Does your organisation create an environment where staff feel able and comfortable enough to challenge something that appears legitimate?
You do not have to work in cyber security for long before hearing that “people are the weakest link”. It is a common phrase, but not one I particularly like.
In reality, people are routinely asked to make security decisions in awkward, pressured or unclear situations. Holding a door open, waving through a visitor or choosing not to challenge someone because you do not want to appear rude can look like human error. But often, it reveals something deeper: a weakness in the processes and controls surrounding that person.
That is why social engineering testing should measure far more than whether an employee can be tricked.
What does social engineering testing actually test?
Social engineering is often treated as one element of a wider red team assessment, or associated primarily with phishing and vishing. But when performed properly, a dedicated social engineering assessment can reveal something far more useful than whether staff can be persuaded to take an unsafe action.
It can test whether security processes work under real-world pressure, whether employees feel empowered to challenge unusual behaviour and whether organisational controls can prevent a convincing pretext from becoming a security incident.
Attackers do not operate in the neat conditions described in policies and security awareness training. They exploit busy receptions, rushed conversations, familiar names, assumptions and the natural instinct most people have to be helpful.
One scenario I’ve used during authorised social engineering engagements demonstrates this particularly well.
A person arrives at reception or enters a shared office area wearing business clothing, with a lanyard partly visible, looking rushed and apologetic. They might say something like:
“Hi, sorry, I’m in a bit of a panic. It’s my first day and I’m running late. Mike from IT – a name gathered during open source intelligence – said he has my pass and told me to head towards the data centre area so he can meet me halfway. Could you point me in the right direction?”
There is no technical exploit in that scenario. Just urgency, assumed legitimacy and a relatable human moment. The person appears polite, slightly flustered and believable, and challenging them can feel unhelpful, rude or unnecessary.
I’ve used variations of this approach on three authorised engagements. On one occasion, it got me into a non-public area, directly bypassing a policy requiring visitors to remain at reception until their contact collected them.
The interesting finding wasn’t simply that I got through the door. It was the gap between the organisation’s documented security process and what happened when that process met a believable human situation.
That is the real value of social engineering testing. It doesn’t just tell you whether somebody can be tricked. It shows whether the organisation has created an environment where people, processes and controls continue to work when something appears legitimate.
What should security teams actually measure?
For security leaders, the useful question isn’t simply whether the tester succeeded. It’s why they succeeded – or why they didn’t.
A well-designed social engineering assessment can help an organisation understand:
- whether employees recognise and follow visitor controls;
- whether those controls remain practical when people are busy or under pressure;
- whether staff know how and where to escalate concerns;
- whether challenging unusual behaviour is culturally supported;
- whether physical and technical controls provide another layer of protection when someone makes the wrong judgement call
- how far an attacker could realistically progress if the initial social engineering attempt succeeded.
That gives security teams something much more useful than a pass or fail rate. It shows where policy, culture and controls diverge in the real world.
This is also why the results of social engineering testing should not be reduced to how many employees were “caught out”. If an assessment stops there, it risks treating the symptom rather than understanding why the scenario succeeded.
What does a strong security culture look like in practice?
A strong security culture does not expect every employee to be suspicious of everyone. That would be unrealistic and rather unpleasant.
Instead, secure behaviour needs to feel normal. People need permission to politely verify something that does not seem right, simple ways to report concerns and confidence that the business will support them for following the process – even if it causes a short delay or an awkward interaction.
And before anyone reaches for their slide decks, this isn’t about adding another annual security awareness presentation that everyone clicks through as quickly as possible.
The strongest environments are those where expectations are visible, repeated and part of daily routines. That could mean clear visitor processes, straightforward reporting routes, reminders in staff areas and managers visibly supporting employees who challenge unusual behaviour.
Practical language can help too. If someone is caught off guard, they shouldn’t have to work out how to challenge a stranger without sounding confrontational. Simple phrases such as “Sorry, I just need to check you’re signed in” or “Could you wait here while I check with the team?” remove some of that awkwardness.
It might sound like a small detail, but it signals something important: the organisation expects and supports the challenge.
There is a broader security point here too. If the only thing standing between an attacker and a sensitive area is one employee overcoming social pressure, recognising a convincing pretext, remembering the correct procedure and feeling confident enough to challenge it, then too much responsibility may be resting on that individual.
Security culture should complement physical and technical controls, not compensate for their absence.
Did we make it easy for staff to do the right thing?
Social engineering assessments are not about embarrassing individuals or catching people out. They are about identifying the gap between the security controls an organisation believes it has and the controls that actually hold up in the real world.
If an attacker gets through a held door or uses a rushed explanation to gain access, the question shouldn’t simply be:
“Why did that employee let them through?”
A better question is:
“Did we make it easy for that employee to do the secure thing?”
Because the best security controls aren’t simply the ones documented in policies or hardening guides. They’re the ones that still work when people are busy, distracted, under pressure – or simply trying to be helpful.
Put your security culture to the test
Want to understand how your people, processes and security controls stand up in the real world?
Explore MTI’s Social Engineering and Penetration Testing services.
About The Author
Luke Spencer is an IT Security Consultant at MTI and a CREST Registered Tester, CHECK Team Member and Practitioner Cyber Security Professional (PraCSP), with more than several years’ experience specialising in penetration testing.
His work spans internal and external infrastructure, web applications, cloud environments and physical security assessments, identifying vulnerabilities and chaining issues together to demonstrate realistic attack paths.
Luke has particular interests in web application security, Active Directory security, vulnerability chaining, social engineering and how security culture influences real-world risk.