Social engineering is the testing of company employees for resistance to deception attempts in order to gain access to confidential information and corporate systems.
As part of this service, we carry out phishing mailings, attacks on social networks, voice attacks (vishing), as well as targeted «attacks at the watering hole». These activities make it possible to identify vulnerabilities in employee awareness and assess how vulnerable they may be to social engineering attacks.
We are testing both the response to massive and targeted phishing attacks. Depending on the attack scenario, we can record the opening of emails, clicks on phishing links, data entry on fake portals, and even conduct testing using special software to evaluate the effectiveness of antivirus protection and security settings of end devices.
The client receives a detailed report with information on employee involvement in social engineering attacks, including statistics on opening emails, entering credentials on fake portals and reactions to malicious attachments; assessment of the level of awareness of employees and the security of end devices; and recommendations for training and improving cyber literacy, including suggestions for briefings and courses on information security.