Skip to main content
CREST-Accredited | Multi-Vector | UK

SocialEngineeringPenetrationTesting

Social engineering penetration testing is a structured assessment of an organisation's human attack surface, conducted by CREST-accredited security professionals. Testing covers phishing simulation, vishing (voice phishing), physical intrusion attempts, and executive impersonation, evaluating whether employees, processes, and physical controls hold under realistic attacker pressure. Precursor Security delivers social engineering penetration testing across the UK from £5,000, with findings mapped to ISO 27001, DORA, PCI DSS, and NHS DSPT compliance frameworks.

Your technical controls are hardened. Your human layer is untested. We conduct CREST-accredited social engineering penetration tests across phishing, vishing, physical intrusion, and executive impersonation vectors, producing evidence-grade findings your auditors, board, and regulators will accept.

CREST-accredited delivery
Covers phishing, vishing, physical & pretexting
Fixed-price from £5,000
Findings mapped to ISO 27001, DORA, PCI DSS, NHS DSPT
Scroll
3,000+ Assessments DeliveredTriple-CREST Accredited24/7 UK SOC in NewcastleReports Accepted by Insurers & RegulatorsEst. 2018
Methodology

Six Attack Vectors.
One Engagement.

Each engagement begins with open-source intelligence gathering to build organisation-specific pretexts, not generic template attacks. We test every entry point your employees represent: email, voice, physical access, and executive impersonation.

Email Vector

Spear Phishing Campaigns

OSINT-built spear phishing campaigns using harvested employee data from LinkedIn, company directories, and public filings. We test credential submission, attachment execution, and link-click rates, with immediate teachable moment delivery to users who interact.

Voice Vector

Vishing (Voice Phishing)

Scripted vishing calls to your helpdesk and target employees, using pretext personas developed during OSINT. We test whether your team follows password reset procedures, discloses sensitive data, or bypasses verification under social pressure.

Physical Vector

Physical Security Testing

Authorised physical intrusion attempts: tailgating, badge cloning, USB drop testing, and rogue device placement. All physical testing is conducted under a signed RoE with authorisation letters carried by testers at all times.

Intelligence

Pretexting & OSINT

Open-source intelligence gathering across LinkedIn, Companies House, social media, and job postings to map your employee attack surface. Pretext personas are built from real-world data, not generic scenarios.

Fraud Simulation

Executive Impersonation

BEC and CEO fraud simulations targeting finance, HR, and executive assistants. We test whether financial controls and verification procedures hold under targeted impersonation pressure, coordinated with your finance team to prevent actual payment processing.

Mobile Vector

Smishing (SMS Phishing)

Targeted SMS and messaging campaigns using spoofed sender IDs and organisation-specific pretexts. We test whether employees recognise and report malicious links delivered via mobile channels, a vector often excluded from platform-based phishing simulations.

Executive Summary

The Human Attack Surface

Your people are the most targeted entry point, and the most under-tested. 74% of all breaches involve the human element.

Critical
74%

Human Element

Of all breaches involve the human element: credentials, social engineering, or human error. Verizon DBIR 2024.

Fixed Price
£5,000

Starts From

Fixed-price social engineering penetration testing. No day-rate surprises. Multi-vector combined assessments from £10,000.

Measurable
11x

Click Rate Reduction

Average reduction in simulated phishing susceptibility after three targeted testing and training cycles. Proofpoint Security Awareness Report.

Mapped
Controls
ISO 27001A.6.3 & A.8.7
PCI DSS 4.0Req 12.6
DORAArt. 26 TLPT
NHS DSPTStandard 9
Decision Aid

Why Managed Testing, Not a SaaS Platform?

The decision between a SaaS phishing platform and a CREST-accredited managed service determines whether your findings carry regulatory weight.

SaaS Phishing Platform

  • Generic template library
  • Email vector only
  • No CREST accreditation
  • Automated dashboard
  • Click rate data only
  • Ongoing awareness tool

CREST Managed Testing

  • OSINT-built, organisation-specific scenarios
  • Phishing + vishing + physical + pretexting
  • CREST-accredited findings accepted by regulators
  • Analyst-authored report with remediation
  • Evidence-grade report for ISO 27001, DORA, PCI DSS
  • Point-in-time penetration test for audit compliance

For organisations running an ongoing phishing awareness programme, our phishing simulation service sits alongside your existing tooling, providing expert-authored campaigns and analyst debrief that platforms cannot. For audit or regulatory compliance, our CREST-accredited assessment produces the evidence-grade report your auditors require. For typical pricing across other engagement types, see our penetration testing cost guide.

Scope Options

Attack Vector Coverage

Three engagement tiers. Every scope includes OSINT reconnaissance, analyst-authored findings, and compliance-ready reporting.

Vector
Phishing Only
From £5,000
Combined
From £10,000
Full Scope
From £15,000+
Spear phishing
Mass phishing
Vishing
Smishing (SMS) Optional
Physical intrusion
Executive impersonation
USB drop testing
OSINT report
Auditor Ready

Mapped directly to your regulatory controls.

Social engineering penetration testing provides evidence-grade documentation for regulated industries across the UK and EU.

ISO 27001:2022

A.6.3

Information security awareness: documents baseline click rates and post-test improvement trajectory

ISO 27001:2022

A.8.7

Protection against malware: tests real-world effectiveness of controls under human manipulation

PCI DSS v4.0

Req 12.6

Security awareness programme: provides documented testing evidence required for QSA review

DORA (EU 2022/2554)

Art. 26

Advanced threat-led testing: social engineering is a required TLPT component

NHS DSPT

Standard 9

Staff awareness testing and documented outcomes for NHS data security compliance

Cyber Essentials

Beyond Scope

Demonstrates controls beyond CE scope, strengthens renewal position and cyber insurance

CREST

Globally Accredited Consultants

All testing is conducted by CREST-accredited professionals.

Verify Accreditation
Engagement Pipeline

Engagement Workflow

Structured to minimise operational friction and maximise the value of the testing window.

Step 01

Reconnaissance

Passive OSINT gathering across LinkedIn, Companies House, social media, and public job postings. We map your employee attack surface (names, roles, reporting structures, technology stack signals) to build authentic, organisation-specific pretexts.

Step 02

Scenario Planning

Pretext development based on OSINT findings. Scenarios are built around your actual infrastructure (your IT helpdesk ticketing system, your email domain, your leadership team names). All scenarios are approved by you in the Rules of Engagement before execution.

Step 03

Execution

Multi-vector campaign execution across agreed testing windows. Phishing campaigns, vishing calls, and physical intrusion attempts are run concurrently or in sequence per your RoE. All activity is monitored in real time with immediate abort capability.

Step 04

Report & Debrief

Analyst-authored findings report with click rates, credential submission rates, vishing success rates, and physical access outcomes, benchmarked against industry averages. Anonymised by default, with a heat map of high-risk departments.

Deliverables

What You Get

Every social engineering penetration test includes the following deliverables, formatted for both security teams and non-technical stakeholders.

Comprehensive social engineering report with anonymised metrics: click rates, credential submission rates, and reporting rates
Detailed breakdown of each scenario with success rates and employee interaction timeline
Specific teachable moment examples showing the red flags employees missed
Comparison against industry benchmarks for your sector
Actionable recommendations for security awareness training topics and policy improvements
Executive summary suitable as compliance evidence for ISO 27001, PCI DSS, DORA, and NHS DSPT auditors

Reports are delivered via encrypted portal. Standard phishing campaigns deliver findings within 5 business days. Combined engagements within 10 business days.

After Testing

Close the Loop.
After the Test.

Your social engineering test identifies where the human layer is vulnerable. We feed those exact findings into our 24/7 Managed SOC and Microsoft 365 MDR, building custom detection rules for phishing attacks that reach your users and continuously monitoring for account compromise between annual tests.

Explore Defensive Services
Service Catalogue

Full Penetration Testing Catalogue

Comprehensive penetration testing services tailored to your environment.

Related security terms

Plain-English definitions of the concepts behind this service, from our security glossary.

Ready to Secure

The best time to test your defences is now.

Join the high-growth companies relying on Precursor for continuous offensive and defensive security.

CREST Triple Accredited|Fixed Price Quotes|Free Scoping Call|UK Based Team

Frequently Asked Questions

Common questions about this service, methodologies, and deliverables.

Social engineering in cyber security refers to manipulation techniques that exploit human psychology rather than technical vulnerabilities to gain unauthorised access to systems, data, or physical premises. Unlike technical attacks that target software flaws, social engineering attacks exploit trust, authority, urgency, and fear. Common social engineering techniques include phishing (email-based deception), vishing (voice-based manipulation), pretexting (building a false identity or scenario), tailgating (gaining physical access by following authorised personnel), and baiting (leaving infected devices for victims to find). Social engineering is responsible for the initial access stage in the majority of successful cyber attacks, making human security testing an essential component of any penetration testing programme.

Phishing simulation platforms (such as KnowBe4, Proofpoint Attack Simulation, or Microsoft Attack Simulator) provide self-service tools for running ongoing staff awareness campaigns using template-based emails. Social engineering penetration testing is a structured professional assessment conducted by CREST-accredited testers, using OSINT-built pretexts specific to your organisation rather than generic templates. The key differences: (1) A penetration test covers multiple attack vectors (phishing, vishing, physical, pretexting) while platforms typically cover email only; (2) A penetration test produces evidence-grade findings accepted by auditors, regulators, and cyber insurers. Platform dashboards typically do not. (3) A penetration test is a point-in-time professional assessment while platforms are designed for ongoing awareness programmes; (4) CREST-accredited testing carries regulatory weight for ISO 27001, DORA, PCI DSS, and NHS DSPT audits that self-service platforms do not. Both have a role: platforms for continuous awareness, professional testing for audit and compliance evidence.

Yes. Phishing awareness training is a natural complement to social engineering testing. After completing a phishing simulation or full social engineering penetration test, Precursor can provide targeted security awareness training sessions addressing the specific red flags and techniques employees missed during testing. Training options include: department-specific workshops for high-risk groups (finance, IT helpdesk, executive assistants), immediate teachable moment notifications to users who interact with simulations, and written security awareness guidance mapped to your test findings. For organisations requiring evidence of security awareness training for ISO 27001, Cyber Essentials, or cyber insurance renewals, we provide documented training completion records alongside testing reports.

Social engineering penetration testing typically ranges from £5,000 to £10,000+ depending on scenario complexity, number of employees targeted, and testing types (phishing-only vs combined phishing + vishing + physical intrusion). A standard phishing campaign for 100-200 employees averages £4,500 covering multi-scenario email testing with click rate analysis and credential harvesting simulation. Vishing testing targeting 20-30 employees typically costs £5,000-£6,000. Combined assessments including phishing, vishing, and physical intrusion testing typically cost £7,000-£10,000. We provide fixed-price quotes after understanding your organisation size, employee count, and testing objectives.

Yes, social engineering testing is legal when conducted under strict Rules of Engagement (RoE) that you approve in writing before testing begins. We operate within ethical boundaries: (1) We do not impersonate law enforcement, regulators, emergency services, or government officials. (2) We do not cause psychological harm, emotional distress, or create unsafe situations. (3) We do not commit actual crimes (real fraud, genuine trespassing without authorization, breaking and entering). (4) Physical intrusion attempts are coordinated with your facilities team with authorisation letters carried at all times. (5) We immediately identify ourselves if confronted and do not escalate confrontations. (6) All testing scenarios are approved in advance. If we successfully gain unauthorised access or compromise credentials, we immediately stop and document the security gap without exploiting it further.