Social engineering testing safely assesses the human layer — how your people respond to the manipulation real attackers use. We run authorised, scoped simulations across email phishing, spear phishing, voice phishing (vishing), SMS phishing and pretexting, and measure the metrics that matter: the click rate, the compromise rate, and crucially the report rate — because whether people recognise and report an attack matters as much as whether they fall for it. It is done to measure and improve, not to blame: results are reported as aggregate metrics and turned into targeted awareness training. Often delivered as part of a red team engagement, or standalone.
// 01 Why test the human layer?
The uncomfortable truth of security is that attackers rarely bother defeating strong technical controls when they can simply ask a person to let them in. Phishing remains the most common initial-access vector in real breaches, because a convincing message to the right person bypasses firewalls, patching and monitoring in one step. Your people are, in effect, part of your attack surface — and the only way to know how resilient that layer is, is to test it the way an attacker would.
Testing the human layer does two things a security-awareness poster cannot: it gives you an honest, measured baseline of how susceptible your organisation actually is, and it identifies precisely where to focus training for the greatest effect. Done well, it also builds the reflex that matters most — recognising and reporting an attack rather than quietly clicking.
// 02 What we test
Email phishing
Broad and targeted campaigns — credential-harvesting pages, malicious attachments and link-based lures — measuring who interacts and who reports.
Spear phishing
Highly targeted messages crafted for specific individuals or roles using OSINT, simulating a determined attacker.
Vishing & smishing
Voice-phone and SMS-based attacks — testing whether staff disclose information or take action over the phone or by text.
Pretexting
Scenario-based social engineering where a tester assumes a plausible false identity to elicit information or access.
// 03 What we measure
A phishing simulation is only useful if it produces meaningful metrics, and the most revealing number is often the one organisations forget to track.
| Metric | What it tells you |
|---|---|
| Click rate | How many people interacted with the lure — raw susceptibility |
| Compromise rate | How many entered credentials or took the risky action — real exposure |
| Report rate | How many recognised and reported it — the true measure of resilience |
| Time to report | How quickly the first report reached the security team |
A high click rate with a high report rate is a very different — and healthier — picture than a low click rate with no reporting. We measure both sides.
// 04 Done to improve, not to blame
Social engineering testing has to be handled carefully, because it involves people. We treat it as a measurement-and-improvement exercise, never a trap to catch individuals out. Engagements are fully authorised and bounded by agreed rules of engagement; results are reported as aggregate metrics rather than named-and-shamed lists; campaigns are designed to teach at the moment of the click; and we agree in advance how escalations, distressed responses and de-briefs are handled. The output is not a list of who failed — it is a clear picture of organisational resilience and a targeted plan to raise it.
// 05 How we run it
Scope & authorise
Agree objectives, target groups, techniques, and rules of engagement including escalation handling.
Reconnaissance
OSINT to craft realistic, relevant lures — the way a real attacker would.
Campaign
Run the simulations across the agreed channels, capturing metrics safely and without disruption.
Analyse & report
Aggregate results, benchmark, and identify where awareness will have the most impact.
Awareness & retest
Recommendations for targeted training, and a follow-up campaign to measure improvement.
// 06 Frequently asked questions
What is social engineering testing?
An authorised assessment of how your people respond to manipulation — phishing, vishing, pretexting — measuring susceptibility and identifying where training helps most.
What types do you test?
Email phishing, spear phishing, vishing (voice), smishing (SMS) and pretexting, scoped to your risk.
Is it safe and ethical?
Yes — fully authorised, scoped, reported as aggregate metrics to measure and improve, never to blame individuals.
What do you measure?
Click rate, compromise rate, and crucially report rate — whether people recognise and report the attack, the true measure of resilience.