Penetration Testing

Social engineering penetration testing that tests the human firewall.

Your people are the primary target. SubRosa safely simulates the multi-channel campaigns real attackers run, phishing, vishing, smishing, and on-site pretexting, to measure how your team detects, reports, and resists them.

Phishing · Vishing · Smishing · Pretexting · Tailgating

Social engineering testing, defined

What is social engineering penetration testing?

Social engineering penetration testing safely simulates the manipulation attacks real adversaries use to trick people into granting access or giving up information: phishing emails, vishing calls, smishing texts, and physical pretexting. Rather than blaming users, it measures how well your detection, reporting, and verification controls hold up, and turns the results into targeted awareness improvements.

What we simulate

Every channel an attacker uses.

We test across all the channels and scenarios real attackers exploit.

Phishing campaigns

Realistic spear-phishing built from OSINT and pretexts tailored to your organization, testing detection, judgment, and reporting workflows.

Vishing & smishing

Voice and SMS attacks that probe identity verification, help-desk protocols, and how employees respond to phone and text threats.

On-site pretexting

Physical pretexting, tailgating, and USB-drop scenarios that test lobby, badge, and escort controls the way a real intruder would.

Reporting & response

We assess the full chain, detection, reporting, escalation, and verification, so you learn where the process breaks, not just who clicked.

How the engagement runs

Run safely, measured honestly.

Social engineering testing can damage trust if it is run carelessly. The design decisions that prevent that matter as much as the techniques.

  1. 01

    Scoping and ethical boundaries

    We agree targets, channels and — importantly — what is off limits. Pretexts exploiting bereavement, medical circumstances, redundancy fears or payroll problems are excluded by default. A test that leaves staff feeling humiliated damages the security culture it was meant to measure.

  2. 02

    Open-source reconnaissance

    We build the picture an attacker would: staff names and roles from public sources, email format, org structure, suppliers, recent announcements. This is also a finding in itself — organisations are often unaware how much is publicly assembled.

  3. 03

    Pretext development

    Generic phishing templates measure very little. We build pretexts specific to your organisation: a real supplier, a genuine internal system, a plausible current event. That is what an actual attacker invests in, so it is what a meaningful test uses.

  4. 04

    Campaign execution

    Campaigns run across the agreed channels — email, voice, SMS, and on-site pretexting where in scope — with activity paced to resemble a real operation rather than arriving in one obvious burst.

  5. 05

    Measuring what matters

    Click rate is the least useful number. What matters is credential submission, whether anyone reported it, how quickly, and whether your security team detected and responded. An organisation with a high click rate and fast reporting is in better shape than the reverse.

  6. 06

    Reporting and awareness debrief

    Results are reported in aggregate rather than as a list of individuals to blame. Findings feed directly into awareness training priorities, and we debrief so the outcome is a better-prepared team rather than a disciplinary exercise.

Why SubRosa

Realistic, not punitive.

Multi-channel campaigns

Real attacks blend email, phone, and physical vectors. We simulate them together to expose the gaps a single-channel test would miss.

OSINT-driven realism

Pretexts are built from real open-source intelligence about your organization, so the test reflects what a motivated attacker could actually pull off.

Control-focused results

We measure your detection and response controls rather than assigning individual blame, and hand back targeted awareness and process improvements.

Every click, report, and gap.

From campaign to coaching.

Your social engineering results land in Sable: detection and reporting rates, the controls that failed, and the follow-up actions, tracked over time so you can prove your human firewall is getting stronger.

Campaign results in Sable
Campaign resultsClicked vs reported
  • Phishing42% clicked · 24% reported
  • Vishing31% clicked · 12% reported
  • Smishing27% clicked · 9% reported
  • Pretexting18% clicked · 6% reported
4 channels testedDetection · reporting · escalation

Common questions

What is social engineering penetration testing?
Social engineering penetration testing safely simulates the manipulation attacks real adversaries use to trick people into granting access or giving up information: phishing emails, vishing calls, smishing texts, and physical pretexting. It measures how well your detection, reporting, and verification controls hold up, and turns the results into targeted awareness improvements rather than blame.
Which channels do you test?
SubRosa runs phishing (email), vishing (voice), and smishing (SMS) campaigns, plus on-site pretexting, tailgating, and USB-drop scenarios. Real attacks blend channels, so we can simulate multi-channel campaigns to expose gaps a single-channel test would miss.
Could a phishing test damage trust with our staff?
It can, if it is run badly, and that is a genuine risk worth taking seriously. We exclude pretexts exploiting bereavement, medical circumstances, redundancy fears or payroll problems by default, report in aggregate rather than naming individuals, and frame the debrief as preparation rather than as a test people failed. A campaign that leaves staff feeling tricked and exposed damages the security culture it was meant to strengthen.
What metrics actually matter?
Not click rate. What matters is whether credentials were submitted, whether anyone reported the message, how quickly, and whether your security team detected and responded. An organisation with a high click rate and fast, confident reporting is in materially better shape than one with a low click rate and total silence.
Do you use generic phishing templates?
No, because they measure very little. Real attackers research the target and build a pretext specific to it — a genuine supplier, a real internal system, a current event at your company. We do the same, because a test using a template your staff have seen in training tells you only that they recognise the template.
Which channels do you cover?
Email phishing, voice (vishing), SMS (smishing), and on-site pretexting where physical access is in scope. Multi-channel campaigns are considerably more effective than email alone — a phishing email followed by a phone call referencing it converts at a much higher rate — which is exactly why attackers use them and why a serious test should.

Test your human firewall.

Let us design a realistic social engineering campaign that shows exactly how your people and processes respond to a real attack.