
Social Engineering
Human psychology remains one of the most exploited attack vectors in modern cyber attacks. Our social engineering assessments help identify and strengthen your organisation's resilience against sophisticated social manipulation and phishing attempts.
What is Social Engineering?
Social Engineering Testing assesses human-layer security by simulating phishing to identify weaknesses in user awareness and response procedures. The goal is to evaluate how well staff can detect and respond to real-world deception tactics used to gain unauthorised access or sensitive information.
Our Engagement Process
T-14 days
Scoping and Strategy
We begin with a detailed consultation to understand your organisation’s structure, key roles, and specific security concerns regarding social engineering threats.
Together, we identify target groups, define campaign objectives, and establish clear boundaries for the assessment to ensure meaningful results while maintaining ethical standards.
T-7 days
Campaign Preparation
Our team develops the technical infrastructure and crafts targeted campaign materials based on reconnaissance or provided information. This includes creating authentic-looking templates, setting up tracking systems, and preparing response mechanisms.
We also establish emergency protocols and points of contact for immediate notification of critical findings.
Campaign Launch
The social engineering campaign begins with carefully timed and targeted approaches to selected groups within your organisation.
Our team actively monitors campaign progression and employee responses, ready to adjust tactics or provide immediate support if needed.
T+14 Days
Analysis and Recommendations
Upon campaign completion, we deliver a comprehensive report detailing campaign results, success rates, and identified vulnerabilities in human security controls.
Our debrief session walks through specific findings, patterns identified, and provides actionable recommendations for improving security awareness and organisational resilience.
Why Social Engineering Testing?
Test Real-World Scenarios
Traditional security controls may be robust, but social engineering often bypasses these by targeting human psychology. Our assessments simulate real-world attack scenarios to identify and address these human-centric vulnerabilities.
Measure Security Awareness
Understanding how your employees respond to social engineering attempts provides valuable insights into the effectiveness of your security awareness training and helps identify areas needing additional focus.
Protect Critical Assets
Social engineering attacks often target high-value assets through human manipulation. Our assessments help protect these assets by identifying and addressing vulnerabilities in human security controls before real attackers can exploit them.
Build Resilient Culture
Beyond identifying vulnerabilities, our assessments help build a security-conscious culture where employees understand their role in maintaining organisational security and are better equipped to recognise and respond to social engineering attempts.
Our Social Engineering Methodology
Project Black's social engineering assessments combine technical expertise with psychological understanding to create realistic and impactful scenarios that test your organisation's human security controls.
Our social engineering campaigns include:
Targeted Campaign Design
We develop customised phishing campaigns targeting distinct roles within your organisation. These campaigns are informed by thorough reconnaissance or customer-provided information to maximise authenticity and effectiveness.- Role-specific targeting strategies
- Custom infrastructure development
- Authentic communication templates
- Multiple attack vectors
Flexible Execution Options
Campaigns can be executed in two modes to suit your organisation's needs:- Blind: Testing without prior internal notification
- Visible: Coordinated with internal security teams
Impact-Focused Objectives
Campaign are designed with specific objectives that demonstrate real business impact, some examples include:- Finance department: Simulated fraudulent transfer attempts
- IT staff: Credential harvesting and access escalation
- Executive team: Business email compromise scenarios
- General staff: Data exfiltration attempts
Frequently Asked Questions
Will employees know a phishing campaign is being conducted?
That depends on the campaign mode. A blind campaign runs without internal notification and produces the most realistic results. A visible campaign is coordinated with your IT or security team, which is useful for testing detection and response capabilities. We discuss the best approach during scoping.
What types of social engineering attacks do you simulate?
We most commonly run phishing and spear phishing campaigns targeted at specific roles. We can also simulate pretexting, vishing (phone-based), and multi-vector campaigns that combine email with phone calls or SMS, depending on your threat model.
What happens when an employee clicks on a phishing link?
This depends on your goals. By default our campaigns will record clicks for a simulated phishing link. In more advanced campaigns we may opt to attempt Adversary in the Middle attacks or attempt to phish for credentials
Do you provide security awareness training after the assessment?
Our engagement concludes with a debrief that details campaign results, patterns identified, and targeted recommendations for improving security awareness. We can recommend training providers and help develop targeted awareness content based on your results.
How do you measure the success of a social engineering engagement?
We track click rates, credential submission rates (if a credential harvest page is in scope). These metrics, broken down by department and role, provide a baseline for measuring the effectiveness of future awareness programs.
Ready for a Pentest Quote?
Simply fill out the form, let us know what you're looking for, and we'll reach out to you within hours!