How to create a social engineering campaign?
Preparing a social engineering campaign can’t be improvised. A social engineering penetration test consists of auditing human behaviours when facing cyberattacks in a company. In practice, realistic phishing, spear phishing, vishing (phone attacks) and physical intrusions can be carried out.
Depending on the objectives of the social engineering audit, the attacks will be more or less sophisticated: sending mass emails or targeted emails, malicious links, cloning interfaces of web solutions used daily by teams, impersonating colleagues or managers…
The social engineering pentest allows both to measure the risks and to reinforce the awareness of the company's staff. Indeed, seeing the concrete results of attacks that have worked is striking, especially for those who have "fallen into the trap". The psychological impact is much stronger than with traditional risk training, and most of the people involved will not fall into the same traps when they are faced with similar threats again.
Social engineering penetration testing can be adapted to different objectives, different types of companies, and different organisational specificities. The purpose of this white paper is to outline what to consider before launching this type of audit.
