Social Engineering & Employee Vulnerability Assessment
Most breaches don't begin with a broken firewall — they begin with a convincing message, a well-timed phone call, or a stranger held the door. We test your human layer the way a real adversary would: ethically, under written authorization, and entirely in confidence.
Veteran researchers. CERT-In empaneled. We measure human risk so you can reduce it — not assign blame.
Your strongest defences still answer the phone
You can harden every server and patch every application, and a determined attacker will still try the one surface no scanner can fix: your people.
Social engineering is the deliberate use of deception and manipulation to persuade someone to do something they otherwise wouldn't — open an attachment, approve a request, read out a code, or hold open a secure door. It is the entry point behind a large and growing share of real-world breaches, precisely because it bypasses technology and targets trust.
A social engineering assessment measures how that trust holds up under pressure — not to catch anyone out, but to understand where your defences depend on a person making the right call in the wrong moment. We approach this work the way an adversary would, then hand you something an adversary never will: a clear, aggregate picture of where the human layer is exposed and exactly which processes, controls and reporting paths will close the gap. The objective is always the same — make your organization measurably harder to manipulate.
"We don't test to prove your people can be fooled. We test to show you how to make sure they aren't."
How an attacker reaches your people
Every technique we use maps to a real adversarial objective. We pursue the same goals an attacker would — under authorization, and without ever putting your people or data at risk.
Build a profile
Quietly assemble open-source intelligence on people, roles and routines to make a pretext believable.
Establish trust
Pose as a vendor, a colleague, IT support or an executive to lower a target's guard.
Create urgency
Manufacture pressure — a deadline, an authority, a crisis — so the request is acted on before it is questioned.
Harvest credentials
Persuade a target to enter or hand over a password, one-time code or access token.
Deliver a payload
Get a malicious link, attachment or device opened, run or connected inside the perimeter.
Cross the physical line
Tailgate through a controlled door, plant a device, or walk out with documents that should never leave the building.
A disciplined, attacker-led methodology
We run every engagement through a structured methodology, so coverage is repeatable and defensible while the pretexts themselves stay creative and realistic. The work moves through four phases — reconnaissance, the attempt itself, what a successful foothold reaches, and a report your team can act on — and every phase operates strictly inside the agreed rules of engagement.
Tested like an adversary. Governed like a partner.
Social engineering is only legitimate when it is fully authorized, tightly scoped and held in confidence. These commitments are non-negotiable on every engagement.
The techniques real adversaries rely on
We use the methods that work against organizations today — selected per engagement and always inside the agreed rules of engagement.
| Technique | What it tests |
|---|---|
| OSINT-driven targeting | We gather open-source intelligence — public records, social media, leaked credentials, document metadata — to understand your people and craft pretexts an attacker would. |
| Phone pretexting & vishing | Authorized voice calls that impersonate a trusted party to test whether a request for access, information or action is verified before it is granted. |
| Email phishing | Realistic spear-phishing and clone-phishing campaigns that test susceptibility to credential capture and malicious links or attachments — and, just as importantly, whether they get reported. |
| Physical / on-site | Premises walk-throughs, tailgating and badge-following to test whether a stranger can reach restricted areas, plant a device, or remove sensitive documents. |
| USB drive baiting | Seeded media left in plausible locations to test whether unknown devices are connected to corporate systems. |
We also test SMS phishing (smishing) and messaging-app pretexts where they reflect your real exposure. Every technique is tailored to your threat model and bounded by the rules of engagement.
It's not whether someone clicks — it's what happens next
A single click is rarely the real story. We measure three things that actually determine whether a social-engineering attempt becomes a breach.
How an engagement works
A controlled, fully-authorized path from scoping to debrief — designed to give your team findings, and a safer organization, not a scoreboard.
What you receive
Every engagement ends in a report your team can act on — written for both the leaders who must understand the human risk and the practitioners who will close the gaps. Everything is reported in aggregate, in confidence, and oriented toward stronger controls.
Executive summary
Human-layer risk and business impact in plain language for leadership.
Technical findings
Each scenario with what was attempted, what succeeded, how it was detected or reported, and reproducible detail — anonymised, never a list of names.
Prioritized recommendations
Specific improvements to verification, reporting, access and awareness processes — ranked by impact, not generic advice.
Debrief presentation
A guided walk-through with the researchers who ran the engagement.
Remediation retest
We re-run targeted scenarios so you can confirm the human layer is genuinely more resilient.
Strict confidentiality
All material handled under NDA and retained per agreement.
Supports ISO 27001, SOC 2 and RBI/SEBI assessment requirements
Frequently asked questions
Is this about blaming our employees?
No — the opposite. We test systems and processes, not individuals, and we report findings in aggregate. The goal is to identify where your defences depend on a person making the right call under pressure, and to fix that with better controls and clearer reporting paths. People are an asset to strengthen, never a target to expose.
Is social engineering testing even legal?
Yes, when it is properly authorized. We never begin without explicit, signed approval from your leadership and a documented scope. That written authorization, together with agreed rules of engagement, is precisely what separates a legitimate assessment from an attack — and it protects both your organization and our team.
Will this disrupt our staff or operations?
We scope and pace engagements to avoid operational impact, define timing windows and volume limits up front, and keep immediate stop conditions and a live point of contact in place throughout. Tests are realistic but controlled, and never designed to harm, endanger or humiliate anyone.
Do you tell us who failed?
No. We report patterns, susceptible scenarios and process gaps — not a list of names. Aggregate, no-blame reporting keeps people willing to report real attacks, which is the behaviour that actually protects you.
How often should we test?
At minimum annually, and after significant change — a reorganisation, a merger, new high-risk processes, or a shift in your threat landscape. Periodic adversarial validation is what keeps the human layer resilient as both your organization and the attackers evolve.
Test the human layer before someone else does.
The same offensive-security discipline extends across the rest of your attack surface.
Test the human layer before someone else does.
Tell us what you're protecting and we'll scope an authorized, fully-confidential assessment that fits — or connect you directly with a researcher.