Skip to content
normSight — Cyber Security

Solutions

Social Engineering Assessment

A social engineering assessment measures how well an organisation's employees withstand phishing and persuasion-based attacks, using controlled scenarios.

No matter how secure an organisation’s network and web systems are, it is equally important that its employees have a certain level of information security awareness. In recent years there have been individuals known as social engineers who exploit human weaknesses and carry out information theft using deception and persuasion. The social engineering assessment emerged from taking the profile and methods of such attackers into account.

In industry terms, in a social engineering attack the attacker carries out a phishing attack in order to use an employee of the organisation for their own purposes. The aim of the attack is to gain unauthorised access, or to join the organisation’s local network from outside and steal information.

If the personnel within an organisation have not received sufficient information security training and their awareness level is not high, encountering social engineering attacks becomes likely. A social engineering assessment should therefore be carried out to determine employee awareness and resilience to phishing attacks.

The assessment is applied as a simulation, within defined scenarios. The stages and methods used may vary. For a staged assessment, the social engineering assessment may involve gathering information, identifying weaknesses, penetrating the system and producing a report. While these stages are applied, phishing may be carried out using a scenario such as a fake human resources page or a fake parcel tracking number.

Frequently Asked Questions

Is the assessment used to single out individual employees?

No. Reporting is done using figures aggregated across the organisation. The aim is not to flag individuals but to measure the level of awareness and show where training is needed.

Are employees told in advance?

The employees being tested are not, because the result would otherwise not reflect reality. Management, IT and, where applicable, the legal department are informed before the work begins and written approval is obtained.

Which scenarios are used?

Depending on the organisation's profile, email phishing, fake login pages, telephone-based information gathering (vishing) and physical access attempts can be planned. Scenarios are agreed with the organisation before the work starts.

See the real risks in your systems.

Talk to our team about a penetration test or training plan that fits your scope.