Menu

Call us on 03450 21 21 51

Social Engineering Testing
Vulnerability Testing

Social Engineering Testing

To achieve Social Engineering testing simulated Phishing, baiting or tailgating can all be utilised: the team at SRM can safely and securely build an attack scenario to test how the organisation would respond to a real and malicious attempt of this nature.

Who is the service for?

In information security, the human element is often the weakest link; leaving an organisation open to unintentional vulnerability. Social engineering is an attack vector which relies on the psychological manipulation of people to gain access to systems. Any business wishing to gain a current and valuable knowledge base around the day-to-day threats facing all staff members can enlist a trusted third party to simulate this type of event and provide follow-up training to make sure any knowledge gaps are filled.

What is Social Engineering?

These types of attack exploit individuals within an organisation. They range in sophistication but commonly include scams where attackers attempt to persuade employees to divulge confidential passwords or sensitive information. Known by terms such as phishing, pretexting, baiting, tailgating or Quid Pro Quo, the types of attack have sinister motivation: usually to coax information or open up a system to allow the introduction of malicious plug-ins.

Preventing social engineering attacks requires a number of strategies, including education, alerts and regular monitoring. Testing is also important and should be included within a systematic Test and Exercise schedule

Why SRM?

The team at SRM can safely and securely build an attack scenario to test how the organisation would respond to a real and malicious attempt of this nature. The purpose of which is not to embarrass or bring disciplinary action to individuals, but to create an environment where all employees recognise their part in preventing this type of cyber-attack.

Associated services

Penetration Testing

Penetration Testing

From vulnerability assessments to Red Team engagement, we work with our partners to provide a full range of bespoke services to deliver a robust and cost-effective solution for your Test and Exercise requirements.

Red Team Engagement

Red Team Engagement

SRM’s network of CREST qualified partners combine a rigorous training process with real-world experience so they can think creatively and with the mindset of a genuine hacker. The difference is that they work for you.

Virtual CISO ™ Virtual ISM ™

Virtual CISO ™ Virtual ISM ™

At SRM we have developed VirtualCISO™ and VirtualISM™, which are totally bespoke services, providing as much or as little as required depending on the individual organisation.


Related articles

Social engineering: what is it and why is it the weapon of choice for so many cybercriminals

Why is social engineering proving so effective when it comes to pulling off a data breach? And how can social engineering testing help? Cybercrime hit an all-time high during..

Turning your remote workers from the weakest link into the strongest

We are all now probably familiar with the concept that, when it comes to technology in general and cyber security in particular, humans are the weakest link. But this..

Phishing attacks and the perks of purple teaming

Cyber criminals are like magicians; they rely of sleight of hand. Like theatrical entertainers, they misdirect so that the trick occurs when the audience least expects it. So while..