What Is Social Engineering Testing?

by | Jul 7, 2023 | Penetration Testing





Tailgating attack where a person follows another employee through a secured office door








Gophish phishing test dashboard showing results from a social engineering campaign






A literal phishing hook with the word “Password” emphasizes the risk of credential theft






Employees gathered in a modern office discussing cybersecurity awareness







What is social engineering in cybersecurity?

Social engineering refers to tactics that manipulate people into giving up sensitive information or access. It includes phishing, pretexting, vishing, and in-person deception.

Is social engineering testing legal?

Yes, as long as it’s scoped properly and approved by the organization. Professional testing firms work within clearly defined rules of engagement and safety protocols.

What’s the difference between phishing and social engineering testing?

Phishing is one type of social engineering. A full social engineering test may also include voice calls, physical impersonation, and more complex pretexting scenarios.

Do I need to tell employees about the test in advance?

Not usually. Most social engineering tests are conducted without prior employee notice to simulate realistic attacks, though leadership approval is always required.

How much does social engineering testing cost?

Costs vary based on scope and complexity. A simple phishing campaign may cost a few thousand dollars, while full social engineering assessments with physical and phone testing may cost more.


Have any questions?

Fill out the form below

Leading-Edge Penetration Testing

Services