Service
Scope

What we test, review, and validate.

Outcome of this engagement

Social Engineering Assessment helps your team measure resilience against phishing, vishing, credential capture, MFA push-fatigue, OAuth consent-phishing scenarios, and other approved social engineering scenarios while focusing improvement on systems and processes, not blame.

Phishing & vishing

  • Targeted phishing scenarios with controlled payloads
  • Vishing and voice-based pretexting
  • MFA push-fatigue and OAuth consent abuse

Process & response

  • User reporting paths and response timing
  • Help desk and account recovery resilience
  • Email security, identity, and detection control performance

Awareness uplift

  • Findings translated into specific learning moments
  • Recommendations for awareness, process, and tooling improvements
  • Optional defender debrief or replay
What You Receive

Social engineering findings your team can use.

  • Executive summary for non-technical stakeholders
  • Scenario-by-scenario results and timing
  • Aggregate user response and reporting metrics
  • Process and tooling findings beyond click rates
  • Email, identity, or detection control observations where in scope
  • Help desk or account recovery observations where in scope
  • Practical recommendations that prioritize process over blame
  • Findings review meeting
  • Optional educational moments for impacted users
  • Optional defender debrief or replay
  • Validation of improved controls or processes where included
  • Letter of attestation, where applicable
Beyond THE REPORT

Human risk is not solved by blaming humans.

Methodology Preview

A controlled process from scenario to improvement.

01
Define
02
Execute
03
Observe
04
Report
05
Improve
See Full Methodology
Why Canary Trap

Social engineering testing that measures systems, not just users.

Senior-led execution

Testing is led by experienced offensive security professionals, not handed off to junior operators following a script.

Ethical guardrails

Scenarios are scoped with clear rules, stakeholder sign-off, approved pretexts, and boundaries designed to protect employees while still producing useful findings.

Process-aware testing

We measure reporting paths, escalation, help desk resilience, account recovery, tooling, and response behavior alongside user interaction.

Modern attack coverage

Engagements can include phishing, vishing, MFA fatigue, OAuth consent abuse, credential capture, and other approved techniques relevant to your environment.

Practical reporting

Findings include operational context, aggregate metrics, control observations, and recommendations your security, IT, and leadership teams can use.

Project management

Every engagement includes clear communication, defined expectations, stakeholder alignment, and controlled escalation paths.

Validation

Where included, validation helps confirm that improved controls, processes, or reporting paths are working, not just documented.

Trust signals

Canary Trap is SOC 2 Type II certified, maintains an NPS above 95, and specializes in offensive security testing.

Related Services

Social engineering risk rarely stops at the inbox.

Red Team Exercise

Microsoft 365 Security Controls Review

Tabletop Exercise

FAQ

Social engineering assessment questions, answered plainly.

Next Step

Ready to scope your Social Engineering Assessment?

Book a Scoping Call