Skip to content
CISO Marketplace Services

Social Engineering Campaign Assessment

Comprehensive social engineering assessment including phishing campaigns, vishing attacks, physical security testing, and employee awareness evaluation.

In scope

  • Phishing campaign development
  • Vishing attack scenarios
  • Physical security tests
  • Employee awareness evaluation
  • Access control testing
  • Removable-media and tailgating exercises (upper tiers)
  • Training session for the groups that responded (upper tiers)

You receive

  • Campaign effectiveness report
  • Employee vulnerability analysis
  • Security awareness recommendations
  • Training program design
  • Response procedure assessment

Tiers

Choose the depth.

Entry — market-sized scope

$7.5K

One email-only exercise for up to 100 staff with a results report. The smallest version of this work.

employees
100
Objectives
1
  • One email exercise
  • Results by department
  • Awareness recommendations
  • — Phone-based and on-site exercises
  • — Follow-up training
Scope Entry — market-sized scope

Core Social Engineering Assessment

$25K

Email exercises for up to 500 staff: 2 campaigns plus an awareness baseline.

employees
500
Objectives
2
  • Two email campaigns
  • Awareness baseline
  • Executive summary
  • — Phone-based and on-site exercises
Scope Core Social Engineering Assessment

Advanced Social Engineering Program

$45K

Email and phone exercises for up to 2,000 staff, plus on-site testing at one location.

employees
2000
Objectives
4
Sites
1
  • Email and phone exercises
  • On-site testing at one location
  • Targeted coaching for repeat responders
  • — More than one on-site location
Scope Advanced Social Engineering Program

Enterprise Social Engineering Solution

$75K

All channels for up to 5,000 staff, on-site testing at up to 3 locations and a follow-up awareness program.

employees
5000
Objectives
8
Sites
3
  • All channels
  • Up to three on-site locations
  • Follow-up awareness program
  • — Ongoing monthly simulations — see Managed Security Awareness
Scope Enterprise Social Engineering Solution

Members: engagement coupons from the CISO Marketplace coupon book apply to services. There is no blanket discount.

What's inside this engagement

Phase by phase.

How a social engineering & physical engagement runs, what happens in each phase and what you see. Exact scope, tier and timeline are fixed in your proposal and SOW.

  1. 01Scoping & authorization

    Targets, pretexts, sites and legal authorization letters agreed before anything is sent or attempted.

    You see · Signed authorization and approved pretexts.

  2. 02OSINT & pretext design

    Public information on staff and sites is used to build believable pretexts.

    You see · Approval of the pretexts.

  3. 03Campaign / on-site execution

    Phishing, vishing or physical entry attempts, run to the agreed plan and stopped on request.

    You see · Real-time escalation if anything goes wrong.

  4. 04Reporting & awareness debrief

    What worked, who reported it, and the controls that failed, without naming and shaming individuals.

    You see · Metrics and a training plan.

Commercials

From first call to final report.

  1. 01

    Scoping call

    A practitioner, not a salesperson, walks through targets, constraints and what a good outcome looks like for you.

  2. 02

    Proposal & rules of engagement

    A fixed-scope proposal with tier, price and deliverables. Rules of engagement, contacts and out-of-bounds systems are agreed in writing.

  3. 03

    Sign, then start

    MSA and SOW are signed electronically and the deposit is paid. Only then does testing begin.

  4. 04

    Execution

    Testing runs to the agreed plan. Critical findings are escalated as they are found; you don't wait for the report.

  5. 05

    Report & debrief

    An executive summary plus technical findings with evidence, reproduction steps and fixes, walked through with your team.

  6. 06

    Retest

    Where the tier includes it, we verify your fixes and reissue the report, so auditors and customers see the issues closed.

Timelines are set per engagement in the SOW.

Related

Research

Latest from the blog

All posts on cisomarketplace.com →
Talk to an advisor
Advisor