Sprocket Security
Social Engineering Testing and Awareness Program
Pages
2
Time to read
3 mins
Publication
Language
English
Pages
2
Time to read
3 mins
Publication
Language
English
This document is a guide detailing Sprocket Security's Social Engineering service, which assesses human vulnerabilities to social engineering attacks. The guide outlines various types of social engineering tactics, including phishing, spear phishing, vishing, and pretexting, and explains how these methods can bypass technical security measures by exploiting human behavior. It describes the process of conducting multi-wave email campaigns and phone-based impersonation attempts to test employee resilience against such attacks. Additionally, the guide emphasizes the importance of demonstrating the potential downstream impact of successful attacks, including credential reuse and privilege escalation. It also highlights compliance requirements from standards such as HIPAA, PCI DSS, and NIST, which mandate regular testing and training against social engineering threats. The document concludes with the operational value of targeted security awareness training based on identified weaknesses within the organization.