Skip to content

Social Engineering and Phishing Testing

 

Learn about phishing simulations vs full engagements, vishing testing, pretexting attacks, using results to improve security awareness, and much more, through the Frequently Asked Questions (FAQs) below. Please schedule a consultation if you are looking for Penetration Testing for compliance or regulatory requirements or to comply with a global security standard.. 

Table of Contents

What is a phishing simulation and how does it differ from a full social engineering test? 

 

A phishing simulation is a controlled exercise in which the penetration testing team sends realistic but fake phishing emails to an organization’s employees to measure how many recipients click malicious links, open attachments, submit credentials, or take other actions the phishing email requests, all without any actual malicious payload being delivered. Phishing simulations measure click rates, credential submission rates, and report rates, and the results are used to identify employees who need additional security awareness training and to assess the overall human vulnerability of the organization. A full social engineering test is broader and more sophisticated, it may combine phishing with vishing (phone calls), pretexting (fabricated scenarios), in-person impersonation, and physical access attempts, all designed to achieve a specific objective such as gaining insider credentials or physical access to a restricted area. A phishing simulation measures susceptibility to one specific attack type; a full social engineering test simulates the multi-channel manipulation techniques used by real threat actors, including those conducting business email compromise (BEC) and spear-phishing campaigns against specific high-value targets.

 

What is vishing (voice phishing) testing in a pen test? 

 

Vishing (voice phishing) testing is a social engineering technique used in penetration tests that involves placing phone calls to employees while posing as a trusted authority, such as an IT help desk technician, vendor, auditor, or senior executive, to manipulate them into revealing sensitive information, resetting passwords without proper verification, or performing actions that compromise security. Real attackers use vishing extensively for business email compromise (BEC) fraud, SIM swapping attacks, and corporate espionage. A vishing test in a penetration engagement evaluates whether employees follow secure identity verification procedures before providing sensitive information or taking security-affecting actions over the phone. Testers document call outcomes, the specific information disclosed, and the security failures that enabled the manipulation. Results inform security awareness training and help organizations improve identity verification procedures for sensitive phone-based requests, particularly in IT help desk and finance department contexts where vishing is most commonly exploited.

 

What is a pretexting attack and how is it simulated? 

 

A pretexting attack is a social engineering technique in which the attacker fabricates a convincing false identity, scenario, or context, called the “pretext”, to manipulate a target into providing information, credentials, or access they would not otherwise grant. Common pretexts include impersonating an IT administrator conducting a system upgrade, a vendor representative needing network access for maintenance, a new employee asking for help with an account setup, or an executive requesting an urgent wire transfer. Pretexting attacks are notable for their sophistication, attackers often research their targets using OSINT to make the pretext credible, referencing real names, internal projects, or corporate events to build trust. In a penetration test, pretexting is simulated by creating a realistic scenario aligned with the client’s organizational context, then testing whether employees follow security procedures, such as identity verification, multi-step approval workflows, or callback verification, when confronted with an urgent-seeming request from an apparently legitimate authority. 

 

How should an organization use social engineering test results to improve security? 

 

Social engineering test results should be used as a data-driven foundation for a targeted, measured security awareness improvement program rather than as a mechanism for shaming or penalizing employees. After a social engineering test, the organization should first analyze the results: which departments had the highest click or compliance rates, which pretexts were most effective, and which specific behaviors (clicking links, submitting credentials, holding doors) were most common. These findings should inform tailored security awareness training focused on the specific scenarios that failed (rather than generic annual training modules), targeted phishing awareness exercises with more frequent exposure for high-risk departments and individuals, improvements to policies and verification procedures (such as requiring callback verification for password resets), and technical controls that reduce the attack surface (such as email authentication via DMARC, DKIM, and SPF to reduce phishing delivery). Metrics should be tracked over time: organizations that measure phishing click rates before and after training interventions consistently demonstrate measurable improvement, providing a concrete ROI demonstration for security awareness programs.

 

Explore Blogs, Webinars and other Resources

Trusted by Reputed Companies

pVerify, Inc.
Electronic Data Solutions
Bernard Robinson & Company
Avance Care
iCliniq
Botsplash
Logically
Mr.Internet Systems
Vision Radiology
Tangible Solutions
Tangible Solutions
WorkSmart
Triyam
Med First Primary and Urgent Care
Arizona State Radiology
DataCaliper
Dose Spot Company Logo
DoseSpot
Forsyte I.T. Solutions
Tego Data

Accreditations and Associations

* Disclaimer: This list of accreditations is held by our team of employees and consultants.

What Our Clients Say

We used databrackets (formerly EHR 2.0) in our small medical practice for our risk analysis assessment to be in compliance with meaningful use. Their response was fast, the final report is detailed but simple and easy to follow. They were always available to answer our questions.
E. Compres
Pulmonary and Sleep Center of the Valley
I never miss the opportunity to learn something new …that’s why I am always registering to all free seminars offered on the web. databrackets (formerly EHR 2.0) happened to be the friendliest, comprehensive and up-to- date source of HIPAA Privacy and Security updates.
Alexandra V.
Community Healthcare Network
Today’s presentation was great! Thank you for sending the slides. My only feedback is that it would be fabulous to have the slides ahead of time so I could print them and take notes on the slides.Thanks for your time and knowledge today!
T.B., PM
Community Health Network
Particularly interesting was the flow chart on Administrative Simplification. I utilize all of the Security subcategories you list under the Security tile and appreciate knowing that I am hitting all of the relevant topics during my employee training.
Jessica B.
JD, CHC
I have re-worked our original risk assessment….We are using databrackets' (formerly EHR 2.0) Meaningful Use Security Risk Analysis Toolkit and it meets our needs. It was easy to use and I believe that it very beneficial to our meeting meaningful use.
Bill Curtis
Neurosurgical Associates Of Texarkana, TX
Information (webinars) presented by databrackets (formerly EHR 2.0) highlights some of today’s most demanding healthcare topics. The webinars help to direct those operating in today’s rapidly changing environment in the right direction.
Candace M.
Privacy and Security Officer, Springhill Medical Center

Our Growing List of Credentials

0 +
Assessments
0 +
Clients
0 +
Assessment Libraries
0 +
Years of Experience
0 +
No. of Staff Trained
0 +
HIPAA
0 +
SOC 2 Readiness
0 +
Pen Testing
0 +
ISO 27001 Certifications
0 +
Dollars Saved in Compliance Penalties