Social Engineering Tests
The best firewalls and EDR won't help when an employee clicks on phishing. We test team resilience against manipulation: email, phone, physical access. Measure vulnerability and train with awareness.

What are Social Engineering Tests?
Social Engineering Tests are realistic simulations of phishing, vishing, and physical office intrusion attacks designed to measure how well your employees resist manipulation — the source of 82% of all security breaches. nFlo conducts unannounced campaigns tailored to your industry, measures concrete metrics like click rate and credential submit rate, and follows up with targeted awareness training to build a lasting security culture.
One click = access to entire corporate network
Comprehensive manipulation resistance testing
Phishing Campaigns
Realistic emails tailored to your industry
Vishing & Pretexting
Phone tests and pretexting scenarios
Physical SE
Physical office access attempts
€650K Wire Transfer Through BEC - Real Story
A manufacturing company’s CFO received an email from the “CEO” requesting an urgent €650K transfer to a key supplier. The email looked authentic: similar domain (company-inc.com instead of company.com), signature with logo, communication tone as usual.
The CFO made the transfer. Money gone. The email was spoofed - attackers had observed communications for a week (compromised assistant’s mailbox) and waited for the opportunity.
Without social engineering tests:
- Employees don’t recognize sophisticated phishing
- No verification procedures for unusual requests (callback)
- Unaware of manipulation techniques (urgency, authority)
- False sense of security (“that doesn’t affect us”)
We Simulate Real Attacks, Measure Reactions, Train
We don’t send obvious phishing “You won $1M”. We design scenarios tailored to your industry and context. Phishing from “HR”, vishing from “IT support”, tailgating as “courier”. Just like real attackers do.
What you get:
- OSINT reconnaissance (what attackers know about your company)
- Phishing campaigns tailored to industry (3-5 scenarios)
- Vishing tests (voice phishing by phone)
- Physical security testing (office access attempts)
- Pretexting scenarios (manipulation through fabricated pretexts)
- Metrics: click rate, credential submit rate, time to report
- Identification of most vulnerable groups (departments, positions)
- Report with vulnerability heat map across organization
- Targeted training for most vulnerable individuals
- Awareness workshops for entire team (optional)
Who Is It For?
This service is for you if:
- You want to measure real team resistance to social engineering attacks
- You’ve had a phishing incident and want to prevent future ones
- You need to meet compliance requirements (awareness training)
- You’re implementing security culture and want to measure it
Test Scope
1. Email Phishing Campaigns
Campaign types:
- Spear phishing - targeted messages to key individuals
- Brand impersonation - impersonating known brands
- Internal phishing - email from “IT”, “HR”, “CEO”
- Credential harvesting - fake login pages (Office 365, VPN)
- Malicious attachments - macro-enabled documents, ISO files
Example scenarios:
- “IT requires Office 365 password change”
- “HR requests personal data update”
- “CEO urgently needs access to document”
- “Fake invoice from supplier with payment link”
- “LinkedIn connection request with malicious PDF”
Metrics:
- Email delivery rate
- Open rate
- Click rate (clicking the link)
- Credential submit rate (entering data)
- Malware execution rate (opening attachment)
- Time to report (how many reported to IT/security)
2. Vishing (Voice Phishing)
Scenarios:
- “IT support” requests password to solve a problem
- “Bank” informs about suspicious transaction
- “Supplier” requests payment details verification
- “CEO” urgently needs specific information
What we test:
- Whether employees verify caller identity
- Whether they share sensitive information by phone
- Whether they escalate unusual requests to supervisor
- Time to detection (do they recognize the attack)
3. Physical Social Engineering
Physical access tests:
- Tailgating - entering behind authorized person
- Impersonation - posing as courier, technician, auditor
- Dumpster diving - searching trash for documents, media
- Badge cloning - attempting to copy access card
- USB drop - leaving infected USB drives
What we check:
- Whether reception verifies guest identity
- Whether employees let strangers through
- Whether sensitive documents are destroyed (shredder)
- Whether found USBs are plugged into computers
4. Pretexting
Scenarios:
- False pretext to obtain information
- Supervisor impersonation (fake authority)
- Urgency scenarios (“we need to do this immediately”)
- Reciprocity (“I helped you, now you help me”)
5. OSINT (Preparation)
Before tests we gather information like real attackers:
- Organization structure (LinkedIn)
- Email patterns (firstname.lastname@)
- Technologies used (job postings, LinkedIn)
- Employee information (social media)
- Public leaks (haveibeenpwned, breached databases)
Methodology
We work according to recognized frameworks:
- Social Engineering Toolkit (SET)
- Gophish - phishing campaigns platform
- OSINT Framework - information gathering
- Custom tools - for advanced scenarios
Ethics and Legality
- Full management approval before tests
- We don’t threaten or scare employees
- We don’t use collected data inappropriately
- After tests - educational debrief, not “name and shame”
Related Glossary Terms
Learn more about key concepts related to this service:
Contact your account manager
Discuss Social Engineering Tests with your dedicated account manager.

How we work
Our proven service delivery process.
OSINT Research
Gathering company and employee information
Scenario Design
Designing realistic attack scenarios
Campaign Execution
Conducting phishing/vishing/physical tests
Metrics Analysis
Click rate, success rate, time to report analysis
Report and Training
Results documentation + awareness workshops
Benefits for your business
What you gain by choosing this service.
Lower Phishing Risk
Employees recognize and report threats
Measurable Progress
Concrete metrics for awareness improvement
Avoid BEC and CEO Fraud
Team verifies unusual requests
Security Culture
Security becomes part of company DNA
Related Articles
Expand your knowledge with our resources.
Blocking the Device Code Flow in Microsoft Entra ID with Conditional Access
Device Code Phishing abuses a flow that most organizations don't even need. We show how to disable or restrict the Device Code Flow in Entra ID with Conditional Access — step by step, with pitfalls and validation.
Read more →Deepfake, vishing and CEO fraud: how to protect your company from AI-powered scams
An employee at engineering firm Arup transferred USD 25 million after a video call with deepfake "directors". Voice cloning and AI-powered CEO fraud are now a real financial risk. We show how to defend against them — from procedures to technology.
Read more →Device Code Phishing: what it is and how the attack on Microsoft Entra ID works
An attacker doesn't need your password — they just need you to enter a code they supplied. See how Device Code Phishing abuses the OAuth2 Device Code Flow in Microsoft Entra ID and why it can bypass MFA.
Read more →Frequently Asked Questions
Common questions about Social Engineering Tests.
How much do social engineering tests cost?
Basic phishing campaign (1 scenario, 100-500 employees): €3,500-5,500. Comprehensive program (phishing + vishing + physical + training): €9,500-19,000. Annual program (quarterly campaigns): €19,000-38,000.
Will employees know it's a test?
No - that would ruin the results. Tests are unannounced. After campaign completion we inform all participants and conduct an educational session. Goal is education, not shaming.
What if an employee clicks on phishing?
That's normal and expected - that's why we test. We don't punish people who clicked. Instead we offer additional training. Typically 20-30% click on the first campaign.
How long does a phishing campaign last?
Typical campaign lasts 2-4 weeks. We send emails gradually (not all at once) to observe reactions and time to report. Vishing and physical SE tests take 1-2 days.
What phishing scenarios do you use?
We design scenarios tailored to industry and context: email from 'HR' about data update, 'IT' about password change, fake invoice from supplier, LinkedIn request with attachment. Just like real attackers do.