Service · A.15 · Social Engineering

Social engineering & phishing simulation — testing the human layer

Attackers target people, not just systems, and your strongest technical controls can be undone by a single click. We safely simulate real phishing, vishing and pretexting attacks to measure how your people respond — and turn the results into targeted awareness that actually changes behaviour.

Social EngineeringPhishingVishingPretextingAwareness
Human Layer: Email Phishing · Spear Phishing · Vishing · Smishing · Pretexting · Click Rate · Report Rate · Targeted Training Human Layer: Email Phishing · Spear Phishing · Vishing · Smishing · Pretexting · Click Rate · Report Rate · Targeted Training
// TL;DR

Social engineering testing safely assesses the human layer — how your people respond to the manipulation real attackers use. We run authorised, scoped simulations across email phishing, spear phishing, voice phishing (vishing), SMS phishing and pretexting, and measure the metrics that matter: the click rate, the compromise rate, and crucially the report rate — because whether people recognise and report an attack matters as much as whether they fall for it. It is done to measure and improve, not to blame: results are reported as aggregate metrics and turned into targeted awareness training. Often delivered as part of a red team engagement, or standalone.

// 01 Why test the human layer?

The uncomfortable truth of security is that attackers rarely bother defeating strong technical controls when they can simply ask a person to let them in. Phishing remains the most common initial-access vector in real breaches, because a convincing message to the right person bypasses firewalls, patching and monitoring in one step. Your people are, in effect, part of your attack surface — and the only way to know how resilient that layer is, is to test it the way an attacker would.

Testing the human layer does two things a security-awareness poster cannot: it gives you an honest, measured baseline of how susceptible your organisation actually is, and it identifies precisely where to focus training for the greatest effect. Done well, it also builds the reflex that matters most — recognising and reporting an attack rather than quietly clicking.

// 02 What we test

01

Email phishing

Broad and targeted campaigns — credential-harvesting pages, malicious attachments and link-based lures — measuring who interacts and who reports.

02

Spear phishing

Highly targeted messages crafted for specific individuals or roles using OSINT, simulating a determined attacker.

03

Vishing & smishing

Voice-phone and SMS-based attacks — testing whether staff disclose information or take action over the phone or by text.

04

Pretexting

Scenario-based social engineering where a tester assumes a plausible false identity to elicit information or access.

// 03 What we measure

A phishing simulation is only useful if it produces meaningful metrics, and the most revealing number is often the one organisations forget to track.

MetricWhat it tells you
Click rateHow many people interacted with the lure — raw susceptibility
Compromise rateHow many entered credentials or took the risky action — real exposure
Report rateHow many recognised and reported it — the true measure of resilience
Time to reportHow quickly the first report reached the security team

A high click rate with a high report rate is a very different — and healthier — picture than a low click rate with no reporting. We measure both sides.

// 04 Done to improve, not to blame

Social engineering testing has to be handled carefully, because it involves people. We treat it as a measurement-and-improvement exercise, never a trap to catch individuals out. Engagements are fully authorised and bounded by agreed rules of engagement; results are reported as aggregate metrics rather than named-and-shamed lists; campaigns are designed to teach at the moment of the click; and we agree in advance how escalations, distressed responses and de-briefs are handled. The output is not a list of who failed — it is a clear picture of organisational resilience and a targeted plan to raise it.

// 05 How we run it

01

Scope & authorise

Agree objectives, target groups, techniques, and rules of engagement including escalation handling.

02

Reconnaissance

OSINT to craft realistic, relevant lures — the way a real attacker would.

03

Campaign

Run the simulations across the agreed channels, capturing metrics safely and without disruption.

04

Analyse & report

Aggregate results, benchmark, and identify where awareness will have the most impact.

05

Awareness & retest

Recommendations for targeted training, and a follow-up campaign to measure improvement.

// 06 Frequently asked questions

What is social engineering testing?

An authorised assessment of how your people respond to manipulation — phishing, vishing, pretexting — measuring susceptibility and identifying where training helps most.

What types do you test?

Email phishing, spear phishing, vishing (voice), smishing (SMS) and pretexting, scoped to your risk.

Is it safe and ethical?

Yes — fully authorised, scoped, reported as aggregate metrics to measure and improve, never to blame individuals.

What do you measure?

Click rate, compromise rate, and crucially report rate — whether people recognise and report the attack, the true measure of resilience.

CY

CyberFortify

Offensive Security Practice

Runs authorised, ethical social engineering across the GCC and US — realistic phishing, vishing and pretexting that measures the human layer and drives targeted improvement, not blame.

How resilient are your people?

We run safe, authorised phishing, vishing and pretexting simulations, measure your real click and report rates, and give you a targeted plan to raise resilience — not a list of who to blame.

Scope a simulation → Full red team →