Skip to main content

Social Engineering Testing

Hacking people is easier than hacking computers

Fortunately we see multi-factor authentication increasing and there are security tools that "see everything". Yet one thing remains unchanged: people want to help, people make mistakes and people can be manipulated.

What is social engineering?

Social engineering is about manipulating people to gain access to information, systems or buildings. It is the art of exploiting human psychology instead of technical weaknesses.

While your IT department installs patches and configures firewalls, an attacker with a smile and a good story simply walks in. That is the power - and the danger - of social engineering.

The weakest link in any security chain is the human. A friendly face and a convincing story open more doors than any exploit.

- Kevin Mitnick

Why test social engineering?

Your firewall doesn't stop a friendly voice on the phone

Your badge reader opens for someone carrying a box

Your SOC doesn't see a conversation at the coffee machine

Your awareness training doesn't cover deepfakes

The Neo Security approach

From classic to cutting-edge

Pretexting

Impersonating a trusted party

Tailgating tests

Physical access via 'piggybacking'

Dumpster diving

Extracting information from trash

USB drops

Custom payloads on USB sticks

Deepfake voice & video

AI-generated personas

OSINT-based targeting

Open source intelligence gathering

Our specialties

Executive impersonation

  • CEO fraud via deepfake technology
  • Board member vishing attacks
  • C-level whaling campaigns
  • Authority abuse simulations

Physical intrusion

  • Clean desk policy checks
  • Server room access tests
  • Badge cloning & RFID exploits
  • Lock picking (yes, really)

Supply-chain exploitation

  • Vendor impersonation attacks
  • Fake delivery infiltration
  • Contractor credential theft
  • Partner portal compromise

Real examples from our practice

The IT helpdesk scam

We call your employees as 'IT Support' with an urgent problem. 67% gives their password over the phone. At one client we got domain admin rights within 30 minutes using this method.

Lesson: Verification protocols are crucial

The delivery trick

With a fake package and a courier jacket we walked into three data centers. Nobody checks a delivery person in a hurry. We placed hardware keyloggers on critical workstations.

Lesson: Physical security starts at the front door

The linkedIn harvest

Via LinkedIn we collected all names and job titles. Then a targeted spearphish as 'new HR manager'. 89% clicked, 34% entered their credentials on our fake portal.

Lesson: Public information is a goldmine for attackers

Ethical boundaries

We test, we teach, but we don't damage people or careers. Every test is aligned in advance and constructively evaluated afterwards.

Our ethical guidelines:

  • No psychological harm to your employees
  • Always with explicit management consent
  • Constructive feedback, no blame culture
  • Focus on learning, not on 'failing'
  • Respect for privacy within the test scope

The human factor

93% of successful cyberattacks start with social engineering. Your employees are your first line of defense - or your biggest weakness. We help them become the first.

2 min

Average time to first click

€4.2M

Average CEO fraud damage

76%

Physical access via tailgating

Start today with real social Engineering to strengthen your team

Do you think your people can't be manipulated?
One phone call and we'll prove otherwise.
But more importantly: we teach them how to defend themselves.

Contact: +31 20 716 5487

Want to get started? Call us and we'll discuss what works for you.

The best way to protect your people against manipulation is to let them experience how it works, in a safe environment.