Social Engineering
Authorised phishing, vishing, and pretext testing that measures how your organisation responds to human-targeted attacks. Constructive reporting, no naming of individuals.
Overview
People are a primary attack vector for malicious actors because human psychology often provides the fastest path past technical security controls. Social engineering testing measures how your organisation responds to realistic social engineering attacks: phishing emails, vishing calls, pretexting, and other social engineering techniques that exploit trust rather than code. It also tests whether your existing security policies, reporting culture, and cybersecurity awareness training hold under real pressure.
We design authorised, scenario-based campaigns within agreed scope, simulate social engineering attempts safely, and capture engagement and reporting metrics. The output is constructive by design. We measure click rates, credential-submission rates, and how effectively staff report suspicious contact. Those results translate directly into specific awareness actions. Penetration test findings often show that technical controls are solid, yet social engineering remains the vulnerability that matters most. This service is designed to address that gap.
Reporting is no-blame throughout. We report on rates and behaviours, never on individuals. Confidential information gathered during testing is handled securely and deleted after the engagement. Security readiness improves when people feel safe to report mistakes rather than hide them.
What’s included
- Email phishing and targeted spear-phishing campaigns
- Voice (vishing) and SMS (smishing) scenarios where in scope
- Pretext and impersonation testing
- Physical security and on-site tailgating scenarios where agreed
- Click, credential-submission, and reporting-rate metrics
- No-blame, constructive reporting on behaviours
- Targeted awareness recommendations and optional training delivery
How we work
-
01
Design the campaign
We agree realistic scenarios, target groups, success metrics, and safe-handling procedures for any captured data, with written authorisation from your leadership before launch. Scenario design uses open source intelligence to reflect the types of social engineering attacks your organisation would realistically face.
-
02
Run it safely
We execute campaigns using social engineering techniques calibrated to your sector, capture engagement metrics, and handle any submitted data securely without exposing sensitive data.
-
03
Measure
We report click, submission, and reporting rates, identify the social engineering tactics and communication patterns that need attention, and note the attack vectors that proved most effective.
-
04
Improve
We translate results into specific awareness recommendations and, if you wish, deliver targeted training programs to close the gaps identified.
What you get
- Social engineering assessment report with engagement metrics
- Analysis of susceptible behaviours and reporting effectiveness
- Targeted awareness recommendations
- Optional awareness training delivery
Frequently asked questions
Will individual employees be named or penalised?
No. We report on rates and behaviours, not individuals, and we recommend a no-blame approach throughout. Security awareness improves in cultures where people feel safe to report mistakes. Naming individuals works against that goal.
What kinds of scenarios do you use?
Scenarios are tailored to your sector and the realistic threats your organisation faces. That might include credential-harvesting phishing emails, IT-helpdesk impersonation vishing calls, supplier-spoofing pretexting, or on-site physical security testing such as tailgating. We agree the scenario design with you before anything is sent or attempted. We use social engineering techniques that malicious hackers use, but within a controlled, authorised scope.
What is the difference between phishing and spear-phishing?
Phishing campaigns target a broad group with a generic message. Spear-phishing uses reconnaissance to craft targeted messages that appear legitimate to a specific individual or team, using real context to gain access to sensitive information. Both are valuable to test. We recommend starting with broader phishing to establish a baseline, then running spear-phishing to assess how your organisation responds to more sophisticated social engineering attempts.
What types of social engineering attacks does this cover?
We cover the main types of social engineering attacks: phishing, spear-phishing, vishing, smishing, pretexting, impersonation, and physical social engineering such as on-site testing and tailgating where agreed. Each type is scoped to your environment and what is realistic for the threat actors relevant to your sector.
See the kind of report you get
Every engagement ends with a report you can act on: an executive summary, CVSS-aligned findings, reproduction evidence, and prioritised fixes. Ask for a redacted sample and we will share one.
Credentials held by our team










How ready is your security and compliance?
Answer 15 quick questions across the controls auditors actually check, and get an instant readiness score with tailored next steps. No call required.
Ready to simplify security and compliance?
Pick a service, book a scope call, or ask a question. Whatever order works.