Security awareness training tends to focus heavily on email phishing, for good reason — it’s the most common vector. But social engineering as a category is broader than email, and the other techniques succeed precisely because most training never covers them.
Vishing: phishing over the phone
A phone call from someone claiming to be IT support, a vendor, or an executive, requesting a password reset, remote access, or an urgent action. Voice adds urgency and social pressure that’s harder to pause and evaluate than a written email, and caller ID can be spoofed convincingly. We test this specifically in some engagements, and it’s consistently effective against staff who’d never click a suspicious link.
Pretexting: building a false scenario
A fabricated but plausible scenario — posing as a new hire needing account access, or a vendor confirming account details — used to extract information or access over an extended interaction rather than a single message. It relies on the same instinct to be helpful that makes good customer service good, which is part of why it works.
Physical tailgating
Simply following an authorized employee through a secured door, often while carrying something (boxes, a coffee tray) that makes holding the door open feel like basic courtesy rather than a security decision. Badge access and door locks provide no protection at all against this specific technique, since the technical control is bypassed by a social one.
Why the full picture matters
Training staff to be suspicious of email links while leaving phone requests, in-person visitors, and physical access largely untested leaves real gaps that a determined attacker will simply route around. A complete social engineering assessment tests more than the inbox, because a real attacker isn’t limited to it either.