Social Engineering & Phishing Defence JudgmentSocial Engineering & Phishing Defence Judgment. Nobody breaks in any more. They ask, and somebody says yes.
A scored diagnostic of the one security skill no firewall covers: what you do in the ninety seconds after a convincing request arrives — by email, by phone, by text, or at the office door.
Not a security quiz — a pretext test
Most awareness training checks whether you can define phishing. This one puts you inside 19 situations where a capable, careful professional could reasonably go either way: a service-desk caller who knows your manager's name, a supplier whose bank details changed this morning, a voice on the phone that sounds exactly like your finance director, a delivery driver at a door your hands are too full to guard.
The Lure Board is a new scoring design. Every situation is built on one of five pretext families — authority, urgency, reward, familiarity and fear — and every option carries a hidden verification weight and a reporting weight, scored separately from answer quality. The report shows which family of lure actually gets past you, which is what a targeted attacker only needs to find once.
Keying follows the published influence and phishing-susceptibility research, out-of-band verification practice in authentication guidance, and the reporting-culture evidence on why near misses go unspoken.
What you walk away with
Five pretext families, each showing how often you took the bait when that family was on offer — the blind spot, named.
Whether your checks run through channels the sender chose for you, or through one they could never control.
How fast a near miss becomes a warning that protects everyone else — the part of this skill that is not about you.
Email, phone, text, chat and the office door, scored separately, because the same person is rarely equally careful in all five.
Your weakest competencies converted into rules you can apply on Monday: the out-of-band check and the ten-minute reporting target.
Inside your report
Illustrative sample — your report is generated from your own responses.
Built for
- Every employee who handles money, access, customer data or a door badge
- Security and IT teams who need a judgment baseline, not another click-rate
- Finance, HR and executive-support staff, the roles attackers target first
Find out which pretext works on you — before somebody else does
30 scored exercises · about 30 minutes · full bespoke report with your lure board, Verification Discipline Index and Reporting Reflex.
₹649 (incl. GST) · assessment and full report, nothing further to pay
Frequently asked questions
Four competencies: verification before action, reading the pretext, guarding access and information, and reporting and team defence. It measures what a person would actually do across 19 realistic attacks — email, phone, text, chat and in person — rather than whether they can define phishing.
Every option carries a graded quality score keyed to published influence and phishing-susceptibility research, plus a hidden verification weight and a reporting weight. Those build your Verification Discipline Index and Reporting Reflex, and each situation is tagged with one of five pretext families so the report can show which lure gets past you.
Any employee who handles money, system access, customer data or building access, and the security teams who train them. Finance, HR and executive-support staff get the most from it, because those are the roles attackers approach first. No technical background is assumed.
About 30 minutes for 30 scored exercises. You get a full report built as a lure board: five pretext families with your bait-taken rate in each, both calibration dials, a channel strip, four banded competencies and two habits to build first — downloadable as a colour PDF.
Rs 649 in India (including GST) or US$6.99 elsewhere, one-time, for one full sitting and report. Commercial security-awareness platforms are sold as annual per-seat subscriptions and measure click rates rather than judgment. Organisations can assess teams through AssessAll credits at 15 credits per person.
Each one takes a single capability, puts you inside the situations where it is actually tested, and scores your choices against published evidence — with a report designed for that capability alone, not a template. They span hiring, compliance, education, operations and personal skill.
Browse the catalogue →Methodology: Measures applied judgment against social engineering through original situational items keyed to published evidence: Cialdini's principles of influence as the pretext taxonomy (1984; 2001) and their documented use in phishing lures (Workman, 2008), the persuasion-in-phishing findings on authority and urgency cues (Vishwanath et al., 2011; Wright & Marett, 2010), the Suspicion-Cognition-Automaticity model of phishing susceptibility (Vishwanath, Harrison & Ng, 2018), habituation and warning fatigue in security dialogs (Anderson et al., 2016), business email compromise and invoice-redirection patterns as publicly reported by national fraud and cyber agencies, out-of-band verification guidance in authentication practice (NIST SP 800-63 series), security-culture and reporting-behaviour research including the protection-motivation account of security intentions (Boss et al., 2015), just-culture reporting and the effect of blame on disclosure (Dekker, 2007), signal-detection framing of user warnings, physical-security research on tailgating and shoulder surfing, and public reporting on synthetic-voice and deepfake-enabled vishing. All items are original works; no vendor's simulation library or trademarked instrument is reproduced, and no affiliation is claimed.