Social Engineering Testing
Hacking people is easier than hacking computers
Fortunately we see multi-factor authentication increasing and there are security tools that "see everything". Yet one thing remains unchanged: people want to help, people make mistakes and people can be manipulated.
What is social engineering?
Social engineering is about manipulating people to gain access to information, systems or buildings. It is the art of exploiting human psychology instead of technical weaknesses.
While your IT department installs patches and configures firewalls, an attacker with a smile and a good story simply walks in. That is the power - and the danger - of social engineering.
“The weakest link in any security chain is the human. A friendly face and a convincing story open more doors than any exploit.”
- Kevin Mitnick
Why test social engineering?
Your firewall doesn't stop a friendly voice on the phone
Your badge reader opens for someone carrying a box
Your SOC doesn't see a conversation at the coffee machine
Your awareness training doesn't cover deepfakes
The Neo Security approach
From classic to cutting-edge
Pretexting
Impersonating a trusted party
Tailgating tests
Physical access via 'piggybacking'
Dumpster diving
Extracting information from trash
USB drops
Custom payloads on USB sticks
Deepfake voice & video
AI-generated personas
OSINT-based targeting
Open source intelligence gathering
Our specialties
Executive impersonation
- •CEO fraud via deepfake technology
- •Board member vishing attacks
- •C-level whaling campaigns
- •Authority abuse simulations
Physical intrusion
- •Clean desk policy checks
- •Server room access tests
- •Badge cloning & RFID exploits
- •Lock picking (yes, really)
Supply-chain exploitation
- •Vendor impersonation attacks
- •Fake delivery infiltration
- •Contractor credential theft
- •Partner portal compromise
Real examples from our practice
The IT helpdesk scam
We call your employees as 'IT Support' with an urgent problem. 67% gives their password over the phone. At one client we got domain admin rights within 30 minutes using this method.
Lesson: Verification protocols are crucial
The delivery trick
With a fake package and a courier jacket we walked into three data centers. Nobody checks a delivery person in a hurry. We placed hardware keyloggers on critical workstations.
Lesson: Physical security starts at the front door
The linkedIn harvest
Via LinkedIn we collected all names and job titles. Then a targeted spearphish as 'new HR manager'. 89% clicked, 34% entered their credentials on our fake portal.
Lesson: Public information is a goldmine for attackers
Ethical boundaries
We test, we teach, but we don't damage people or careers. Every test is aligned in advance and constructively evaluated afterwards.
Our ethical guidelines:
- ✓No psychological harm to your employees
- ✓Always with explicit management consent
- ✓Constructive feedback, no blame culture
- ✓Focus on learning, not on 'failing'
- ✓Respect for privacy within the test scope
The human factor
93% of successful cyberattacks start with social engineering. Your employees are your first line of defense - or your biggest weakness. We help them become the first.
2 min
Average time to first click
€4.2M
Average CEO fraud damage
76%
Physical access via tailgating
Start today with real social Engineering to strengthen your team
Do you think your people can't be manipulated?
One phone call and we'll prove otherwise.
But more importantly: we teach them how to defend themselves.
Contact: +31 20 716 5487
Want to get started? Call us and we'll discuss what works for you.
“The best way to protect your people against manipulation is to let them experience how it works, in a safe environment.”