855-TRUSEC-1 (855-878-7321) [email protected]

Human Risk Assessment

Social engineering testing that measures behavior, not just clicks.

TruSec designs controlled phishing, telephone, and approved physical scenarios to evaluate whether employees follow verification procedures when an attacker uses urgency, authority, familiarity, or technical pretexts.

Service Overview

Test the decisions attackers rely on people to make.

Security awareness training is important, but organizations also need evidence of how personnel respond during realistic interactions.

A user may recognize a suspicious email but still disclose information during a convincing phone call, approve an MFA prompt, bypass a visitor procedure, or follow instructions from someone claiming to be IT support.

TruSec works with authorized engagement contacts to develop scenarios that reflect the organization’s environment, policies, terminology, and risk objectives. Safeguards, data handling, escalation, and employee protections are defined before testing begins.

Common program objectives

  • Measure awareness training effectiveness
  • Evaluate caller verification and help-desk procedures
  • Test credential, MFA, payment, or sensitive-data handling behavior
  • Identify departments or scenarios that need targeted training
  • Establish a baseline and validate improvement through follow-up testing

Assessment Coverage

Scenarios tailored to people, process, and business context.

Each channel can be tested independently or combined into a coordinated campaign.

SE-01

Email Phishing

Controlled messages, links, attachments, credential simulations, reporting behavior, repeat interactions, and training-focused observations.

SE-02

Telephone Vishing

Pretexts involving IT support, security events, business requests, vendors, executives, or familiar operational topics.

SE-03

MFA & Credential Behavior

Testing whether users disclose passwords, one-time codes, reset information, or approve unexpected authentication prompts.

SE-04

Process Verification

Evaluation of callback procedures, identity verification, help-desk escalation, payment changes, and sensitive information requests.

SE-05

Physical Scenarios

Approved attempts involving visitor controls, tailgating, pretexting, restricted areas, or document exposure when included in scope.

SE-06

Training Support

Sanitized examples, annotated red flags, audience-specific observations, and practical recommendations for corrective awareness efforts.

How the Engagement Works

Controlled testing with defined safeguards.

  1. Define objectives

    Select channels, targets, pretexts, success criteria, exclusions, data handling, and emergency contacts.

  2. Prepare scenarios

    Build realistic but controlled content and infrastructure aligned to the organization’s environment.

  3. Execute and observe

    Record user actions, verification behavior, escalation, reporting, and meaningful process failures.

  4. Report and improve

    Provide aggregate results, targeted observations, training recommendations, and a follow-up testing strategy.

Deliverables

Results that support corrective action without unnecessary employee exposure.

Reporting emphasizes trends, control failures, and practical training priorities while handling individual results according to the agreed rules.

Email PhishingTelephone VishingMFA BehaviorProcess ValidationPhysical SecurityTraining Support
  • Executive summary and overall human-risk posture
  • Scenario and methodology overview
  • Aggregate channel and outcome metrics
  • Observed verification and escalation failures
  • Role, department, or location trends when authorized
  • Sanitized examples and training material
  • Policy and process recommendations
  • Suggested follow-up testing after corrective training

Common Questions

Social engineering testing questions

Can the test include both email and telephone scenarios?

Yes. Combining channels can reveal whether a user who resists one approach is still vulnerable to a coordinated or more personal pretext. Email, telephone, and approved physical scenarios can also be tested independently when a narrower assessment is preferred.

Do you collect real passwords?

Testing can simulate credential submission without retaining or using real passwords. Exact handling is defined in the rules of engagement and is designed to minimize the collection, storage, and exposure of sensitive information.

Will employees know they are being tested?

Typically, only authorized engagement contacts know in advance. The organization determines notification, employee-relations requirements, labor or legal considerations, and how individual results may be used.

Do you provide training recommendations?

Yes. Recommendations are tied to the behaviors and process failures observed during the exercise. TruSec can also provide sanitized examples, annotated red flags, role-specific observations, and a follow-up testing strategy to help measure improvement.

How are employees selected for social engineering testing?

Targets are selected with authorized client contacts based on the engagement objectives. The sample may include a broad cross-section of employees or focus on departments, locations, roles, or personnel with elevated access and data-handling responsibilities.

Can scenarios be customized for specific departments or roles?

Yes. Scenarios can reflect the organization’s vendors, terminology, workflows, technologies, and risk concerns. Pretexts may be tailored for executives, finance, human resources, clinical staff, customer service, information technology, or other approved groups.

Can the help desk or call center be specifically tested?

Yes. Testing can evaluate identity verification, password-reset procedures, callback requirements, escalation, account recovery, MFA handling, and requests involving sensitive or operational information.

How are individual employee results protected and reported?

Reporting rules are agreed upon before testing. Results can be presented in aggregate or, when authorized, by individual, role, department, or location. Access to detailed results is limited to approved recipients, and reports emphasize corrective action rather than unnecessary employee exposure.

Can executives or other high-risk personnel be tested separately?

Yes. Executives, finance personnel, administrators, help-desk staff, and users with privileged access may be assessed through separate scenarios and success criteria that reflect their access, authority, and likely threat exposure.

When should social engineering testing be repeated?

Follow-up testing is most useful after corrective training and process improvements have had time to take effect, commonly at least three months later. Periodic testing can then use new pretexts, channels, departments, and request types to measure sustained improvement.

Ready to measure real employee and process behavior?

Share the number of targets, preferred channels, business locations, risk scenarios, training objectives, and desired testing window.

Request a scope