Social Engineering Services

Most breaches start with a person, not a port. We test the human attack surface the way real attackers do, targeted phishing, pretexting, MFA-fatigue, physical access, then report in aggregate and hand you the fixes that actually reduce risk.

Delivered by RedSecLabs: CREST member, PCI SSC QSA Company, ISO 27001 and 9001 certified (UKAS-accredited). Ethical, authorised, aggregate-reported, we measure organisational resilience, never individual failure.

CREST Certified Pen Test Provider ISO Certified OSCP Certified Industry Certification

Get Your Fixed-Fee Quote

Tell us what needs testing. You’ll get a scoped, fixed-fee quote back the same business day, from a senior assessor, not a sales rep. No obligation, no spam.

✓ Same-day response✓ Fixed-fee, no surprises✓ Senior testers only✓ Retest included

We reply within one business day with next steps. Your details are used only to scope your enquiry, never shared or sold.

Testing the human attack surface properly

Most breaches start with a person, not a port. Social engineering testing measures how your organisation holds up against the techniques attackers actually use: targeted phishing, voice pretexting (vishing), MFA-fatigue and consent-phishing attacks, and where authorised, physical access attempts. The point is not to embarrass employees, it is to find the process and technology gaps that let a convincing pretext succeed.

Every campaign is scoped and authorised in advance, run under strict ethical rules, and reported in aggregate, we measure organisational resilience, not individual failure. Results feed awareness programmes and technical controls (mail filtering, MFA hardening, help-desk verification) that measurably reduce risk.

Beyond the phishing click-rate

A click-rate on its own tells you little. We test the whole chain: does the pretext get through your mail controls, does a click harvest credentials, do those credentials bypass MFA, and does anything detect the anomalous login that follows? That end-to-end view is what turns a phishing statistic into an actionable list of technical fixes.

For higher-assurance engagements, social engineering is woven into a full adversary simulation or red team, using a human foothold as the realistic initial-access vector rather than testing it in isolation. It also maps cleanly onto the human-factor expectations in ISO 27001, PCI DSS awareness requirements, and DORA operational-resilience testing.

What you leave with

Aggregate resilience metrics across the attack chain (delivery, click, credential capture, MFA bypass, detection), the specific pretexts that succeeded and why, prioritised technical and process fixes, and awareness-programme input grounded in what actually worked against your people, not generic training content.

Three ways to run it

Baseline, chain-test, or fold into a full red team.

Phishing baseline
A targeted campaign that measures delivery, click and credential capture across the org.
  • Aggregate resilience metrics
  • Realistic sector pretexts
  • Awareness-programme input
Run a baseline
MOST CHOSEN
Full-chain social engineering
Phishing, vishing and MFA-fatigue tested end to end: does the whole sequence break?
  • Multi-vector campaign
  • Tests MFA bypass + detection
  • Technical + process fixes
Scope a campaign
Red-team initial access
Human foothold used as the realistic entry point for a full adversary simulation.
  • Feeds a full red team
  • Physical access where authorised
  • Most realistic attack path
Combine with red team

How social engineering testing runs

Authorised, ethical, and measured across the whole attack chain, not just a click-rate.

1
Scope and authorise
We agree targets, pretexts, boundaries and handling of results up front, with everything authorised in writing before anything runs.
2
Run the campaign
We test the chain: delivery, click, credential capture, MFA bypass and detection, using the pretexts real attackers use against your sector.
3
Report and strengthen
Aggregate resilience metrics, the pretexts that succeeded, and prioritised technical and awareness fixes, never individual blame.

Frequently asked questions

No. Ethical social engineering measures organisational resilience and reports in aggregate. The goal is to fix the process and technology gaps that let a pretext succeed, not to blame the person who clicked. Scope, consent and handling of results are agreed before anything runs.

Phishing is one vector. Full social engineering testing covers targeted spear phishing, voice pretexting, MFA-fatigue and consent-phishing, and, where authorised, physical access attempts, tested as a chain: delivery, click, credential capture, MFA bypass and detection, so you see where the whole sequence actually breaks.

Human-factor testing supports ISO 27001 controls, PCI DSS awareness requirements and DORA operational-resilience expectations. It also strengthens any red team or adversary simulation by providing a realistic initial-access vector rather than assuming one.

Yes. Point-in-time campaigns give a baseline; a recurring programme measures whether awareness and technical controls are actually improving over time, with trend metrics you can show leadership.

Get My Fixed-Fee Quote

Book a free 30-minute scoping call. CREST-format proposal within 48 hours, engagement starts within 1-2 weeks.

Frequently Asked Questions

CREST audits member companies against a quality framework covering methodology documentation, tester competence (mandatory CREST-certified individuals), ethical conduct, ongoing professional development, complaint handling, and operational quality. Membership is reviewed periodically and can be withdrawn. It is the strongest single quality signal for penetration testing providers.

CREST Registered Tester (CRT) is the entry-level individual certification, passed after demonstrating practical infrastructure testing competence. CREST Certified Tester (CCT) is the senior level requiring substantially more experience and a harder examination, separated into Infrastructure and Applications specialisms. CCT testers lead the most complex engagements.

Methodologically, both should look similar. The differences are: tester certification (CREST member companies must use CREST-certified testers), audited quality framework (CREST audits members), ethical conduct framework (formal CREST code), and report quality expectations (CREST-format reports are recognisable to enterprise security teams). For regulated buyers, CREST removes the need to assess these things yourself.

CREST testing typically runs 10-25% above unaccredited equivalents reflecting the cost of certified-tester staffing and quality framework. External infrastructure tests £4,500-£11,000; web application tests £6,500-£20,000; threat-led testing engagements £45,000+. Fixed-fee quotes within 48 hours of scoping.

Yes. Every penetration test we deliver follows CREST methodology and is led by CREST-certified testers, there is no "CREST-lite" or non-CREST option from RedSecLabs. Other services like vulnerability assessment and red teaming follow their own appropriate methodologies (CREST also accredits red teaming under STAR).
What you receive

Every engagement includes

  • Scoping call. A 30-minute call to define scope, timeline, and authorisation boundaries.
  • Test plan. Written test plan covering targets, methodology, and rules of engagement.
  • Technical report. Detailed findings with reproduction steps, evidence, and remediation guidance.
  • Executive summary. Board-ready 1-2 page summary with risk ratings and business impact.
  • Audit-ready evidence. Findings letter formatted for auditors, customers, and supervisory authorities.
  • Retest letter. Free retest of remediated findings within an agreed window. Confirmation letter included.
  • Remediation call. A call with our lead tester to walk through findings and remediation strategy.
How we deliver

Our process, end to end

  1. 1
    Scoping call & fixed-scope quote
    A 30-minute call. We define scope, targets, timeline. You get a fixed-scope quote within one working day. No surprise invoices.
  2. 2
    Test plan & authorisation
    Written test plan covering methodology, targets, and rules of engagement. Authorisation letter signed before any testing begins.
  3. 3
    CREST-accredited execution
    Senior tester runs the engagement. Critical findings flagged immediately during testing. Daily updates if you want them.
  4. 4
    Technical + executive report
    Detailed technical findings with reproduction steps. Board-ready executive summary. Delivered within agreed working days.
  5. 5
    Remediation call & retest
    Walkthrough with our lead tester. Retest of remediated findings within the agreed window. Confirmation letter for your auditors.
Engagement scope

What shapes the quote

Small scope
Single app, focused scope, smaller surface. 5-7 working days.
Medium scope
Multi-role platform, several user types, integrations. 8-12 working days.
Enterprise scope
Complex environment, multiple targets, compliance evidence. 12-25 working days.
Fixed-scope quote within 1 working day
No surprise invoices, no scope-creep. We commit to a number before you commit to us.
Sample report
See exactly what we deliver
Download a redacted RedSecLabs penetration test report. Same format, same depth, same clarity as the report your team will receive.
Download sample report
Why RedSecLabs

Grounded reasons clients choose us

UK-based team
Testers based in the UK. Data stays within UK/EU jurisdiction for sensitive engagements.
CREST member company
CREST-accredited methodology. Senior testers hold CREST CRT or CCT certifications.
Manual testing, not scanner-only
Automated scanners catch the obvious. Our human testers find the issues that matter.
Clear executive reporting
Reports your board can read and your developers can act on. No jargon padding.
Compliance-aware delivery
PCI, SOC 2, ISO 27001, DORA, GDPR. We map findings to your compliance framework.
Retest support included
Free retest of remediated findings within agreed window. Confirmation letter for auditors.
Related services

Often paired with this engagement

Web App Pentesting
CREST methodology applied to applications.
Network Pentesting
CREST methodology for infrastructure.
Red Team Assessment
CREST-accredited adversary simulation.
DORA TLPT
For DORA-regulated financial entities.
SWIFT CSP
For SWIFT-connected financial institutions.
📞 Call us Book a call