Skip to content
Penetration testing
  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation
Security assurance
  • Essential Eight assessment
  • Configuration review and benchmarking
  • Remediation support and retesting
Managed security
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring
All services on one page
Industries How we work About Blog
1300 AURIAN Contact
Menu
Penetration testing
  • Penetration testing services
  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation
Security assurance
  • Security assurance and compliance services
  • Essential Eight assessment
  • Configuration review and benchmarking
  • Remediation support and retesting
Managed security
  • Managed security services
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring
  • All services
  • Industries
  • How we work
  • About
  • Blog
Call 1300 AURIAN Contact
  1. Services
  2. Penetration testing
  3. Social engineering and phishing simulation

Penetration testing

Social engineering and phishing simulation

We test how your people and processes respond to a realistic attack, to build a baseline, not to name and shame.

Scope a test Call 1300 AURIAN

Who this is for

  • Your people are your largest attack surface

    Attacks routinely start with someone being persuaded to click, enter a password or approve a prompt. You want to know how your organisation responds.

  • An insurer or board wants evidence of awareness testing

    Cyber insurance and governance now expect regular, measured phishing simulation with results you can report against.

  • You want to test detection and response, not just click rates

    The useful question is not only who clicked, but whether anyone reported it and how quickly your team acted.

What our social engineering assessment covers

Internet Web application API Perimeter Cloud tenancy Email Office network Workstation Identity Wireless Crown jewels Servers INTERNET: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. WEB APPLICATION: NOT IN SCOPE HERE Covered by web application penetration testing. Click to open that service. API: NOT IN SCOPE HERE Covered by API penetration testing. Click to open that service. PERIMETER: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. CLOUD TENANCY: NOT IN SCOPE HERE Covered by cloud security assessment. Click to open that service. EMAIL: CHECKS INCLUDE Phishing campaigns against agreed groups Mail filtering, attachment and link handling Reporting behaviour and response time OFFICE NETWORK: NOT IN SCOPE HERE Covered by internal network penetration testing. Click to open that service. WORKSTATION: CHECKS INCLUDE What a clicked lure reaches on the endpoint Macro and attachment execution controls Credential prompts and browser defences IDENTITY: CHECKS INCLUDE Credential capture and MFA prompt approval Voice phishing of the service desk Password reset and enrolment processes WIRELESS: NOT IN SCOPE HERE Covered by wireless penetration testing. Click to open that service. CROWN JEWELS: NOT IN SCOPE HERE Covered by internal network penetration testing. Click to open that service. SERVERS: NOT IN SCOPE HERE Covered by configuration review and benchmarking. Click to open that service. Internet Web application Perimeter API Email Cloud tenancy Office network Workstation Wireless Identity Crown jewels Servers INTERNET: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. WEB APPLICATION: NOT IN SCOPE HERE Covered by web application penetration testing. Click to open that service. PERIMETER: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. API: NOT IN SCOPE HERE Covered by API penetration testing. Click to open that service. EMAIL: CHECKS INCLUDE Phishing campaigns against agreed groups Mail filtering, attachment and link handling Reporting behaviour and response time CLOUD TENANCY: NOT IN SCOPE HERE Covered by cloud security assessment. Click to open that service. OFFICE NETWORK: NOT IN SCOPE HERE Covered by internal network penetration testing. Click to open that service. WORKSTATION: CHECKS INCLUDE What a clicked lure reaches on the endpoint Macro and attachment execution controls Credential prompts and browser defences WIRELESS: NOT IN SCOPE HERE Covered by wireless penetration testing. Click to open that service. IDENTITY: CHECKS INCLUDE Credential capture and MFA prompt approval Voice phishing of the service desk Password reset and enrolment processes CROWN JEWELS: NOT IN SCOPE HERE Covered by internal network penetration testing. Click to open that service. SERVERS: NOT IN SCOPE HERE Covered by configuration review and benchmarking. Click to open that service.

We run measured, consented campaigns against agreed scenarios, and we measure the response of both your people and your processes.

  • Email phishing campaigns using realistic, current pretexts agreed with you
  • Credential-harvesting scenarios against a monitored, safe landing page
  • Multi-factor authentication fatigue and prompt-bombing scenarios where relevant
  • Voice phishing, or vishing, against agreed targets and scenarios
  • Detection and reporting: whether staff report the attempt and how fast
  • The response process once an attempt is reported, from triage to containment
  • An awareness baseline you can measure future campaigns against

How we test it

Intrusions routinely begin with a person: someone persuaded to click a link, enter a password, or approve an authentication prompt. Social engineering tests that reality directly, but it is easily done badly, as a way to catch people out and publish an embarrassing number. Aurian runs it the other way around. The aim is a measured baseline of how your organisation, its people and its processes together respond to a realistic attack, and a clear set of improvements. It is authorised, consented at the right level, and reported around the organisation rather than the individual.

Scoping comes first. A small, informed group agrees the scenarios, the targets, the timing and the limits, with HR involved wherever people are the subject, and they can call a halt at any point. We then run the agreed campaigns using pretexts that reflect what real attackers are sending now, whether that is a payroll update, an invoice, a document share or a voice call to the service desk. Any landing page is monitored and safe, and no credentials are stored.

What we measure matters as much as what we send. The click rate is the least interesting number: some people will always click. The useful questions are whether anyone reported the attempt, how quickly, and whether your response process then did its job. Those answers point to fixes that reduce risk: a reporting button, a rehearsed response, better mail filtering. Blame reduces nothing. The debrief and report give you the aggregate results, the process gaps and a baseline to measure the next campaign against.

Standards PTES, NIST SP 800-115

  1. 01 Scoping and consent

    We agree the scenarios, the targets, the timing and the rules with a small, informed group in your organisation, including HR where people are involved.

  2. 02 Campaign

    We run the agreed campaigns using realistic pretexts, capturing who engaged, who entered credentials, and crucially, who reported it.

  3. 03 Response measurement

    We measure not just the click, but whether your monitoring caught it and how your team responded once it was reported.

  4. 04 Reporting and debrief

    You receive aggregate results, the process gaps we found, and recommendations, delivered as a baseline rather than a list of names.

What you receive

Every finding in an Aurian report looks like this: what we found, the evidence, what it means for you, and what to change.

Moderate AUR-2026-014 Sample finding, fictional environment

No route to report a suspicious email, and none was reported

Affected asset
Staff phishing campaign, 240 recipients
Rating
Moderate Possible 3 × High 4 = 12

Description

A credential-harvesting campaign reached 240 staff. A number engaged and a smaller number entered credentials on the monitored landing page. More telling than the click rate was that not one recipient reported the email, because there is no button or address to report to, and the response process was never triggered.

Evidence

Campaign: "Payroll update required" (consented, monitored)
Delivered            : 240
Opened               : 171  (71%)
Clicked the link     :  86  (36%)
Entered credentials  :  29  (12%)
Reported to IT       :   0  ( 0%)   # no reporting route exists

The engagement figures matter less than the last line: with no way to report, the incident-response process never started.

Impact

A real campaign would have harvested twenty-nine sets of credentials with the defenders entirely unaware, because nothing and no one raised the alarm. The absence of a reporting route turns a survivable incident into a silent compromise, and it is a process gap, not a failing of any individual.

Remediation

Add a one-click report button to the mail client and a monitored address, and make reporting the trained response rather than deletion. Rehearse the process that a report triggers, and measure reporting rate as the primary metric in future campaigns, above click rate.

References

  • ASD, recognise and report phishing
  • NIST SP 800-115, technical guide to information security testing
  • Executive summary written for the board, framed around the organisation, not individuals
  • Aggregate results: engagement, credential entry and, most importantly, reporting rate
  • The process gaps found, from reporting routes to response handling
  • Recommendations for awareness, process and technical controls
  • A baseline you can measure future campaigns against

Common findings

What this kind of engagement typically surfaces, so you can recognise your own environment.

  • No reporting route

    Staff have no simple way to report a suspicious message, so real attacks go unseen even when someone is suspicious.

  • Response process never triggered

    Even when an attempt is reported, the process that should follow is unclear, slow or untested.

  • Multi-factor fatigue

    Users who approve repeated authentication prompts to make them stop, defeating a control the organisation relies on.

  • Pretext susceptibility

    Particular lures, such as payroll, invoices and document shares, that consistently succeed and point to where training should focus.

  • Technical controls that let the message through

    Mail filtering and authentication gaps that allowed a realistic phishing email to land in the first place.

  • Over-reliance on staff to catch everything

    An expectation that people will spot every attempt, without the technical controls and processes to back them up.

Frequently asked questions

Will this single out or punish staff?

No, and we design it so it cannot. Results are reported in aggregate, framed around the organisation's processes and controls. The purpose is a baseline and a set of improvements, not a list of names. We involve HR in scoping wherever people are the subject.

Is it done with our knowledge?

A small, informed group in your organisation agrees the scenarios, targets and timing in advance and can stop the campaign at any point. The wider staff are not forewarned, because that would defeat the test, but the exercise is fully authorised and consented at the right level.

What is the most useful thing we will learn?

Usually the reporting rate and the response process, not the click rate. Some people will always click; the question that matters is whether anyone raises the alarm and whether your team acts. We measure both.

How often should we run campaigns?

Regularly rather than once. A single campaign is a snapshot; a programme over time shows whether awareness and process are improving. Many clients run quarterly campaigns after an initial baseline.

Related services

Internal network penetration testing

Internal penetration testing from a foothold on your network: Active Directory attack paths, credential hygiene and segmentation, tested to domain admin.

Essential Eight assessment

Essential Eight assessment against the ASD maturity model: every strategy tested with evidence, rated ML0 to ML3, with a prioritised uplift roadmap.

EDR monitoring

Managed EDR monitoring on your endpoint platform: alert triage, investigation, containment guidance, threat hunting and tuning by the consultants who test.

Penetration testing services

Scope a test with a senior consultant

Tell us what you need to know about your environment. We reply within one business day.

Scope a test Call 1300 AURIAN

Aurian Security is an Australian penetration testing and security assurance firm. Senior consultants perform every engagement, for clients across the country.

Penetration testing

  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation

Assurance and managed

  • Security assurance
  • Essential Eight assessment
  • Configuration review and benchmarking
  • Remediation support and retesting
  • Managed security
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring

Company

  • About Aurian
  • How we work
  • Industries
  • Blog
  • Contact
  • Privacy policy
526/368 Sussex St, Sydney NSW 2000 1300 AURIAN (1300 287 426) sales@aurian.com.au

© 2026 Aurian Security Pty Ltd. ACN 639 930 528.

This site is static, loads no third-party trackers, and publishes a security.txt.