Offensive Security · Social Engineering Assessment Service dossier · 01/11

Social Engineering & Employee Vulnerability Assessment

Most breaches don't begin with a broken firewall — they begin with a convincing message, a well-timed phone call, or a stranger held the door. We test your human layer the way a real adversary would: ethically, under written authorization, and entirely in confidence.

Veteran researchers. CERT-In empaneled. We measure human risk so you can reduce it — not assign blame.

Discipline
Offensive Security · Human Layer
Techniques
Phishing · Vishing · Pretexting · Physical · Baiting
Engagement
Written authorization · agreed rules of engagement
Reporting
Aggregate, no-blame findings
Credential
CERT-In Empaneled
02

Your strongest defences still answer the phone

You can harden every server and patch every application, and a determined attacker will still try the one surface no scanner can fix: your people.

Social engineering is the deliberate use of deception and manipulation to persuade someone to do something they otherwise wouldn't — open an attachment, approve a request, read out a code, or hold open a secure door. It is the entry point behind a large and growing share of real-world breaches, precisely because it bypasses technology and targets trust.

A social engineering assessment measures how that trust holds up under pressure — not to catch anyone out, but to understand where your defences depend on a person making the right call in the wrong moment. We approach this work the way an adversary would, then hand you something an adversary never will: a clear, aggregate picture of where the human layer is exposed and exactly which processes, controls and reporting paths will close the gap. The objective is always the same — make your organization measurably harder to manipulate.

"We don't test to prove your people can be fooled. We test to show you how to make sure they aren't."
03

How an attacker reaches your people

Every technique we use maps to a real adversarial objective. We pursue the same goals an attacker would — under authorization, and without ever putting your people or data at risk.

01

Build a profile

Quietly assemble open-source intelligence on people, roles and routines to make a pretext believable.

02

Establish trust

Pose as a vendor, a colleague, IT support or an executive to lower a target's guard.

03

Create urgency

Manufacture pressure — a deadline, an authority, a crisis — so the request is acted on before it is questioned.

04

Harvest credentials

Persuade a target to enter or hand over a password, one-time code or access token.

05

Deliver a payload

Get a malicious link, attachment or device opened, run or connected inside the perimeter.

06

Cross the physical line

Tailgate through a controlled door, plant a device, or walk out with documents that should never leave the building.

04

A disciplined, attacker-led methodology

We run every engagement through a structured methodology, so coverage is repeatable and defensible while the pretexts themselves stay creative and realistic. The work moves through four phases — reconnaissance, the attempt itself, what a successful foothold reaches, and a report your team can act on — and every phase operates strictly inside the agreed rules of engagement.

PHASE 01 RECON PHASE 02 BREACH PHASE 03 POST-BREACH PHASE 04 REPORTING ✓ EXECUTIVE + TECHNICAL REPORTING — DEBRIEF & REMEDIATION RETEST
FIG. 01Engagement lifecycle — four phases, reporting to two audiences
PHASE 01 Recon Map the human attack surface. Open-source intelligence across search engines, email and DNS records, social media, document metadata and public records, alongside physical observation — premises walk-throughs, what's visible in the open, and the tailgating opportunities an attacker would scout.
Digital
Search EnginesEmail HarvestingDNS RecordsSocial MediaMetadataPublic Records
Physical
Physical WalkDumpster DivingTailgating Employees
PHASE 02 Breach Attempt the access an adversary would. Obtain credentials through phishing and spear-phishing, and test whether physical safeguards can be bypassed to reach documents or restricted areas — always safely, and always with prior authorization.
Domain Credentials — PhishingDomain Credentials — Spear PhishingBypass Physical Security
PHASE 03 Post-Breach Measure what a single success actually reaches. We assess how far a captured credential or a planted device would carry an attacker — without disrupting operations or touching data beyond the agreed scope.
PHASE 04 Reporting Deliver clear, prioritized findings for two audiences: an executive-level summary of human risk in business terms, and a technical report with reproducible detail, a debrief presentation, and remediation retesting to confirm the gaps are closed.
Executive-Level ReportTechnical ReportPresentationRemediation Testing
05

Tested like an adversary. Governed like a partner.

Social engineering is only legitimate when it is fully authorized, tightly scoped and held in confidence. These commitments are non-negotiable on every engagement.

01 Written authorization No test begins without explicit, signed approval from your leadership and a documented scope. It is the line between an authorized assessment and an attack.
02 Agreed rules of engagement We define the pretexts, channels, timing windows, volume limits, safe-words and immediate stop conditions together, before anything goes live.
03 People kept safe Exclusions are honoured, intimidation is bounded, and no test is designed to harm, humiliate or endanger anyone. The objective is the control, never the individual.
04 Aggregate, no-blame reporting We report patterns and process gaps, not a list of names. Findings strengthen the organization; they are never used against the people who took part.
05 Strict confidentiality Everything we observe stays between us and your authorized stakeholders, under NDA, handled and retained per agreement.
06

The techniques real adversaries rely on

We use the methods that work against organizations today — selected per engagement and always inside the agreed rules of engagement.

TechniqueWhat it tests
OSINT-driven targeting We gather open-source intelligence — public records, social media, leaked credentials, document metadata — to understand your people and craft pretexts an attacker would.
Phone pretexting & vishing Authorized voice calls that impersonate a trusted party to test whether a request for access, information or action is verified before it is granted.
Email phishing Realistic spear-phishing and clone-phishing campaigns that test susceptibility to credential capture and malicious links or attachments — and, just as importantly, whether they get reported.
Physical / on-site Premises walk-throughs, tailgating and badge-following to test whether a stranger can reach restricted areas, plant a device, or remove sensitive documents.
USB drive baiting Seeded media left in plausible locations to test whether unknown devices are connected to corporate systems.

We also test SMS phishing (smishing) and messaging-app pretexts where they reflect your real exposure. Every technique is tailored to your threat model and bounded by the rules of engagement.

07

It's not whether someone clicks — it's what happens next

A single click is rarely the real story. We measure three things that actually determine whether a social-engineering attempt becomes a breach.

The opening Susceptibility How readily a credible pretext succeeds across channels — email, voice, in person — so you understand where the human layer is most exposed, by scenario rather than by individual.
The decisive moment Detection & reporting Whether attempts are recognised and, critically, reported through the right channel — fast. A reported phishing email is a win, not a failure; we measure the behaviour that lets your security team respond before damage is done.
The safety net Process resilience Whether your verification and escalation processes catch what a person misses — call-back checks, approval controls, visitor and access procedures. The strongest defences don't rely on anyone spotting a sophisticated deception unaided.
08

How an engagement works

A controlled, fully-authorized path from scoping to debrief — designed to give your team findings, and a safer organization, not a scoreboard.

01
Scope and authorize
We agree objectives, in-scope channels and people, exclusions, timing and a clear rules-of-engagement document — and obtain written authorization from your leadership before anything begins.
02
Reconnaissance
We assemble open-source intelligence to model your human attack surface and design pretexts that are realistic for your sector, your people and your threat model.
03
Controlled execution
We run the agreed techniques — phishing, vishing, on-site, baiting — within the defined windows and limits, with live coordination and immediate stop conditions in place throughout.
04
Measure the response
We capture not just where attempts succeeded but whether they were detected, reported and contained — the behaviours and controls that determine real-world impact.
05
Report, debrief and retest
We deliver an executive summary and a technical report, walk your stakeholders through the findings, recommend specific control improvements, and retest to confirm the gaps are closed.
09

What you receive

Every engagement ends in a report your team can act on — written for both the leaders who must understand the human risk and the practitioners who will close the gaps. Everything is reported in aggregate, in confidence, and oriented toward stronger controls.

01

Executive summary

Human-layer risk and business impact in plain language for leadership.

02

Technical findings

Each scenario with what was attempted, what succeeded, how it was detected or reported, and reproducible detail — anonymised, never a list of names.

03

Prioritized recommendations

Specific improvements to verification, reporting, access and awareness processes — ranked by impact, not generic advice.

04

Debrief presentation

A guided walk-through with the researchers who ran the engagement.

05

Remediation retest

We re-run targeted scenarios so you can confirm the human layer is genuinely more resilient.

06

Strict confidentiality

All material handled under NDA and retained per agreement.

CERT-In Empaneled Aligned to MITRE ATT&CK · Initial Access Informed by NIST Awareness Guidance

Supports ISO 27001, SOC 2 and RBI/SEBI assessment requirements

10

Frequently asked questions

Is this about blaming our employees?

No — the opposite. We test systems and processes, not individuals, and we report findings in aggregate. The goal is to identify where your defences depend on a person making the right call under pressure, and to fix that with better controls and clearer reporting paths. People are an asset to strengthen, never a target to expose.

Is social engineering testing even legal?

Yes, when it is properly authorized. We never begin without explicit, signed approval from your leadership and a documented scope. That written authorization, together with agreed rules of engagement, is precisely what separates a legitimate assessment from an attack — and it protects both your organization and our team.

Will this disrupt our staff or operations?

We scope and pace engagements to avoid operational impact, define timing windows and volume limits up front, and keep immediate stop conditions and a live point of contact in place throughout. Tests are realistic but controlled, and never designed to harm, endanger or humiliate anyone.

Do you tell us who failed?

No. We report patterns, susceptible scenarios and process gaps — not a list of names. Aggregate, no-blame reporting keeps people willing to report real attacks, which is the behaviour that actually protects you.

How often should we test?

At minimum annually, and after significant change — a reorganisation, a merger, new high-risk processes, or a shift in your threat landscape. Periodic adversarial validation is what keeps the human layer resilient as both your organization and the attackers evolve.

11

Test the human layer before someone else does.

The same offensive-security discipline extends across the rest of your attack surface.

Offensive Security · Social Engineering Assessment

Test the human layer before someone else does.

Tell us what you're protecting and we'll scope an authorized, fully-confidential assessment that fits — or connect you directly with a researcher.