/ BLOG
Companies that prioritize cybersecurity typically build robust technical defenses. They segment their networks, implement EDR/XDR and SIEM systems, enable multi-factor authentication (MFA), and regularly conduct penetration tests on their infrastructure and applications. This is the essential foundation that ISO 27001 or PCI DSS auditors focus on first and foremost.
However, even a perfectly configured infrastructure remains vulnerable if an employee personally hands over a password to an attacker, confirms a payment in response to a fake email from a manager, or opens a malicious file sent by a colleague. A classic penetration test shows whether a system can be hacked technically, but it doesn’t address the most important question: Are employees capable of recognizing manipulation?
This problem is addressed through social engineering testing—a practical assessment of staff resilience to psychological manipulation.
The NIST SP 800-115 guideline clearly defines the role of social engineering in a security system. In the section titled “Target Vulnerability Validation Techniques”, the document classifies it as an official vulnerability validation technique—on par with penetration testing, password cracking, and application security auditing.
For businesses, this means that social engineering is no longer just an “optional extra.” NIST recognizes the human factor as a distinct risk and requires that it be assessed using specialized methods, rather than through technical audits.
The updated ISO/IEC 27001:2022 standard includes clause A.6.3, “Awareness, Education, and Training,” under the category of personnel controls. This requirement mandates that an organization provide systematic training on cybersecurity hygiene to employees and contractors.
A key aspect of the standard: it is not enough simply to conduct training—you must demonstrate its effectiveness. To pass the audit, it is not enough to provide an attendance log or lecture materials. The auditor requires concrete evidence that the staff has applied the knowledge in practice.
This is precisely where social engineering testing proves its value: it assesses employees' actual behavior in situations that closely resemble real-world attacks.
Regarding the PCI DSS 4.0 standard, it is important to distinguish between the mandatory requirements and the recommended practices of the PCI SSC:
● Requirement 12.6.3.1 mandates that training programs include topics on current threats, including phishing and social engineering.● Point 5.4.1 requires the implementation of technical and procedural mechanisms to protect email from phishing attacks. The standard clearly states that training is not a substitute for technical controls—they must work in conjunction with one another.● The PCI SSC recommends incorporating social engineering into the overall penetration testing methodology as a way to assess the effectiveness of training programs.
It is a common mistake to confuse this recommendation with a mandatory requirement. PCI DSS 4.0 establishes clear standards for training and technical safeguards, while the PCI SSC offers an additional approach—testing staff resilience during penetration tests.
What Do Social Engineering Tests Actually Reveal?
Without ongoing testing, it is impossible to assess the team’s true readiness. Technical reports may be flawless, but the actual risk of a targeted attack will remain unknown.
Social engineering testing provides transparent and measurable metrics:
● which departments are most likely to fall for it;● which manipulation tactics are most effective;● how quickly employees report suspicious activity to security.
Thanks to this data, the company can tailor its training program to actual needs rather than wasting its budget on formal training. Only this kind of comprehensive approach provides an understanding of the business’s objective readiness, since attackers always target the weakest link.
Infrastructure penetration testing and social engineering testing address different challenges: the former tests systems, while the latter tests people. International standards (NIST SP 800-115, ISO 27001, and PCI DSS 4.0) confirm that assessing staff awareness is a mandatory component of a mature information security system.
Social engineering testing by the IT Specialist team provides a realistic picture of how prepared your employees are to respond to a cyberattack. Our experts will help you turn employee awareness into a reliable line of defense.
Identify vulnerabilities in your system before real attackers exploit them! Submit a request for a consultation with IT Specialist experts to assess your business’s resilience and develop a testing scenario.
Our main specialisation is verifying the readiness of your business to real attacks, assessing the speed and effectiveness of your system and employee response.
We promptly identify and eliminate security threats before they inflict reputational or financial harm.
Sigma business centre,
6 Vatslav Havel Boulevard, building 3,
Kyiv, Ukraine, 03124
moc.tsilaicepsti-ym%40olleh
Our main specialisation is verifying the readiness of your business to real attacks, assessing the speed and effectiveness of your system and employee response.
We promptly identify and eliminate security threats before they inflict reputational or financial harm.
Sigma business centre,
6 Vatslav Havel Boulevard, building 3,
Kyiv, Ukraine, 03124
moc.tsilaicepsti-ym%40olleh
Наша головна спеціалізація - це перевірка готовності вашого бізнесу до реальних атак зловмисників, оцінка швидкості реагування та ефективності дій персоналу.
Ми оперативно виявляємо та усуваємо загрози безпеки ще до того, як вони перетворяться на репутаційні та фінансові проблеми.
Бізнес-центр Sigma,
бульвар Вацлава Гавела, 6, корпус 3,
Україна, Київ, 03124
moc.tsilaicepsti-ym%40olleh
Наша головна спеціалізація - це перевірка готовності вашого бізнесу до реальних атак зловмисників, оцінка швидкості реагування та ефективності дій персоналу.
Ми оперативно виявляємо та усуваємо загрози безпеки ще до того, як вони перетворяться на репутаційні та фінансові проблеми.
Бізнес-центр Sigma,
бульвар Вацлава Гавела, 6, корпус 3,
Україна, Київ, 03124
moc.tsilaicepsti-ym%40olleh