Human-Layer Security Testing

Social Engineering Testing Test the People, Not Just the Firewall

Social engineering testing is an authorized, controlled simulation of the manipulation tactics real attackers use - phishing emails, phone pretexting, malicious USB drops, and physical tailgating - measured against your own staff to reveal how a live attacker would talk their way past your controls. It answers a question no vulnerability scanner can: when someone convincing asks an employee to click, pay, or open a door, what actually happens? Petronella Technology Group, Inc. has run these engagements for regulated Raleigh and Triangle businesses since 2002, then turned every result into training that closes the gap.

NC Licensed Digital Forensics Examiner/ CyberAB Registered Provider Organization #1449/ BBB A+ Rated Since 2003

Key Takeaways

  • Social engineering testing measures the human layer of security the way a penetration test measures the technical layer: through authorized, in-scope simulated attacks with written rules of engagement, not real harm.
  • A complete program covers five vectors: email phishing, voice pretexting (vishing), SMS phishing (smishing), physical intrusion, and media drops. Testing only email leaves four open doors.
  • The click rate is the least useful number. What matters is the report rate, the time to first report, and whether a click led to credential capture or lateral movement.
  • Compliance frameworks including CMMC 2.0, HIPAA, PCI DSS, and the FTC Safeguards Rule expect ongoing awareness testing, not a one-time exercise.
  • A test with no follow-up training is a wasted engagement. Petronella Technology Group pairs every simulation with targeted security awareness training so the result improves the next result.

Before You Send the First Fake Email

Social engineering testing only produces trustworthy data when it is authorized in writing, scoped to named populations, and coordinated so that a real incident during the test window is never confused with the simulation. Petronella Technology Group runs every engagement under a signed rules-of-engagement document that names the vectors in play, the test window, the escalation contact, and an explicit stop condition. That paperwork is what separates a professional assessment from an action that damages trust with your own staff.

Definition

What Is Social Engineering Testing?

A plain answer before the detail.

Social engineering testing is the practice of safely imitating the psychological manipulation techniques criminals use, in order to measure how an organization's people respond and to prove where awareness training needs to go next. Where a penetration test attacks software, configuration, and network exposure, a social engineering test attacks the decision a human makes when a message feels urgent, an authority figure asks a favor, or a stranger holds a door. The two disciplines are complementary halves of the same question: can an outsider get in?

The engagement is authorized, bounded, and observed. Testers work from a written scope, they do not exfiltrate real regulated data, and they record what happened rather than exploiting it. The deliverable is not a list of embarrassed employees. It is a measurement - how many people were reached, how many acted, how quickly the first person raised the alarm, and which specific pretexts worked - alongside a plan to move those numbers.

Social Engineering Testing vs Phishing Simulation vs Penetration Testing

These three terms overlap and get used loosely, which causes businesses to buy one and assume they covered the others. A phishing simulation is the email-only subset: scheduled, benign lures sent to staff to measure click and report behavior over time. Social engineering testing is the broader discipline that adds voice, text, physical, and media vectors and often a specific target objective. Penetration testing is the technical assault on systems, which may include a social engineering component when the rules of engagement allow it. A mature program runs all three on different cadences: continuous phishing simulation, periodic full social engineering assessment, and annual or event-driven penetration testing.

Attack Vectors

The Five Vectors a Complete Test Covers

Attackers do not limit themselves to email, and neither should an assessment that claims to model real risk.

1. Email Phishing

The highest-volume vector and the one most organizations already test. Effective phishing assessment goes beyond a generic "your password expired" template. Petronella Technology Group builds pretexts from public reconnaissance - a vendor your team actually uses, an internal announcement style, a seasonal event such as open enrollment or a fiscal year close - because a lure that looks plausible produces data that reflects real risk. Credential-harvesting landing pages capture whether a click became a submitted password without ever storing the real credential.

2. Voice Pretexting (Vishing)

A phone call remains one of the most effective attacks because it carries urgency and authority that email cannot. A tester posing as the help desk, a bank, or a senior executive walks a target through a pretext designed to extract a password reset, a wire approval, or a multi-factor code. Business email compromise increasingly pivots to the phone precisely because so many organizations trained their staff on email and left the phone untouched.

3. SMS Phishing (Smishing)

Text messages bypass the email security stack entirely and land on personal devices where corporate controls do not reach. A smishing test measures whether staff will tap a link or reply to a text impersonating a delivery service, a payroll system, or the IT department. This vector has grown sharply as attackers exploit the trust people place in their phones.

4. Physical Intrusion

Tailgating through a badge-controlled door, presenting a fabricated visitor pretext at reception, or plugging into an open network jack in a conference room tests the controls a technical scan can never see. Physical social engineering is scoped carefully, always with an authorization letter the tester carries, and it reveals gaps that no amount of email training will close.

5. Media Drops

A USB device left in a parking lot or lobby, labeled to invite curiosity, measures whether a found device gets plugged into a corporate machine. The test payload does no harm - it phones home to record that the device was opened - but a real one would establish a foothold inside the network. This classic technique still works, which is exactly why it belongs in the assessment.

Methodology

How a Social Engineering Test Is Run

Six stages that turn a simulated attack into a defensible measurement.

1

Scope and Authorization

Every engagement starts with a written rules-of-engagement document: the vectors in play, the target population, the test window, the objective, the escalation contact, and the stop condition. Nothing is sent, called, or attempted until that authorization is signed. This is the step that protects both the organization and its staff.

2

Reconnaissance

Testers gather the same open-source intelligence a real attacker would use: employee names and roles from public sources, the vendors and tools your organization references publicly, email naming conventions, and the events that make a plausible pretext. The quality of this stage determines whether the test models a real threat or a generic one.

3

Pretext Development

Each vector gets a tailored scenario. Petronella Technology Group builds pretexts that mirror the attacks the organization is actually likely to face, informed by Craig Petronella's forensic casework on how real breaches began. A defense contractor sees a supply-chain lure; a medical practice sees a patient-records or insurance pretext.

4

Controlled Execution

The simulated attacks run inside the agreed window, monitored so that any genuine incident is never mistaken for the test. Actions are recorded, not exploited: a captured credential is logged and discarded, a plugged-in device beacons and does nothing more, an opened door is noted and the tester leaves.

5

Measurement and Analysis

Results are scored on metrics that predict real risk: reach, action rate, report rate, time to first report, and depth of compromise. The analysis identifies which pretexts, departments, and channels represent the highest exposure, and it distinguishes a lucky miss from a genuine control.

6

Debrief and Training

The engagement ends with a report leadership can act on and targeted training for the people and teams that need it. The debrief is deliberately non-punitive, because a program that shames staff teaches them to hide mistakes rather than report them - the opposite of the goal.

Metrics

The Numbers That Actually Matter

Click rate makes a dramatic headline and a poor security metric. These are the measurements that tell you whether your human layer is improving.

MetricWhat It MeasuresWhy It Matters More Than Click Rate
Report rateShare of recipients who reported the attempt to IT or securityA high report rate means the organization detects attacks in progress. This is the single best predictor of resilience.
Time to first reportMinutes between the attack landing and the first alarm raisedReal attacks are stopped by early reporting. A fast first report can contain an incident before credentials are used.
Action rateShare who clicked, called back, replied, or plugged inMore honest than raw clicks because it spans every vector, not just email.
Depth of compromiseWhether an action led to captured credentials, a beacon, or building accessA click that hits a warning page is very different from one that submitted a password. Depth separates the two.
Repeat-responder concentrationWhether the same individuals act across multiple testsTargeted coaching for a small group often moves the whole organization's risk more than broad training.

"Petronella Cybersecurity provides outstanding service! Their team is extremely knowledgeable, responsive, and truly cares about protecting their clients. They take the time to explain complex issues in simple terms and deliver real solutions, not just promises."

GB Entrainement, verified TrustIndex review
Compliance

Social Engineering Testing and Compliance

Awareness testing is not optional for regulated organizations. Several frameworks expect it as an ongoing control.

Defense Contractors and CMMC 2.0

CMMC 2.0 and the underlying NIST SP 800-171 controls require security awareness and training that recognizes social engineering and the indicators of insider and outsider threats. A documented testing program produces the evidence a C3PAO assessor looks for. As Craig Petronella, a CMMC Registered Practitioner and author of the CMMC 2.0 Certification Guide, structures these engagements, the test results become part of the assessment evidence rather than a separate exercise. Petronella Technology Group is a CyberAB Registered Provider Organization, #1449.

Healthcare and HIPAA

The HIPAA Security Rule requires a security awareness program, and social engineering is the mechanism behind most protected-health-information breaches. Testing gives a medical practice defensible proof that its workforce training is real and measured, not a binder on a shelf. Craig Petronella is the author of How HIPAA Can Crush Your Medical Practice and an NC Licensed Digital Forensics Examiner who has investigated healthcare breaches directly.

PCI DSS, the FTC Safeguards Rule, and Everyone Else

Payment-handling businesses under PCI DSS and financial-adjacent firms under the FTC Safeguards Rule both carry awareness-training obligations that a testing program satisfies with evidence. For any organization, the business case is simpler than the regulation: business email compromise and credential phishing remain among the most common and most expensive incidents, and the human layer is where they succeed or fail.

Common Mistakes

Five Ways Social Engineering Programs Go Wrong

Patterns Petronella Technology Group sees when businesses run testing without a plan behind it.

Testing Email and Nothing Else

The most common gap. An organization runs quarterly phishing simulations, reports a falling click rate, and believes it is covered - while the phone, text, physical, and media vectors have never been touched. Attackers move to the untested channel. A program that only measures email measures one fifth of the exposure.

Optimizing for a Low Click Rate

When leadership rewards a low click number, the pressure is to send easy lures. That produces flattering reports and no security improvement. The right target is a high report rate against realistic pretexts, which sometimes means the click rate goes up before it comes down.

Punishing the People Who Fail

Naming and shaming employees who clicked teaches the workforce to conceal mistakes. The behavior a program most needs to encourage - fast reporting of a suspected attack - dies the moment reporting feels dangerous. Testing must be non-punitive to work.

Testing Once and Declaring Victory

A single assessment is a snapshot, and awareness decays. New staff arrive untrained, attack techniques evolve, and last year's result says nothing about this year's risk. Testing has to be a recurring program tied to onboarding and to the threat landscape.

Running the Test With No Training Behind It

The result of a test is only valuable if it changes what happens next. A report that identifies a weak department and is never followed by security awareness training for that department is a diagnosis with no treatment. The test and the training are one system.

Our Approach

How Petronella Technology Group Runs the Engagement

Petronella Technology Group, Inc. has secured regulated Raleigh, Durham, and Triangle businesses since 2002, and social engineering testing sits inside a larger security practice rather than standing alone as a one-off product. That matters because the test result feeds directly into the controls that reduce the risk it exposed: a weak reporting rate leads to security awareness training, a captured credential leads to hardened authentication and Managed XDR monitoring, and a physical gap leads to a facilities conversation. The company is a CyberAB Registered Provider Organization, #1449, and BBB A+ rated since 2003.

Every engagement is led with the perspective of Craig Petronella, an MIT-certified cybersecurity professional, cybersecurity expert witness, and NC Licensed Digital Forensics Examiner whose forensic casework informs the pretexts. As Craig details in How Hackers Can Crush Your Business, the majority of real intrusions begin not with a technical exploit but with a person persuaded to do something ordinary. The testing program is built to find those moments before an attacker does. For organizations that want to combine human-layer testing with a technical assessment, the same team runs network penetration testing and a full cybersecurity tabletop exercise so leadership can rehearse the response as well as measure the exposure.

The output is written for two audiences. Technical staff get the vector-by-vector detail: which pretexts landed, which credentials were captured, which controls held. Leadership gets the business view: where the organization stands, how it compares to the last assessment, and the specific, sequenced actions that will move the numbers. No jargon dump, no shame, no binder that never gets opened.

FAQ

Social Engineering Testing Questions, Answered

What is social engineering testing?
Social engineering testing is an authorized, controlled simulation of the manipulation techniques attackers use - phishing, voice pretexting, SMS phishing, physical intrusion, and media drops - run against an organization's own staff to measure how people respond and to direct security awareness training. It tests the human layer of security the way a penetration test measures the technical layer, and it is always conducted under a signed rules-of-engagement document rather than as a surprise.
How is social engineering testing different from a phishing simulation?
A phishing simulation is the email-only subset of social engineering testing: scheduled, benign lures sent to staff to track click and report rates over time. Social engineering testing is the broader discipline that also covers voice pretexting, SMS phishing, physical intrusion, and media drops, and it often carries a specific objective such as reaching a target system. Most organizations should run continuous phishing simulation and periodic full social engineering assessments together.
Is social engineering testing legal and safe for my staff?
Yes, when it is done properly. Every Petronella Technology Group engagement runs under a written authorization that names the vectors, the target population, the test window, and a stop condition. Testers do not exfiltrate real regulated data, captured credentials are logged and discarded rather than used, and the debrief is deliberately non-punitive so staff are encouraged to report rather than fear being caught. The paperwork and the professional conduct are what make it safe.
How often should we run social engineering tests?
Phishing simulation should be continuous, typically monthly, because awareness decays and new staff arrive untrained. A broader social engineering assessment covering multiple vectors is usually run once or twice a year, and again after a significant change such as a merger, a new office, or a shift in the threat landscape. Compliance frameworks including CMMC 2.0 and HIPAA treat awareness testing as an ongoing control, not a one-time event.
What metrics should we care about in the results?
The report rate and the time to first report matter most, because early reporting is what stops a real attack. Action rate across all vectors, depth of compromise (did a click actually submit a credential or establish a foothold), and whether the same individuals respond repeatedly are the other measurements worth tracking. The raw click rate is the weakest metric and the easiest to game with soft lures.
Does social engineering testing help with CMMC or HIPAA compliance?
Yes. CMMC 2.0 and NIST SP 800-171 require security awareness and training that addresses social engineering, and the HIPAA Security Rule requires an awareness program. A documented testing program with results and follow-up training produces the evidence assessors expect. Petronella Technology Group is a CyberAB Registered Provider Organization, #1449, and Craig Petronella is a CMMC Registered Practitioner and NC Licensed Digital Forensics Examiner.
What happens to employees who fail a test?
Nothing punitive. A program that punishes staff for clicking teaches them to hide mistakes, which is the opposite of what security needs. Petronella Technology Group uses results to direct targeted, supportive training to the people and departments that need it most, and measures whether the next test improves. The behavior the program most wants to build is fast reporting, and that only grows in a non-punitive environment.
Can you combine social engineering testing with a penetration test?
Yes, and it is often the most realistic approach. A real attacker uses social engineering to gain an initial foothold and then pivots technically, so combining human-layer testing with network penetration testing models the full attack path. The same Petronella Technology Group team runs both, along with a cybersecurity tabletop exercise to rehearse the response, so the engagement measures exposure and readiness together.

Test the Human Layer Before an Attacker Does

Most breaches begin with a person, not a firewall. A social engineering test from Petronella Technology Group measures where your organization stands and gives you the training plan to improve it - under written authorization, without shaming your staff.

Petronella Technology Group, Inc. · 5540 Centerview Dr., Suite 200, Raleigh, NC 27606 · 919-348-4912

Last Updated: August 12, 2026