Skip to main content
    Cybersecurity13 min read

    Social Engineering Penetration Testing: What's Tested and What It Costs (2026)

    By Patrick Nevels

    A social engineering penetration test checks whether attackers can talk their way in through phishing, vishing, help desk pretexting and SMS. Here is what gets tested, how engagements run, and what they cost in 2026.

    Voice waveform passing through identity verification in an authorized social engineering security test

    Quote in 48 hours

    Get a custom quote

    Fixed-fee scoping in 24 hours. No sales pitch.

    Most penetration tests are aimed at software. Your web app, your APIs, your cloud accounts, your external network. They answer one question well: can an attacker break in through the technology?

    They do not answer the question that keeps coming up in breach reports: can an attacker simply ask to be let in? A convincing phone call to the help desk, an email that looks like it came from the CFO, a text about a payroll change. None of that touches a CVE, and none of it shows up in a scanner.

    That is what a social engineering penetration test measures. This guide covers what gets tested, how an engagement actually runs, how it differs from a phishing simulation or awareness training, and what it costs in 2026.

    What is social engineering penetration testing?

    Social engineering penetration testing is an authorized, scoped attack on an organization's people and processes. Testers use the same techniques real attackers use, such as phishing emails, voice phishing (vishing) calls, SMS phishing (smishing) and pretexting, to see whether employees will hand over credentials, reset an account, approve a payment or grant access. The output is a report showing which techniques worked, which teams and workflows were exposed, and which controls failed.

    The key word is process. A good social engineering test is not a trap for individual employees. It is a test of whether your verification steps hold up when a confident, well-prepared stranger pushes on them. When a caller talks the help desk into resetting an executive's MFA, the finding is not "Jordan failed." The finding is "the reset workflow has no out-of-band identity check."

    Why it matters more in 2026 than it did three years ago

    Three things changed at once.

    • The human element is still the majority of breaches. The 2025 Verizon Data Breach Investigations Report attributes roughly 60% of breaches to a human element such as social engineering, error or misuse.
    • Help desks became the front door. CISA's advisory on Scattered Spider (AA23-320A) describes attackers calling IT help desks while posing as employees to get passwords reset and MFA moved to attacker-controlled devices. The U.S. health sector's HC3 office published a threat actor profile warning healthcare organizations about the same playbook.
    • AI made voice attacks cheap. Voice cloning and real-time voice agents let one attacker run hundreds of convincing calls. CrowdStrike reported a 442% jump in vishing between the first and second half of 2024. We cover how those calls work in AI Can Now Clone Your CFO's Voice.

    Email phishing still matters, and most companies already run phishing simulations. The gap is everything that is not email: the phone, the help desk, the vendor change request, the text message. That is where testing budgets have not caught up with attackers.

    What a social engineering pentest actually tests

    Email, voice call and SMS channels connected to an identity-security control

    A full engagement picks from six attack vectors. Most organizations do not need all six. The table below shows what each one proves.

    VectorWhat the tester doesWhat it provesTypical measurement
    Email phishingSends a realistic campaign to an agreed list, often with a credential capture pageWhether email filtering and user judgment stop a broad attackClick rate, credential submission rate, report rate
    Spear phishingBuilds individual pretexts for high-value roles using public informationWhether finance, executives and admins can be singled outSuccess rate by role, time to first report
    Vishing (voice phishing)Calls employees while impersonating IT, a vendor, an executive or a patientWhether staff will disclose information or take action over the phoneDisclosure rate, actions taken, calls escalated
    Help desk pretextingCalls the help desk posing as an employee who needs a password or MFA resetWhether identity verification holds under pressureResets granted, verification steps skipped
    SmishingSends text messages tied to payroll, delivery, MFA or benefitsWhether mobile channels are a blind spotClick rate, credential submission rate
    PhysicalAttempts tailgating, badge cloning or entry under a pretextWhether physical access controls and staff challenge strangersAreas reached, challenges made

    Email phishing and spear phishing

    This is the vector most teams already know. The difference between a phishing simulation and a phishing penetration test is intent. A simulation platform sends templated emails on a schedule to train people. A tester designs a campaign the way an attacker would, using your real vendors, your real tools and current events, and then follows through on whatever the campaign captures. A captured password is not the end of the finding. The question is what that password unlocks.

    Vishing

    Vishing tests call employees directly. Common pretexts include IT support asking someone to confirm a login, a vendor asking to update bank details, an executive asking for an urgent favor, or in healthcare, a caller posing as a patient or another provider's office. Vishing is where most organizations perform worst, because phone calls carry urgency, tone and social pressure that an email does not. We break down how AI agents now run these calls in AI Agents Automate Vishing Phone Calls.

    Help desk pretexting

    Illustrated help desk caller and identity-verification workflow

    If you only fund one social engineering test this year, make it this one. The help desk exists to be helpful, it is measured on speed, and it holds the keys to every account. A tester calls posing as an employee who is locked out, traveling, or on a new phone, and asks for a password reset or an MFA re-enrollment. The test measures whether your verification process (callback to a number on file, manager approval, ID check through a separate channel) is actually followed when the caller is polite, plausible and in a hurry.

    A failed help desk test is one of the most actionable findings in security. The fix is usually a process change, not a product purchase.

    Smishing

    Text messages bypass email security entirely and land on personal devices. Smishing tests use pretexts like payroll changes, package delivery, benefits enrollment or MFA prompts. They are worth including if your workforce relies on mobile devices or if attackers have targeted your industry through text.

    Physical social engineering

    Physical testing checks whether someone can walk into a restricted area by following an employee through a door, posing as a contractor, or cloning a badge. It requires on-site work, careful legal authorization and travel, so it is usually scoped and priced separately from remote testing.

    Social engineering pentest vs. phishing simulation vs. awareness training

    These three get confused constantly, and buyers end up paying for one while expecting the results of another.

    Security awareness trainingPhishing simulationSocial engineering penetration test
    GoalTeach people what attacks look likeMeasure and train email behavior over timeProve what an attacker could actually achieve
    ChannelsVideos, modules, quizzesMostly emailEmail, phone, help desk, SMS, physical
    Run byTraining platformAutomated platformTesters, increasingly with AI support
    CadenceAnnual or quarterlyMonthlyAnnually, or before an audit or major change
    OutputCompletion ratesClick and report ratesFindings tied to failed controls, with remediation steps
    Answers"Did people take the training?""Do people click?""Could someone talk their way into our systems?"

    They work best together. Training sets expectations, simulations keep email habits sharp, and a social engineering penetration test checks whether the processes behind your people, especially the phone and the help desk, would survive a real attacker.

    How a social engineering engagement runs

    Authorized engagement stages from approval and scoping to testing, reporting and retesting

    1. Scope and authorization. Agree on objectives, channels, target groups, off-limits topics and people, and what the tester is allowed to do with anything captured. Everything is written into rules of engagement and signed before a single email or call goes out.
    2. Reconnaissance. Testers collect public information the way an attacker would: your website, staff on LinkedIn, vendor relationships, phone trees, email formats and job postings.
    3. Pretext design. Each scenario is built around a believable story for a specific audience. A help desk pretext sounds nothing like a vendor payment pretext.
    4. Execution. Campaigns and calls run within the agreed window. Calls are recorded or transcribed where the law and your policy allow, so every result is evidenced.
    5. Reporting and retest. The report maps each success to the control or process step that failed, ranks the fixes, and sets up a retest to confirm they worked.

    Two things separate a good provider here. First, ethics: the engagement should be designed to fix processes, not to embarrass or punish individuals. Second, data handling: social engineering produces sensitive workforce data, including recordings and captured credentials, so retention and deletion terms belong in the contract.

    Example scope: authorized vishing for a healthcare organization

    This is a representative scope for a healthcare organization, not a description of an identifiable client or a completed engagement. Organization size, locations, technology vendors and contact routes are deliberately omitted.

    • Targets: a limited, approved sample of administrative, operational and IT support roles. Results are reported by workflow rather than identifying individual employees.
    • Route: only contact channels explicitly approved in the written rules of engagement, during agreed testing windows.
    • Scenario: a simulated account-support request used to evaluate identity verification, escalation and reporting procedures. Test accounts and non-sensitive markers replace real credentials.
    • Off limits: patients, patient records, clinical decisions, live account changes and anything that could interrupt care. The organization can stop the test at any time.
    • Success criteria: aggregate rates of completed verification, appropriate escalation, reporting and deviations from the approved account-support process.

    The deliverable is a workflow-level findings report with remediation priorities and an agreed retest, without publishing staff identities or organization-specific operational details.

    How much does a social engineering penetration test cost in 2026?

    Published market ranges are fairly consistent:

    SourcePublished rangeWhat it covers
    Synack 2026 pricing guide$3,000 to $12,000Phishing, vishing and physical pretexting, varying by targets, campaigns and reporting
    vCSO.ai 2026 pricing guide$5,000 to $20,000Phishing-only at the low end; phone pretexting and physical access at the high end
    Triaxiom SecurityAbout $3,690 for a small engagement, more than $10,000 for larger onesSmall example: vishing 5 people, spear phishing 5, bulk phishing 25

    What moves the price within those ranges:

    • Number of people targeted. Ten help desk calls and five hundred phishing emails are very different amounts of work.
    • Number of channels and campaigns. Each unique pretext needs its own research and design.
    • Depth of follow-through. Stopping at "they clicked" is cheaper than using captured access to show impact.
    • Physical testing. Travel and on-site time push engagements to the top of the range.
    • Retesting. Some providers charge for it separately. Ask.

    Vishing is where the economics are changing fastest. When every call needs a human operator, testing hundreds of employees by phone gets expensive quickly. AI voice agents can place the calls, adapt to how each person responds, and transcribe everything, while a senior tester designs the pretexts and validates the results. That is how we run vishing at StealthNet AI: AI agents make the calls at scale, and a senior US-based tester reviews and signs the findings. Engagements are scoped by the number of targets and calls and quoted at a fixed fee within one business day. You can also bundle social engineering with a technical pentest; see our pricing page for how one-time and annual engagements are structured, or our broader penetration test cost guide.

    Do compliance frameworks require social engineering testing?

    Usually not by name, but they increasingly expect evidence that it is happening.

    • PCI DSS 4.0 requires security awareness training that covers phishing and social engineering (Requirement 12.6.3.1). A social engineering test is strong evidence that the training works. See our PCI DSS pentesting page.
    • HIPAA requires a security awareness program for the workforce, and help desk and front desk staff in healthcare are frequent vishing targets. See our HIPAA pentesting page.
    • SOC 2 does not require social engineering testing, but auditors accept it as evidence for communication and awareness controls, and enterprise customers increasingly ask about it in security reviews. See our SOC 2 pentesting page.
    • Cyber insurers ask about phishing and payment verification controls at renewal, and a recent test with remediation evidence answers those questions directly.

    How to choose a social engineering testing provider

    Ask these five questions before you sign:

    1. Which channels do you test, and who runs the calls? Many providers only do email. If vishing is included, find out whether it is a person, an AI agent, or both, and who validates the results.
    2. Will you test our help desk specifically? If the answer is vague, the highest-risk workflow probably is not in scope.
    3. How do you report results? You want findings tied to failed controls and processes, not a list of employee names.
    4. How do you handle recordings, transcripts and captured credentials? Get retention and deletion terms in writing.
    5. Is a retest included? A process fix is only proven when the same pretext fails the second time.

    The bottom line

    Technical pentests tell you whether your systems can be broken. A social engineering penetration test tells you whether they can be talked open. For most organizations the highest-value starting point is not a giant multi-channel campaign. It is a focused vishing test of the help desk and the front-line teams that answer the phone, followed by a retest once the verification process is fixed.

    Want to hear what one of these calls sounds like? Try a live AI vishing call, read a sample vishing assessment report, or see how our vishing testing service works.

    Frequently asked questions

    Ready to find what attackers would find?

    AI-powered, hybrid, or fully manual penetration testing with audit-ready reports for SOC 2, PCI DSS, HIPAA, and CMMC. Most engagements can start within 24 hours.

    Share this article