Social Engineering Assessments

Controlled assessments evaluating organisational resilience to targeted manipulation techniques including phishing, vishing, and physical security.

4
Assessment Types
Controlled
Authorised Testing
Portal
Managed Delivery

Select a Service

Email Phishing

The Email Phishing Security Assessment evaluates an organisation’s exposure to phishing attacks delivered via email, focusing on both technical controls and user susceptibility.

Email Phishing Credential Harvesting Awareness Campaigns
View details →

Smishing (SMS Phishing)

The Smishing (SMS Phishing) Security Assessment evaluates an organisation’s exposure to phishing attacks delivered via SMS and mobile messaging platforms.

SMS Phishing Mobile Pretexting Campaigns
View details →

Vishing (Telephone Phishing)

The Vishing (Telephone Phishing) Security Assessment evaluates an organisation’s exposure to social engineering attacks conducted via telephone communications.

Telephone Social Engineering Voice Pretexting Scenarios
View details →

Physical

The Physical Security Assessment evaluates the effectiveness of physical controls designed to protect facilities, assets, and personnel from unauthorised access or interference.

Physical Access Control Tailgating Badge Cloning Site Assessment
View details →
Portal Access
Detailed Reporting
Remediation Guidance
Direct Communication
Attestation Letters

Standards applied

Social engineering assessments follow the Penetration Testing Execution Standard (PTES) for engagement structure and NIST SP 800-115 for the overall assessment process, under explicit written authorisation and agreed rules of engagement.

Risk rating CVSS v4.0, mapped to CWE
Quality assurance Independently reviewed before release, never by the consultant who wrote it

All services are delivered subject to formal scoping, contractual agreement, and explicit authorisation.

Get in Touch

If you would like to discuss an assessment or understand how Nanorisk can support your organisation, please get in touch.