As email security filters continue to evolve and improve, attackers are moving from email-based phishing to other social engineering methods, such as SMS, phone, in-person impersonation, media drops, etc. These non-email based forms of social engineering rarely have the security solutions in place to monitor and block malicious messages and attacks, which is an advantage for the attacker.
The Social Engineering Assessment could include everything from the Phishing Assessment service (email-based social engineering), but it could also include a custom-tailored combination of SMS (i.e. smishing), phone (i.e. vishing), in-person impersonation (i.e. physical social engineering), baiting (ex. USB drops), social media, mailed letters/packages, etc. The details of the assessment are tailored to your specific needs and risk profile.
View our Sample Findings and Recommendations Report to see the level of detail PEN Consultants provides in our report.
Because our Social Engineering Assessment services are highly tailored to each client engagement, it is more difficult to give sample pricing. The following are sample costs for some of the most common – vishing, smishing, and baiting:
In order to keep our testing prices low, we’ve removed certain services that not every client requests. Under our Cybersecurity Unlimited Retainer (included with all of our contracts) you can add on the following services as needed. Please reference the Cybersecurity Unlimited Retainer page for pricing details.