Phishing & Social Engineering Assessments
Your firewalls are only as strong as your most susceptible employee. We test the human layer — across email, phone, text, and physical access — the way real attackers do.
Get a Quote →The most exploited attack vector
The vast majority of successful breaches begin with a human. Phishing campaigns, social engineering calls, and physical access attempts routinely bypass technical controls and reach your most sensitive data and systems. An independent test of your human defenses is no longer optional — it's a fundamental component of any mature security program.
Email phishing assessments
We design and execute staged email phishing campaigns — beginning with broad, easily-detected attacks and progressively escalating to highly-targeted spear-phishing using mimicked domains and custom pretexts. This reveals not just whether your users will fall victim, but at what level of sophistication your defenses will fail.
Phone phishing (vishing)
Our engineers call your staff using a range of social engineering scenarios — posing as IT support, company leadership, or affiliated vendors. Both live calls and automated scenarios are used, as each produces different results. All calls are non-disruptive, typically under a minute.
SMS phishing (smishing)
Text-based phishing is a growing and highly-effective attack vector. Many users apply far less skepticism to text messages than to email, making smishing assessments a valuable addition to any social engineering engagement.
Physical on-site assessments
Our engineers visit your facility and attempt to gain physical access using social engineering — posing as couriers, contractors, or staff. If successful, we attempt to access network resources, plant authorized testing hardware, or gain access to workstations and server rooms. Physical testing is frequently combined with a network penetration test for a complete picture of your risk exposure. Pricing is scoped individually based on number of locations and travel requirements — request a custom quote →
Post-assessment: security awareness training
The results of a real social engineering assessment are the single most effective input for security awareness training. Generic training videos are easy to ignore — but employees who were just fooled by a simulated phishing attack or a phone call pay very close attention to what follows.
Based in New York. Assessments Nationwide.
Grid32 conducts phishing, vishing, and smishing assessments for organizations across the United States — all conducted remotely with no geographic restrictions. Physical on-site social engineering assessments are available for clients who need them; contact us to discuss scope and logistics. We are particularly experienced working with financial institutions, law firms, and healthcare organizations navigating compliance-driven security programs.
What Grid32 security awareness training covers
- —Recognizing phishing and spear-phishing
- —Vishing and social engineering calls
- —Physical security and tailgating
- —Password hygiene and MFA
- —Incident reporting procedures
- —Industry-specific compliance obligations
Training is tailored to your organization's actual test results, size, and industry. Available as a standalone on-site session or as a follow-up to any social engineering engagement. Pricing varies by scope — contact us to discuss →
Assessment Types
- Email phishing campaigns
- Spear-phishing (targeted)
- Phone / vishing calls
- SMS / smishing campaigns
- Physical on-site testing
- Awareness training follow-up
Performing this test and proving vulnerability allowed me to finally gain the understanding from our Board to fund further defenses. Thank you to the Grid32 team.
IT Manager — Construction Company