How to create a social engineering campaign? 

Preparing a social engineering campaign can’t be improvised. A social engineering penetration test consists of auditing human behaviours when facing cyberattacks in a company. In practice, realistic phishing, spear phishing, vishing (phone attacks) and physical intrusions can be carried out.

Depending on the objectives of the social engineering audit, the attacks will be more or less sophisticated: sending mass emails or targeted emails, malicious links, cloning interfaces of web solutions used daily by teams, impersonating colleagues or managers…

The social engineering pentest allows both to measure the risks and to reinforce the awareness of the company's staff. Indeed, seeing the concrete results of attacks that have worked is striking, especially for those who have "fallen into the trap". The psychological impact is much stronger than with traditional risk training, and most of the people involved will not fall into the same traps when they are faced with similar threats again.

Social engineering penetration testing can be adapted to different objectives, different types of companies, and different organisational specificities. The purpose of this white paper is to outline what to consider before launching this type of audit.

visual

In this white paper, you’ll find:

Information on the types of tests performed during a social engineering campaign
Elements to consider when narrowing down your choices: When to conduct a social engineering pentest? Should you opt for black box or grey box testing? Should you do it in-house or outsource the tests? Is it better to inform employees or not to let anything slip?
Steps to prepare a social engineering campaign: definition of priority risks and threats, targets, and specificities to be taken into account
Advice on building attack scenarios, as well as executing them and tracking the results