SecureBlockLog inStart a pentest
All servicesSocial Engineering

Measure your human risk layer before attackers exploit it.

Targeted spear-phishing, MFA fatigue, vishing, and pretext campaigns — consent-based exercises that quantify your exposure and give your team real training data.

See a sample report
Consent-based alwaysRole-targeted campaignsAwareness reporting included
What we test

Full coverage, tested by hand.

Every assessment is led by an OSCP- or CREST-certified tester — not a scanner with a human proofreading the output.

Targeted spear-phishing

OSINT-driven campaigns crafted to your employees, roles, and current company events — the way real threat actors target organisations, not generic mass-phishing.

MFA fatigue & push abuse

Test whether MFA push notification fatigue attacks succeed against your employee base, with response rates segmented by department and role.

Vishing (voice phishing)

Phone-based pretexting scenarios — IT helpdesk impersonation, executive fraud, and vendor credential requests — to test voice-channel resilience.

Awareness metrics & reporting

Click rates, credential submission rates, and reporting rates segmented by department and role — actionable data for your security awareness programme.

Methodology

How we run the engagement.

A structured process that ends with a report you can hand directly to your auditor.

1
Consent & scoping

Engagement rules agreed in writing: target list, campaign types, start/end window, and out-of-scope individuals.

2
OSINT & pretext development

Build realistic pretexts from public information: LinkedIn, company website, press releases, and event calendars.

3
Campaign execution

Phishing waves deployed in controlled phases. Real-time dashboard shows click, credential, and reporting metrics.

4
Debrief & training data

Full report with per-department breakdown, scenario recreations, and recommended training materials.

Sample findings

The kind of issues we find.

Real finding types from past engagements — titles and targets anonymised.

highCVSS 7.2SB-SE-001
34% of employees submitted credentials in spear-phishing campaign
Finance & HR departments (87 targets)Week 1
Remediation — Deploy targeted security awareness training for high-click departments. Enforce phishing-resistant MFA (FIDO2) for all users.
highCVSS 6.8SB-SE-002
Helpdesk reset password without verifying caller identity
IT Helpdesk — 3 of 5 calls succeededWeek 1
Remediation — Implement a callback verification procedure for all password resets. Require out-of-band identity confirmation through HR system.
mediumCVSS 5.0SB-SE-003
MFA push fatigue accepted by 12% of targeted users
18 users received repeated push notificationsWeek 2
Remediation — Enable number matching and additional context in MFA push notifications. Consider FIDO2 hardware keys for privileged accounts.
Platform

Findings land live — not in a PDF three weeks later.

Every confirmed issue goes into the platform the moment it's documented. Your team tracks status, chats directly with the tester, and exports evidence without waiting for the engagement to close.

Live findings during testingIssues appear as they are confirmed — no batch delivery at the end.
Direct tester chatComment on any finding and the tester who wrote it responds.
Evidence export on demandOne-click SOC 2, ISO 27001, PCI and HIPAA evidence packs.
app.secureblock.com/projects/social-engineering/vulnerabilities
Projects/Acme Corp — Phishing Simulation
AC
Acme Corp — Phishing Simulation
Start: 12 Jan 2026 · Due: 12 Feb 2026 · Lead tester assigned
In progress
Overview
Vulnerabilities
Scope
Tasks
Reports
Vulnerabilities3
Export evidence
#DateTitleSeverityStatus
0114 Jan34% of employees submitted credentials in spear-phishing campaignhighOpen
0214 JanHelpdesk reset password without verifying caller identityhighRetest requested
0321 JanMFA push fatigue accepted by 12% of targeted usersmediumFix verified
FAQ

Questions about this service.

Still unsure? Ask an engineer in chat — not a sales rep.

Senior leadership is informed; individual employees are not, to ensure realistic results. Post-test we recommend a transparency communication.

Know where you stand before your auditor does.