Back to Offensive Security Services
Offensive

Social Engineering Simulation

Measure real human risk with controlled phishing, vishing, and physical simulations, ethically scoped and leadership-ready.

Simulation of social engineering attacks (phishing, vishing, physical).

1–2 weeksMedium effort

Why teams engage us

Most targeted breaches include a human step: cred harvesting, MFA fatigue, or impersonation. Without realistic simulations, awareness programs optimize for compliance clicks, not behavior change. Poorly designed tests erode trust and create legal exposure.

What we deliver

We design and execute social engineering simulations aligned to your culture and risk: email and SMS phishing, voice scenarios, and physical attempts where appropriate. Rules of engagement define safety, escalation, and data handling. Reporting emphasizes systemic lessons, not naming-and-shaming individuals by default.

How we run it

  1. Threat profile: who attackers impersonate and what they want
  2. Scenario design: difficulty, pretext quality, and safety rails
  3. Execution with monitoring and abort criteria
  4. Aggregate metrics and thematic analysis
  5. Workshop: lessons and program improvements

Outcomes you can expect

  • Measured susceptibility and reporting rates with trends over time
  • Recommendations for controls: MFA policies, help desk verification, device posture
  • Awareness themes tied to observed failure modes
  • Leadership-ready narrative on human risk

Why Evaluris

  • Scenarios informed by real offensive engagements and current attacker TTPs.
  • Ethical guardrails and legal alignment are non-negotiable.
  • Outputs improve controls, not just training completion rates.

Deliverables

  • Campaign report
  • Response statistics
  • Training recommendations

When it makes sense

  • Awareness program validation
  • After training
  • High-risk workforce

FAQ

Is this legal and compliant?

We work from signed rules of engagement, privacy constraints, and labor-policy alignment. We do not surprise executives or access personal data without agreement.

Do you identify individuals?

By default we report aggregate metrics. Individual detail is optional and tightly governed when required for investigations.

Physical testing scope?

Badge tailgating, visitor desk, and device drop tests are examples, only with explicit approval and safety coordination.

Related offerings

Ready to scope this engagement?

Tell us about your environment, timelines, and objectives, we will respond with a tailored proposal.

Contact Evaluris