PenTesting Company

Social engineering testing

Social Engineering Tests - Protect Your Organization

Many security incidents start with people, not software. A social engineering test measures how your organization responds when someone tries to trick staff into giving up access or information, and it shows you where to strengthen training and controls.

What is social engineering?

Social engineering is an umbrella term for attacks that target people rather than hardware or software. Instead of breaking a system directly, an attacker convinces someone to open a door for them, by clicking a link, sharing a password, approving a request, or handing over information they should not.

People are often the easiest path in, which is why attackers rely on these techniques so heavily. Testing for them helps your team recognize and resist the attempts they are most likely to see.

Common techniques we test

  • Phishing: email messages designed to get a recipient to click a link, open an attachment, or enter credentials.
  • Vishing: phone calls that use a believable pretext to request access or information.
  • Pretexting: a crafted story or identity used to build trust before making a request.
  • Physical scenarios, where in scope: attempts to gain access to a location or device.
Laptop, desktop, and mobile devices used during application testing

What a good report includes

Results you can act on, without blame.

  • Which scenarios were attempted and how they were handled.
  • Business impact described in plain language.
  • Severity rated with a documented, consistent method.
  • Practical guidance for training, process, and technical controls.
  • A readout to walk through the findings with your team.

Our process

  1. 1

    Scope and rules of engagement

    We agree on the scenarios, the targets, and the boundaries before any testing begins.

  2. 2

    Controlled testing

    We run the agreed scenarios in a controlled way and record how they are handled.

  3. 3

    Reporting

    You receive findings with what happened, the impact, severity, and practical guidance.

  4. 4

    Readout

    We walk through the results with your team and answer questions. Retest terms are set in the statement of work.

Scoping checklist

These questions define coverage so both sides know what is included. This is about clarity, not a checklist for choosing a vendor.

  • Which scenarios and channels are in scope, such as phishing email, phone calls, or physical access.
  • Who may be targeted and any people or groups that are off limits.
  • What is explicitly out of scope.
  • Rules of engagement and the conditions that stop a test.
  • Who to contact if we confirm a critical-severity issue mid-engagement.

Social engineering testing works best alongside technical testing. If you are also looking at your systems, see our network penetration testing and web application security testing services.

What is included

Beyond the testing itself, you get the deliverables your team needs to prioritize and fix what we find.

  • Scoped social engineering testing of the phishing, vishing, and physical scenarios we agree are in scope.
  • A written report with steps to reproduce, business impact, severity, and remediation guidance.
  • A readout after delivery to walk through findings and answer questions.
  • Retest terms set in the statement of work.

Scope a social engineering test

Tell us what you want to test and we will follow up with next steps.