  • Physical pretexting and tailgating (optional)
  • Reporting channel effectiveness
  • Follow-up awareness sessions

Methodology

Phases run in this order. Each one produces evidence that feeds the next.

  1. Open source reconnaissance

    We build the same picture of your people and processes an attacker would, from public sources only.

  2. Pretext design

    Campaigns are designed around realistic scenarios for your industry and approved by you before launch.

  3. Execution

    Campaigns run in waves with safe payloads and capture pages under our control. Nothing harmful is delivered.

  4. Measurement

    Opens, clicks, credential submissions, and reports are measured by team without naming individuals in the report.

  5. Training and reporting

    Results become a short awareness session built on the pretexts that worked.

Deliverables

  • Executive summary with rates by campaign and team
  • Campaign details and timelines
  • Reporting channel assessment
  • Comparison to prior campaigns where available
  • Awareness session materials built from results
  • Recommendations for technical controls that would have stopped the pretexts

Sample report excerpt

One finding, in the structure every finding follows. The content is illustrative.

AttackVector · Social engineering test · Technical findingsIllustrative excerpt
HighFinding 1 of 19

Help desk reset a password for an unverified caller

Severity
High
Status
Open, retest pending
Affected assets
Listed in appendix A

Impact

An attacker impersonating an employee obtained a password reset for a privileged account after a single phone call, bypassing every technical control on the login.

Evidence

Recorded and approved call transcript in which the help desk reset the account after confirming only publicly available details.

Screenshot and request/response evidence appear here

Remediation

Require verification through a second channel or manager approval for privileged resets, script the verification steps, and measure adherence with periodic tests.

Verification

Retested after remediation. Result and date are recorded here and reflected in the attestation letter.

Every finding follows this structure.Download the full sample report

Timeline

Typical duration

Typically 2 to 4 weeks including reconnaissance and campaign waves

What affects it

Voice campaigns are scheduled around business hours. Multiple waves spaced over weeks give a truer picture than a single blast.

Compliance drivers

Need this for an audit or renewal? This test provides accepted evidence for PCI DSS, HIPAA, SOC 2, Cyber insurance.

See the full requirement mapping

Frequently asked questions

Will employees be named in the report?

No. Results are reported by team or department. Individual results can be shared privately with HR or security leadership if you request it.

How long does a campaign take?

Typically two to four weeks including reconnaissance, pretext approval, campaign waves, and reporting.

Is anything harmful sent?

No. Payloads are inert, capture pages are ours, and credentials entered are hashed and discarded after reporting.

How is this different from awareness training software?

Software sends generic templates. We build pretexts from real reconnaissance about your organization and include voice and in-person techniques that software cannot test.

Can this be combined with a penetration test?

Yes. A phished credential is a realistic starting point for an internal test, and the two together show the full path from email to data.

Ready to scope a social engineering test?

Tell us about your environment and timelines. You will talk to the people who run the engagement and hear back within one business day.