Phishing & Social Engineering Assessments

Your firewalls are only as strong as your most susceptible employee. We test the human layer — across email, phone, text, and physical access — the way real attackers do.

Get a Quote →

The most exploited attack vector

The vast majority of successful breaches begin with a human. Phishing campaigns, social engineering calls, and physical access attempts routinely bypass technical controls and reach your most sensitive data and systems. An independent test of your human defenses is no longer optional — it's a fundamental component of any mature security program.

Email phishing assessments

We design and execute staged email phishing campaigns — beginning with broad, easily-detected attacks and progressively escalating to highly-targeted spear-phishing using mimicked domains and custom pretexts. This reveals not just whether your users will fall victim, but at what level of sophistication your defenses will fail.

Phone phishing (vishing)

Our engineers call your staff using a range of social engineering scenarios — posing as IT support, company leadership, or affiliated vendors. Both live calls and automated scenarios are used, as each produces different results. All calls are non-disruptive, typically under a minute.

SMS phishing (smishing)

Text-based phishing is a growing and highly-effective attack vector. Many users apply far less skepticism to text messages than to email, making smishing assessments a valuable addition to any social engineering engagement.

Physical on-site assessments

Our engineers visit your facility and attempt to gain physical access using social engineering — posing as couriers, contractors, or staff. If successful, we attempt to access network resources, plant authorized testing hardware, or gain access to workstations and server rooms. Physical testing is frequently combined with a network penetration test for a complete picture of your risk exposure. Pricing is scoped individually based on number of locations and travel requirements — request a custom quote →

Post-assessment: security awareness training

The results of a real social engineering assessment are the single most effective input for security awareness training. Generic training videos are easy to ignore — but employees who were just fooled by a simulated phishing attack or a phone call pay very close attention to what follows.

Based in New York. Assessments Nationwide.

Grid32 conducts phishing, vishing, and smishing assessments for organizations across the United States — all conducted remotely with no geographic restrictions. Physical on-site social engineering assessments are available for clients who need them; contact us to discuss scope and logistics. We are particularly experienced working with financial institutions, law firms, and healthcare organizations navigating compliance-driven security programs.

What Grid32 security awareness training covers

  • Recognizing phishing and spear-phishing
  • Vishing and social engineering calls
  • Physical security and tailgating
  • Password hygiene and MFA
  • Incident reporting procedures
  • Industry-specific compliance obligations

Training is tailored to your organization's actual test results, size, and industry. Available as a standalone on-site session or as a follow-up to any social engineering engagement. Pricing varies by scope — contact us to discuss →

Get an Online Quote →