A phone rings at the finance desk. The caller knows the CFO’s name, the invoice number, and sounds exactly like the bank. Nobody had to break through a firewall to get this far, because nobody needed to. This is what social engineering penetration testing exists to find out: not whether your systems can be hacked, but whether your people can be talked past them.
Table of Contents
The weak link isn’t a person, it’s an untested assumption
“People are the weakest link” is a tired line, and it’s not quite right. The real weak point is usually an untested assumption: that staff will always spot a fake email, that a caller who knows internal jargon must be internal, that nobody would bother tailgating through a door for a company this size. A social engineering penetration test replaces that assumption with evidence.
The evidence tends to be sobering. The UK government’s Cyber Security Breaches Survey 2025/2026 found 43% of UK businesses experienced a breach or attack in the past year. Phishing was the single most common cause, affecting 38% of them, and 69% of those hit called it the most disruptive attack they faced. Verizon’s 2026 Data Breach Investigations Report backs this up globally: the human element was present in 62% of breaches, and social engineering was the third most common incident pattern overall.

What social engineering penetration testing actually does
A social engineering penetration test is a controlled, authorised simulation, not a prank. A tester researches your organisation using the same open-source techniques a criminal would (staff names, job titles, email formats, anything public on LinkedIn or your own website), then builds scenarios around what they find. Six tactics recur across most engagements:
- Phishing: deceptive email, still the most common opening move.
- Vishing: the same con, delivered by phone, often as fake IT support.
- Smishing: a text message pointing to a fake delivery or bank alert.
- Pretexting: a fabricated but believable cover story, sustained over several contacts.
- Baiting: a tempting object, like a branded USB drive, left where someone will find it.
- Tailgating: walking through a secure door behind someone who holds it open.
A test rarely uses just one. Real attackers chain them, and a good tester does the same: a phishing reply hands over a name, that name becomes the hook for a phone call a week later.
How the engagement is actually scoped and run
Behind the creative scenarios sits a fairly disciplined process. First comes scoping. You and the tester agree in writing which staff, buildings or departments are fair game, which tactics are off-limits, and who to call if something unexpected happens. Then reconnaissance, where the tester gathers the same public information an attacker would. Scenario design follows, built around your actual business rather than a generic template. Execution happens over an agreed window, with a safety mechanism so anything unplanned can be paused immediately. Finally comes reporting: what worked, what didn’t, and specific fixes, usually with an option to retest.
A good report earns its cost. It should explain which pretexts succeeded and why, roughly how far an attacker could have progressed from that first foothold, and concrete recommendations, such as changing a call-back verification process, rather than a generic line about “raising awareness”. Ask to see a redacted sample report before you commission anyone. Our own guide on planning a social engineering assessment walks through scoping this in more detail if you want to go a step further before briefing a provider.
Is it actually legal to test your own staff like this?
Yes, as long as it’s properly authorised. The Computer Misuse Act 1990 makes unauthorised access to a computer system a criminal offence. A written, signed scope agreement from someone with the authority to grant it is what turns a simulated attack into a lawful test rather than the real thing. Where a scenario impersonates a named individual, a responsible tester either seeks that person’s consent or designs around it.
UK GDPR sets the other boundary. A phishing simulation generates data about who clicked and what they typed, and calls may be recorded. That data should be minimised, held only long enough to write the report, and never used to name and shame individual employees. Tests run in that spirit teach people to report suspicious contact. Tests run as a “gotcha” teach people to hide their mistakes instead, which is the opposite of what you’re paying for.
What it costs, and how to scope it sensibly
Cost tracks scope closely. A single-vector phishing test against 100 to 200 staff typically starts around £4,500 to £5,000. Combine phishing with vishing or smishing and packages generally run £7,000 to £10,000. A full-scope engagement adding physical intrusion and executive impersonation, spread over several weeks, can run £15,000 to £30,000 or more.
Few smaller businesses need the top tier straight away. Targeting your highest-value staff, finance, payroll and anyone with access to customer data, with a focused phishing and vishing test usually tells you more per pound than a broad campaign spread across everyone at once.
Run the same scoped test again a year later and the number that matters most isn’t the click rate itself, it’s whether that click rate has actually moved. A business that goes from 30% to 10% has evidence its training budget is working. One that stays flat has evidence it needs to change something before the next real attempt lands.
How this sits alongside a phishing simulation programme
A scheduled phishing simulation testing platform builds a habit through repetition. A social engineering penetration test checks whether that habit holds up against something adaptive: a human tester who adjusts the story in real time and, where scoped, adds a phone call or a physical visit that automated tools can’t reproduce. Neither replaces the other. Many organisations run the platform monthly and commission a fuller test annually, or after a change significant enough to reset how staff expect to be contacted, such as a merger or a move to new premises.
If you want this run properly rather than as a box-ticking exercise, Aardwolf Security’s social engineering testing service follows exactly the scoping and safety process described above. A short conversation is usually enough to work out whether a phishing-only test or a fuller engagement fits what you actually need, and you’re welcome to get in touch to talk it through.
Frequently asked questions
How often should a business repeat this kind of test?
Once a year is a reasonable baseline, plus an additional round after a major change to your office, phone systems or workforce.
Does a failed test mean staff will be disciplined?
It shouldn’t. Results are best reported by team, not by name, and used to fix a process rather than punish an individual.
Can remote teams be tested the same way?
Yes. Phishing, vishing and smishing scenarios work regardless of where staff sit, and physical tests are simply left out of scope where there’s no shared office.
What should be excluded from a test?
Agree exclusions at the scoping stage: usually anything that could disrupt customer-facing systems, contact with board members without prior notice, and distressing pretexts such as bereavement.
How is this different from a general cyber security risk assessment?
A risk assessment reviews policies and controls on paper. A social engineering penetration test actually attempts to defeat them, which is why the two are complementary rather than substitutes.
Does the cost usually include a retest?
Sometimes, but not always. A handful of providers bundle one retest into the original quote, while others price it separately once remediation is finished, so it’s worth confirming before you sign.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.