Will someone hand over the keys?
Social engineering test
A social engineering test measures how your people respond to realistic deception: phishing emails, voice calls, text messages, and in-person pretexts. It produces rates you can act on and shows which pretexts actually work against your organization.
What you get
- Click, credential, and report rates by team
- Which pretexts work against your organization
- Awareness training built from real results
Overview
Technology can be locked down while a single phone call opens the door. We run controlled phishing, voice phishing, and other pretext campaigns to measure how your team responds under realistic pressure, then turn the results into training that sticks.
Scope
What is typically in scope. The final list is agreed with you before testing starts.
- Email phishing campaigns with credential capture or payload delivery
- Voice phishing against help desk, finance, or executive assistants
- SMS and messaging platform pretexts
- Physical pretexting and tailgating (optional)
- Reporting channel effectiveness
- Follow-up awareness sessions
Methodology
Phases run in this order. Each one produces evidence that feeds the next.
Open source reconnaissance
We build the same picture of your people and processes an attacker would, from public sources only.
Pretext design
Campaigns are designed around realistic scenarios for your industry and approved by you before launch.
Execution
Campaigns run in waves with safe payloads and capture pages under our control. Nothing harmful is delivered.
Measurement
Opens, clicks, credential submissions, and reports are measured by team without naming individuals in the report.
Training and reporting
Results become a short awareness session built on the pretexts that worked.
Deliverables
- Executive summary with rates by campaign and team
- Campaign details and timelines
- Reporting channel assessment
- Comparison to prior campaigns where available
- Awareness session materials built from results
- Recommendations for technical controls that would have stopped the pretexts
Sample report excerpt
One finding, in the structure every finding follows. The content is illustrative.
Help desk reset a password for an unverified caller
- Severity
- High
- Status
- Open, retest pending
- Affected assets
- Listed in appendix A
Impact
An attacker impersonating an employee obtained a password reset for a privileged account after a single phone call, bypassing every technical control on the login.
Evidence
Recorded and approved call transcript in which the help desk reset the account after confirming only publicly available details.
Remediation
Require verification through a second channel or manager approval for privileged resets, script the verification steps, and measure adherence with periodic tests.
Verification
Retested after remediation. Result and date are recorded here and reflected in the attestation letter.
Timeline
Typical duration
Typically 2 to 4 weeks including reconnaissance and campaign waves
What affects it
Voice campaigns are scheduled around business hours. Multiple waves spaced over weeks give a truer picture than a single blast.
Compliance drivers
Need this for an audit or renewal? This test provides accepted evidence for PCI DSS, HIPAA, SOC 2, Cyber insurance.
See the full requirement mappingFrequently asked questions
Will employees be named in the report?
No. Results are reported by team or department. Individual results can be shared privately with HR or security leadership if you request it.
How long does a campaign take?
Typically two to four weeks including reconnaissance, pretext approval, campaign waves, and reporting.
Is anything harmful sent?
No. Payloads are inert, capture pages are ours, and credentials entered are hashed and discarded after reporting.
How is this different from awareness training software?
Software sends generic templates. We build pretexts from real reconnaissance about your organization and include voice and in-person techniques that software cannot test.
Can this be combined with a penetration test?
Yes. A phished credential is a realistic starting point for an internal test, and the two together show the full path from email to data.
Related
Often paired with
External penetration test
Can an outsider get in?
Your internet-facing perimeter, tested from the outside in.
Learn moreInternal penetration test
What damage can an insider do?
Assume the perimeter has failed. Find out what happens next.
Learn moreRed team operation
Would we notice a determined attacker?
A goal-driven adversary simulation against people, process, and technology.
Learn moreReady to scope a social engineering test?
Tell us about your environment and timelines. You will talk to the people who run the engagement and hear back within one business day.