Skip to main content

Social Engineering Assessments and the Consent They Require

Testing people is not testing systems. What can be assessed, what must be agreed first, and why individual results should almost never leave the room.

2 min read

Social engineering targets your staff rather than your systems, and that changes what has to be agreed before it starts and what may be reported afterwards.

What the assessment covers

Phishing by email, the most common. Voice pretexting — calling the service desk, which is frequently the most effective route of all. Physical entry, and whether anyone challenges a stranger. Occasionally messaging platforms, where the same pretexts work with less scepticism because people expect email to be the attack surface.

What has to be agreed first

Beyond the usual rules of engagement, three things specific to testing people.

Who authorises it. Employment and privacy questions are engaged the moment a real person's behaviour is recorded. In many organisations this needs HR and legal to have seen the plan, not just security — and in some jurisdictions or where a works council exists, more than that. This is not bureaucracy; it is what makes the exercise defensible afterwards.

Which pretexts are off limits. Some work extremely well and should not be used. Anything invoking redundancy, disciplinary action, a bereavement, a medical matter, or a real named individual's authority in a way that damages trust in them. The measure is not what an attacker would do — an attacker would do all of it — but what leaves your organisation functioning afterwards.

How results are reported. The most important, and covered below.

Individual results should stay out of the report

A phishing exercise can produce a list of who clicked. That list is almost never the useful output and is frequently harmful.

What is useful: how many, how quickly, whether anyone reported it, how long until the first report, and what the service desk did when called. Those are measures of the organisation.

What is harmful: names. Once staff learn that an exercise produces a list managers see, the rational response is to stop reporting anything ambiguous — and the reporting rate is the single most valuable defensive metric you have. An assessment that improves click rates while destroying reporting rates has made you less safe.

The narrow exception is a person who repeatedly hands over credentials after training, which is a management conversation rather than a security finding. Even then, the pathway should be agreed before the test, not improvised from results.

Reading the numbers honestly

A click rate without a pretext description is not comparable to anything. A generic template sent to two thousand mailboxes and a targeted message built from reconnaissance are different exercises, and quoting them as the same percentage across quarters measures the pretext, not the people.

The number worth tracking is the reporting rate — what proportion recognised it and told someone, and how fast. That is what actually shortens an intrusion, and it is the one a good assessment is designed to improve.

How these routes are used inside a wider engagement is in how red teams get in.