Social Engineering Test
Want to test how well protected your organization is against cybercrime? At Tozettawe don't just test systems, we also test the human factor: through phishing, phone contact or a physical visit to your premises.
Discover below what a social engineering engagement can mean for your organization, from a low-threshold phishing test to a full physical and online attack simulation.
- Physical and online vulnerabilities mapped out
- Creates awareness among employees
- Transparent and clear process

[ 01 ]Social Engineering
What is social engineering?
Social engineering is a specific form of cyberattack in which the human factor is exploited to gain access to information or systems. This can happen through phishing by phone or email, or someone physically trying to break in.
What is social engineering?
How does an attack work?
Who carries this out?
[ 02 ]Attack types
Physical vs. online attack
A social engineering engagement can be carried out entirely remotely, or physically on location. Pick an attack type below and see which methods belong to it.
Digital attack, remote
In an online social engineering attack we approach your employees entirely remotely, via email or phone, to test whether they give away sensitive information or click a malicious link.
OSINT research
Gathering public information about employees and the organization to build a credible scenario.
01Phishing attack
Sending a controlled phishing email to (part of) the organization to measure click behavior and reporting willingness.
02Spearphishing
A personalized phishing email targeted at specific people or departments, tailored using OSINT information.
03Vishing (phone phishing)
Contacting by phone under a false pretext to obtain confidential information or access.
04Certifications
Our ethical hackers are broadly certified
From OffSec to Hack The Box: the Tozetta team sets the bar high with internationally recognized, hands-on certifications. We put that in-depth expertise to work in every pentest, so organizations can count on thorough, high-quality security research.

OSCP
Offensive Security Certified Professional

OSWE
Offensive Security Web Expert

OSEP
Offensive Security Experienced Penetration Tester

OSED
Offensive Security Exploit Developer

OSCE3
Offensive Security Certified Expert 3

CPTS
HTB Certified Penetration Testing Specialist

CWEE
HTB Certified Web Exploitation Expert

CWES
HTB Certified Web Exploitation Specialist

AED
Android Exploit Developer

APIsec
API Penetration Testing

eWPT
Web Application Penetration Tester

BED
Browser Exploit Design

Corelan
Windows Expert-Level Stack Exploit Dev

OSCP
Offensive Security Certified Professional

OSWE
Offensive Security Web Expert

OSEP
Offensive Security Experienced Penetration Tester

OSED
Offensive Security Exploit Developer

OSCE3
Offensive Security Certified Expert 3

CPTS
HTB Certified Penetration Testing Specialist

CWEE
HTB Certified Web Exploitation Expert

CWES
HTB Certified Web Exploitation Specialist

AED
Android Exploit Developer

APIsec
API Penetration Testing

eWPT
Web Application Penetration Tester

BED
Browser Exploit Design

Corelan
Windows Expert-Level Stack Exploit Dev

“An attacker doesn't just look at your systems, but at your entire organization. Where the technology is well secured, human behavior can offer another route inside. With social engineering we test that route in practice.”
[ 03 ]Why Tozetta
Why a social engineering engagement with Tozetta?
A social engineering test is a good way to reveal how vulnerable your employees and organization are to a cybercrime attack. At Tozetta a professional investigates how resilient your people are against deception, both online and physically on location.
A security awareness training is then one of the ways to make employees more aware of the risks and how they can respond.

[ 04 ]Our process
How does a social engineering engagement work?

Introduction & scope
In a no-obligation conversation we determine together which scenarios, departments and attack types we test, physical and/or online.
OSINT & preparation
Our professionals gather public information and prepare a credible scenario, tailored to your organization.
Execution
The agreed attack is carried out, from a phishing email to a physical visit on location, with an eye for discretion.
Reporting & debrief
A clear report in Tozetta Reports, followed by a joint debrief and advice for next steps.

“I've capped off 5+ years of experience as an ethical hacker with an OSCP, OSED, OSWE, OSEP & OSCE3 certification. With that knowledge, I make sure your networks, websites, and mobile applications are tested thoroughly.”





[ 05 ]Investment
Social Engineering pricing
At Tozetta we want to be very transparent about the pricing of a Social Engineering engagement. From a low-threshold phishing test based on a single email to a full physical and online attack simulation.
Not sure which package fits you? Feel free to get in touch, custom work is also possible.

Social Engineering pricing
At Tozetta we bring the highest quality to every engagement. Every project comes with the following added value:
- We always test with certified professionals
- Every engagement starts with a no-obligation scope discussion
- Extensive reporting including an improvement plan in Tozetta Reports
- Personal debrief after completing the engagement
- Discreet and carried out carefully, always within agreed boundaries
Social Engineering light
Low-threshold first introduction
€1295
- 1 phishing email to the whole organization
- Fully online, no physical attack component
- Overview of click and reporting behavior
Social Engineering basic
The standard phishing test
€1895
- Basic OSINT research
- Phishing attack
- Physical letter mail
Social Engineering business
Focused on specific departments
€2695
- Advanced OSINT research
- Phishing attack
- Spear phishing attack on two departments
- Physical letter mail
Social Engineering professional
Full physical & online simulation
€4995
- Advanced OSINT research
- Spear phishing on every department
- Physical visit by an actor
- WiFi-spoofing
- Physical letter mail
Frequently asked social engineering questions
What does the Social Engineering light package include?
What is WiFi-spoofing?
What is Bluetooth Pentesting?
What is Spear Phishing?
Ready to test your organization?
Get in touch without obligation and discuss the possibilities of a Social Engineering engagement.