
Martin Hořický
Increased requirements for cyber resilience (as outlined in regulations such as DORA and NIS2) and the growing number of attacks targeting employees clearly demonstrate that technical security measures alone are no longer sufficient. Attackers today often target not systems but human behavior - through manipulation, trusted communication or persuasive posturing. It only takes one careless click, a rushed response, or a seemingly harmless phone call for an attacker to gain access that technical controls would otherwise prevent.
This is why it's essential to assess how well employees can resist such tactics. Simulated social engineering attacks help identify real vulnerabilities in human behavior, enhance the organization's readiness to respond to manipulation, and strengthen overall cyber resilience.
Unlike technical attacks, social engineering targets the human element rather than systems or technologies:
From a security perspective, social engineering is one of the most effective and hardest-to-detect methods of attack—because the attacker exploits human behavior, not code-based vulnerabilities.
| Type | Description | Objective |
|---|---|---|
| Phishing Campaigns | Simulated mass emails that mimic typical corporate or commercial messages, prompting recipients to click links, enter credentials, or download files. | Assess overall employee resilience to common fraudulent emails and their ability to recognize spoofed messages. |
| Vishing | Simulated phone calls where the attacker impersonates a colleague, supplier, or technician to extract access credentials or confidential information. | Test employee reactions to unexpected calls and verify adherence to communication and verification protocols. |
| Smishing | Simulated fraudulent SMS messages containing links to fake login pages or calls to enter sensitive data or download malicious content. | Evaluate how employees respond to fraudulent mobile messages and their ability to detect manipulation. |
| Physical Testing | Simulation of unauthorized attempts to enter company premises to evaluate the effectiveness of physical security controls. | Verify the level of physical security, staff awareness, and resistance to manipulative techniques in real-world scenarios. |
| Baiting | Placement of physical traps, such as USB drives, rogue devices, or QR codes designed to provoke curiosity or trust. | Test employee curiosity and habits, as well as the effectiveness of internal policies for handling external devices. |
Define the types of attacks to be simulated (e.g. phishing, vishing, physical intrusion). Determine the scope of the simulation, rules of engagement, and the level of awareness among internal teams.
Develop customized email, SMS, and call scripts adapted to the client's environment. Scenarios reflect specific organizational roles and relevant risk profiles.
Sending phishing emails, conducting vishing calls, placing USB bait, or attempting physical intrusions.
Analyze interaction statistics, success rates, incident detection by security teams, and internal response effectiveness.
Demonstrate real-world attack examples, explain common signs of manipulation, share recommended response procedures, and conduct Q&A sessions.
BDO provides social engineering services in line with the specific requirements of European regulators (e.g. ECB, EBA, ESMA) and frameworks such as NIS2 and DORA, which focus on the security of people, processes, and technology. Our methodology combines advanced social engineering techniques, knowledge of the regulatory framework, and deep technical know-how—including scenarios reflecting sector threats and digital attacks in the European financial space.
01 Independence and credibility
As an independent consulting firm, we do not own any technologies and offer truly objective assessments. Cooperation with BDO is a clear signal of quality and trust for both regulators and clients.
02 Certified team with expert experience
Our specialists hold certifications such as OSCP, CRTP, eCPPT, BSCP, CEH, CRT, CPSA, CISSP, CCISO, and others. They have experience testing large banks, insurers, and ICT providers.