Skip to content
Cybersecurity

Social Engineering Tests

The best firewalls and EDR won't help when an employee clicks on phishing. We test team resilience against manipulation: email, phone, physical access. Measure vulnerability and train with awareness.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

What are Social Engineering Tests?

Social Engineering Tests are realistic simulations of phishing, vishing, and physical office intrusion attacks designed to measure how well your employees resist manipulation — the source of 82% of all security breaches. nFlo conducts unannounced campaigns tailored to your industry, measures concrete metrics like click rate and credential submit rate, and follows up with targeted awareness training to build a lasting security culture.

Realistic Scenarios
Real campaigns
Click Rate Metrics
Concrete indicators
Follow-up Training
Not just testing

One click = access to entire corporate network

82% of security breaches leverage social engineering

Comprehensive manipulation resistance testing

Phishing Campaigns

Realistic emails tailored to your industry

Vishing & Pretexting

Phone tests and pretexting scenarios

Physical SE

Physical office access attempts

€650K Wire Transfer Through BEC - Real Story

A manufacturing company’s CFO received an email from the “CEO” requesting an urgent €650K transfer to a key supplier. The email looked authentic: similar domain (company-inc.com instead of company.com), signature with logo, communication tone as usual.

The CFO made the transfer. Money gone. The email was spoofed - attackers had observed communications for a week (compromised assistant’s mailbox) and waited for the opportunity.

Without social engineering tests:

  • Employees don’t recognize sophisticated phishing
  • No verification procedures for unusual requests (callback)
  • Unaware of manipulation techniques (urgency, authority)
  • False sense of security (“that doesn’t affect us”)

We Simulate Real Attacks, Measure Reactions, Train

We don’t send obvious phishing “You won $1M”. We design scenarios tailored to your industry and context. Phishing from “HR”, vishing from “IT support”, tailgating as “courier”. Just like real attackers do.

What you get:

  • OSINT reconnaissance (what attackers know about your company)
  • Phishing campaigns tailored to industry (3-5 scenarios)
  • Vishing tests (voice phishing by phone)
  • Physical security testing (office access attempts)
  • Pretexting scenarios (manipulation through fabricated pretexts)
  • Metrics: click rate, credential submit rate, time to report
  • Identification of most vulnerable groups (departments, positions)
  • Report with vulnerability heat map across organization
  • Targeted training for most vulnerable individuals
  • Awareness workshops for entire team (optional)

Who Is It For?

This service is for you if:

  • You want to measure real team resistance to social engineering attacks
  • You’ve had a phishing incident and want to prevent future ones
  • You need to meet compliance requirements (awareness training)
  • You’re implementing security culture and want to measure it

Test Scope

1. Email Phishing Campaigns

Campaign types:

  • Spear phishing - targeted messages to key individuals
  • Brand impersonation - impersonating known brands
  • Internal phishing - email from “IT”, “HR”, “CEO”
  • Credential harvesting - fake login pages (Office 365, VPN)
  • Malicious attachments - macro-enabled documents, ISO files

Example scenarios:

  • “IT requires Office 365 password change”
  • “HR requests personal data update”
  • “CEO urgently needs access to document”
  • “Fake invoice from supplier with payment link”
  • “LinkedIn connection request with malicious PDF”

Metrics:

  • Email delivery rate
  • Open rate
  • Click rate (clicking the link)
  • Credential submit rate (entering data)
  • Malware execution rate (opening attachment)
  • Time to report (how many reported to IT/security)

2. Vishing (Voice Phishing)

Scenarios:

  • “IT support” requests password to solve a problem
  • “Bank” informs about suspicious transaction
  • “Supplier” requests payment details verification
  • “CEO” urgently needs specific information

What we test:

  • Whether employees verify caller identity
  • Whether they share sensitive information by phone
  • Whether they escalate unusual requests to supervisor
  • Time to detection (do they recognize the attack)

3. Physical Social Engineering

Physical access tests:

  • Tailgating - entering behind authorized person
  • Impersonation - posing as courier, technician, auditor
  • Dumpster diving - searching trash for documents, media
  • Badge cloning - attempting to copy access card
  • USB drop - leaving infected USB drives

What we check:

  • Whether reception verifies guest identity
  • Whether employees let strangers through
  • Whether sensitive documents are destroyed (shredder)
  • Whether found USBs are plugged into computers

4. Pretexting

Scenarios:

  • False pretext to obtain information
  • Supervisor impersonation (fake authority)
  • Urgency scenarios (“we need to do this immediately”)
  • Reciprocity (“I helped you, now you help me”)

5. OSINT (Preparation)

Before tests we gather information like real attackers:

  • Organization structure (LinkedIn)
  • Email patterns (firstname.lastname@)
  • Technologies used (job postings, LinkedIn)
  • Employee information (social media)
  • Public leaks (haveibeenpwned, breached databases)

Methodology

We work according to recognized frameworks:

  • Social Engineering Toolkit (SET)
  • Gophish - phishing campaigns platform
  • OSINT Framework - information gathering
  • Custom tools - for advanced scenarios

Ethics and Legality

  • Full management approval before tests
  • We don’t threaten or scare employees
  • We don’t use collected data inappropriately
  • After tests - educational debrief, not “name and shame”

Learn more about key concepts related to this service:

Contact your account manager

Discuss Social Engineering Tests with your dedicated account manager.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Custom quote

Providing your phone number will speed up contact.

How we work

Our proven service delivery process.

01

OSINT Research

Gathering company and employee information

02

Scenario Design

Designing realistic attack scenarios

03

Campaign Execution

Conducting phishing/vishing/physical tests

04

Metrics Analysis

Click rate, success rate, time to report analysis

05

Report and Training

Results documentation + awareness workshops

Benefits for your business

What you gain by choosing this service.

Lower Phishing Risk

Employees recognize and report threats

Measurable Progress

Concrete metrics for awareness improvement

Avoid BEC and CEO Fraud

Team verifies unusual requests

Security Culture

Security becomes part of company DNA

Frequently Asked Questions

Common questions about Social Engineering Tests.

How much do social engineering tests cost?

Basic phishing campaign (1 scenario, 100-500 employees): €3,500-5,500. Comprehensive program (phishing + vishing + physical + training): €9,500-19,000. Annual program (quarterly campaigns): €19,000-38,000.

Will employees know it's a test?

No - that would ruin the results. Tests are unannounced. After campaign completion we inform all participants and conduct an educational session. Goal is education, not shaming.

What if an employee clicks on phishing?

That's normal and expected - that's why we test. We don't punish people who clicked. Instead we offer additional training. Typically 20-30% click on the first campaign.

How long does a phishing campaign last?

Typical campaign lasts 2-4 weeks. We send emails gradually (not all at once) to observe reactions and time to report. Vishing and physical SE tests take 1-2 days.

What phishing scenarios do you use?

We design scenarios tailored to industry and context: email from 'HR' about data update, 'IT' about password change, fake invoice from supplier, LinkedIn request with attachment. Just like real attackers do.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist