Social Engineering Testing Test the People, Not Just the Firewall
Social engineering testing is an authorized, controlled simulation of the manipulation tactics real attackers use - phishing emails, phone pretexting, malicious USB drops, and physical tailgating - measured against your own staff to reveal how a live attacker would talk their way past your controls. It answers a question no vulnerability scanner can: when someone convincing asks an employee to click, pay, or open a door, what actually happens? Petronella Technology Group, Inc. has run these engagements for regulated Raleigh and Triangle businesses since 2002, then turned every result into training that closes the gap.
Key Takeaways
- Social engineering testing measures the human layer of security the way a penetration test measures the technical layer: through authorized, in-scope simulated attacks with written rules of engagement, not real harm.
- A complete program covers five vectors: email phishing, voice pretexting (vishing), SMS phishing (smishing), physical intrusion, and media drops. Testing only email leaves four open doors.
- The click rate is the least useful number. What matters is the report rate, the time to first report, and whether a click led to credential capture or lateral movement.
- Compliance frameworks including CMMC 2.0, HIPAA, PCI DSS, and the FTC Safeguards Rule expect ongoing awareness testing, not a one-time exercise.
- A test with no follow-up training is a wasted engagement. Petronella Technology Group pairs every simulation with targeted security awareness training so the result improves the next result.
Before You Send the First Fake Email
Social engineering testing only produces trustworthy data when it is authorized in writing, scoped to named populations, and coordinated so that a real incident during the test window is never confused with the simulation. Petronella Technology Group runs every engagement under a signed rules-of-engagement document that names the vectors in play, the test window, the escalation contact, and an explicit stop condition. That paperwork is what separates a professional assessment from an action that damages trust with your own staff.
What Is Social Engineering Testing?
A plain answer before the detail.
Social engineering testing is the practice of safely imitating the psychological manipulation techniques criminals use, in order to measure how an organization's people respond and to prove where awareness training needs to go next. Where a penetration test attacks software, configuration, and network exposure, a social engineering test attacks the decision a human makes when a message feels urgent, an authority figure asks a favor, or a stranger holds a door. The two disciplines are complementary halves of the same question: can an outsider get in?
The engagement is authorized, bounded, and observed. Testers work from a written scope, they do not exfiltrate real regulated data, and they record what happened rather than exploiting it. The deliverable is not a list of embarrassed employees. It is a measurement - how many people were reached, how many acted, how quickly the first person raised the alarm, and which specific pretexts worked - alongside a plan to move those numbers.
Social Engineering Testing vs Phishing Simulation vs Penetration Testing
These three terms overlap and get used loosely, which causes businesses to buy one and assume they covered the others. A phishing simulation is the email-only subset: scheduled, benign lures sent to staff to measure click and report behavior over time. Social engineering testing is the broader discipline that adds voice, text, physical, and media vectors and often a specific target objective. Penetration testing is the technical assault on systems, which may include a social engineering component when the rules of engagement allow it. A mature program runs all three on different cadences: continuous phishing simulation, periodic full social engineering assessment, and annual or event-driven penetration testing.
The Five Vectors a Complete Test Covers
Attackers do not limit themselves to email, and neither should an assessment that claims to model real risk.
1. Email Phishing
The highest-volume vector and the one most organizations already test. Effective phishing assessment goes beyond a generic "your password expired" template. Petronella Technology Group builds pretexts from public reconnaissance - a vendor your team actually uses, an internal announcement style, a seasonal event such as open enrollment or a fiscal year close - because a lure that looks plausible produces data that reflects real risk. Credential-harvesting landing pages capture whether a click became a submitted password without ever storing the real credential.
2. Voice Pretexting (Vishing)
A phone call remains one of the most effective attacks because it carries urgency and authority that email cannot. A tester posing as the help desk, a bank, or a senior executive walks a target through a pretext designed to extract a password reset, a wire approval, or a multi-factor code. Business email compromise increasingly pivots to the phone precisely because so many organizations trained their staff on email and left the phone untouched.
3. SMS Phishing (Smishing)
Text messages bypass the email security stack entirely and land on personal devices where corporate controls do not reach. A smishing test measures whether staff will tap a link or reply to a text impersonating a delivery service, a payroll system, or the IT department. This vector has grown sharply as attackers exploit the trust people place in their phones.
4. Physical Intrusion
Tailgating through a badge-controlled door, presenting a fabricated visitor pretext at reception, or plugging into an open network jack in a conference room tests the controls a technical scan can never see. Physical social engineering is scoped carefully, always with an authorization letter the tester carries, and it reveals gaps that no amount of email training will close.
5. Media Drops
A USB device left in a parking lot or lobby, labeled to invite curiosity, measures whether a found device gets plugged into a corporate machine. The test payload does no harm - it phones home to record that the device was opened - but a real one would establish a foothold inside the network. This classic technique still works, which is exactly why it belongs in the assessment.
How a Social Engineering Test Is Run
Six stages that turn a simulated attack into a defensible measurement.
Scope and Authorization
Every engagement starts with a written rules-of-engagement document: the vectors in play, the target population, the test window, the objective, the escalation contact, and the stop condition. Nothing is sent, called, or attempted until that authorization is signed. This is the step that protects both the organization and its staff.
Reconnaissance
Testers gather the same open-source intelligence a real attacker would use: employee names and roles from public sources, the vendors and tools your organization references publicly, email naming conventions, and the events that make a plausible pretext. The quality of this stage determines whether the test models a real threat or a generic one.
Pretext Development
Each vector gets a tailored scenario. Petronella Technology Group builds pretexts that mirror the attacks the organization is actually likely to face, informed by Craig Petronella's forensic casework on how real breaches began. A defense contractor sees a supply-chain lure; a medical practice sees a patient-records or insurance pretext.
Controlled Execution
The simulated attacks run inside the agreed window, monitored so that any genuine incident is never mistaken for the test. Actions are recorded, not exploited: a captured credential is logged and discarded, a plugged-in device beacons and does nothing more, an opened door is noted and the tester leaves.
Measurement and Analysis
Results are scored on metrics that predict real risk: reach, action rate, report rate, time to first report, and depth of compromise. The analysis identifies which pretexts, departments, and channels represent the highest exposure, and it distinguishes a lucky miss from a genuine control.
Debrief and Training
The engagement ends with a report leadership can act on and targeted training for the people and teams that need it. The debrief is deliberately non-punitive, because a program that shames staff teaches them to hide mistakes rather than report them - the opposite of the goal.
The Numbers That Actually Matter
Click rate makes a dramatic headline and a poor security metric. These are the measurements that tell you whether your human layer is improving.
| Metric | What It Measures | Why It Matters More Than Click Rate |
|---|---|---|
| Report rate | Share of recipients who reported the attempt to IT or security | A high report rate means the organization detects attacks in progress. This is the single best predictor of resilience. |
| Time to first report | Minutes between the attack landing and the first alarm raised | Real attacks are stopped by early reporting. A fast first report can contain an incident before credentials are used. |
| Action rate | Share who clicked, called back, replied, or plugged in | More honest than raw clicks because it spans every vector, not just email. |
| Depth of compromise | Whether an action led to captured credentials, a beacon, or building access | A click that hits a warning page is very different from one that submitted a password. Depth separates the two. |
| Repeat-responder concentration | Whether the same individuals act across multiple tests | Targeted coaching for a small group often moves the whole organization's risk more than broad training. |
"Petronella Cybersecurity provides outstanding service! Their team is extremely knowledgeable, responsive, and truly cares about protecting their clients. They take the time to explain complex issues in simple terms and deliver real solutions, not just promises."
GB Entrainement, verified TrustIndex reviewSocial Engineering Testing and Compliance
Awareness testing is not optional for regulated organizations. Several frameworks expect it as an ongoing control.
Defense Contractors and CMMC 2.0
CMMC 2.0 and the underlying NIST SP 800-171 controls require security awareness and training that recognizes social engineering and the indicators of insider and outsider threats. A documented testing program produces the evidence a C3PAO assessor looks for. As Craig Petronella, a CMMC Registered Practitioner and author of the CMMC 2.0 Certification Guide, structures these engagements, the test results become part of the assessment evidence rather than a separate exercise. Petronella Technology Group is a CyberAB Registered Provider Organization, #1449.
Healthcare and HIPAA
The HIPAA Security Rule requires a security awareness program, and social engineering is the mechanism behind most protected-health-information breaches. Testing gives a medical practice defensible proof that its workforce training is real and measured, not a binder on a shelf. Craig Petronella is the author of How HIPAA Can Crush Your Medical Practice and an NC Licensed Digital Forensics Examiner who has investigated healthcare breaches directly.
PCI DSS, the FTC Safeguards Rule, and Everyone Else
Payment-handling businesses under PCI DSS and financial-adjacent firms under the FTC Safeguards Rule both carry awareness-training obligations that a testing program satisfies with evidence. For any organization, the business case is simpler than the regulation: business email compromise and credential phishing remain among the most common and most expensive incidents, and the human layer is where they succeed or fail.
Five Ways Social Engineering Programs Go Wrong
Patterns Petronella Technology Group sees when businesses run testing without a plan behind it.
Testing Email and Nothing Else
The most common gap. An organization runs quarterly phishing simulations, reports a falling click rate, and believes it is covered - while the phone, text, physical, and media vectors have never been touched. Attackers move to the untested channel. A program that only measures email measures one fifth of the exposure.
Optimizing for a Low Click Rate
When leadership rewards a low click number, the pressure is to send easy lures. That produces flattering reports and no security improvement. The right target is a high report rate against realistic pretexts, which sometimes means the click rate goes up before it comes down.
Punishing the People Who Fail
Naming and shaming employees who clicked teaches the workforce to conceal mistakes. The behavior a program most needs to encourage - fast reporting of a suspected attack - dies the moment reporting feels dangerous. Testing must be non-punitive to work.
Testing Once and Declaring Victory
A single assessment is a snapshot, and awareness decays. New staff arrive untrained, attack techniques evolve, and last year's result says nothing about this year's risk. Testing has to be a recurring program tied to onboarding and to the threat landscape.
Running the Test With No Training Behind It
The result of a test is only valuable if it changes what happens next. A report that identifies a weak department and is never followed by security awareness training for that department is a diagnosis with no treatment. The test and the training are one system.
How Petronella Technology Group Runs the Engagement
Petronella Technology Group, Inc. has secured regulated Raleigh, Durham, and Triangle businesses since 2002, and social engineering testing sits inside a larger security practice rather than standing alone as a one-off product. That matters because the test result feeds directly into the controls that reduce the risk it exposed: a weak reporting rate leads to security awareness training, a captured credential leads to hardened authentication and Managed XDR monitoring, and a physical gap leads to a facilities conversation. The company is a CyberAB Registered Provider Organization, #1449, and BBB A+ rated since 2003.
Every engagement is led with the perspective of Craig Petronella, an MIT-certified cybersecurity professional, cybersecurity expert witness, and NC Licensed Digital Forensics Examiner whose forensic casework informs the pretexts. As Craig details in How Hackers Can Crush Your Business, the majority of real intrusions begin not with a technical exploit but with a person persuaded to do something ordinary. The testing program is built to find those moments before an attacker does. For organizations that want to combine human-layer testing with a technical assessment, the same team runs network penetration testing and a full cybersecurity tabletop exercise so leadership can rehearse the response as well as measure the exposure.
The output is written for two audiences. Technical staff get the vector-by-vector detail: which pretexts landed, which credentials were captured, which controls held. Leadership gets the business view: where the organization stands, how it compares to the last assessment, and the specific, sequenced actions that will move the numbers. No jargon dump, no shame, no binder that never gets opened.
Social Engineering Testing Questions, Answered
What is social engineering testing?
How is social engineering testing different from a phishing simulation?
Is social engineering testing legal and safe for my staff?
How often should we run social engineering tests?
What metrics should we care about in the results?
Does social engineering testing help with CMMC or HIPAA compliance?
What happens to employees who fail a test?
Can you combine social engineering testing with a penetration test?
Test the Human Layer Before an Attacker Does
Most breaches begin with a person, not a firewall. A social engineering test from Petronella Technology Group measures where your organization stands and gives you the training plan to improve it - under written authorization, without shaming your staff.
Petronella Technology Group, Inc. · 5540 Centerview Dr., Suite 200, Raleigh, NC 27606 · 919-348-4912
Last Updated: August 12, 2026