Applied Judgment Assessment
Social engineering defence · every employee · browse the full catalogue

Social Engineering & Phishing Defence JudgmentSocial Engineering & Phishing Defence Judgment. Nobody breaks in any more. They ask, and somebody says yes.

A scored diagnostic of the one security skill no firewall covers: what you do in the ninety seconds after a convincing request arrives — by email, by phone, by text, or at the office door.

30 minutes30 scored exercisesEvidence-keyed scoringGlobal · INR & USD

Not a security quiz — a pretext test

Most awareness training checks whether you can define phishing. This one puts you inside 19 situations where a capable, careful professional could reasonably go either way: a service-desk caller who knows your manager's name, a supplier whose bank details changed this morning, a voice on the phone that sounds exactly like your finance director, a delivery driver at a door your hands are too full to guard.

The Lure Board is a new scoring design. Every situation is built on one of five pretext families — authority, urgency, reward, familiarity and fear — and every option carries a hidden verification weight and a reporting weight, scored separately from answer quality. The report shows which family of lure actually gets past you, which is what a targeted attacker only needs to find once.

Keying follows the published influence and phishing-susceptibility research, out-of-band verification practice in authentication guidance, and the reporting-culture evidence on why near misses go unspoken.

Four competencies of practical security judgment, each measured by at least six independent scored exercises:
Verification Before ActionReading the PretextGuarding Access & InformationReporting & Team Defence

What you walk away with

Your lure board

Five pretext families, each showing how often you took the bait when that family was on offer — the blind spot, named.

A Verification Discipline Index

Whether your checks run through channels the sender chose for you, or through one they could never control.

A Reporting Reflex reading

How fast a near miss becomes a warning that protects everyone else — the part of this skill that is not about you.

A channel strip

Email, phone, text, chat and the office door, scored separately, because the same person is rarely equally careful in all five.

Two habits to build first

Your weakest competencies converted into rules you can apply on Monday: the out-of-band check and the ten-minute reporting target.

Inside your report

Illustrative sample — your report is generated from your own responses.

Quality × Coherence
62FOCUS
Judgement quality75
Strategic coherence49
Verdict: Brilliant Fragments
The altitude corridor
Climbing
Ground-boundthe corridorDetached
1.3
Drop distance
17/28
At the level
1.0
Lift distance

Built for

  • Every employee who handles money, access, customer data or a door badge
  • Security and IT teams who need a judgment baseline, not another click-rate
  • Finance, HR and executive-support staff, the roles attackers target first

Find out which pretext works on you — before somebody else does

30 scored exercises · about 30 minutes · full bespoke report with your lure board, Verification Discipline Index and Reporting Reflex.

₹649 (incl. GST) · assessment and full report, nothing further to pay

Buy this assessment

No account needed to buy. Your name and email identify the purchase and Razorpay sends your receipt to that address.

Secure Razorpay payment · ₹649 includes 18% GST

Bought this already and lost the tab? Sign in and enter your purchase code under Claim a purchase on your dashboard.

Secure checkout · INR & USDFull report immediately after submission

Frequently asked questions

What does the Social Engineering & Phishing Defence Judgment assessment measure?

Four competencies: verification before action, reading the pretext, guarding access and information, and reporting and team defence. It measures what a person would actually do across 19 realistic attacks — email, phone, text, chat and in person — rather than whether they can define phishing.

How is it scored?

Every option carries a graded quality score keyed to published influence and phishing-susceptibility research, plus a hidden verification weight and a reporting weight. Those build your Verification Discipline Index and Reporting Reflex, and each situation is tagged with one of five pretext families so the report can show which lure gets past you.

Who is it for?

Any employee who handles money, system access, customer data or building access, and the security teams who train them. Finance, HR and executive-support staff get the most from it, because those are the roles attackers approach first. No technical background is assumed.

How long does it take and what do I get?

About 30 minutes for 30 scored exercises. You get a full report built as a lure board: five pretext families with your bait-taken rate in each, both calibration dials, a channel strip, four banded competencies and two habits to build first — downloadable as a colour PDF.

How much does it cost?

Rs 649 in India (including GST) or US$6.99 elsewhere, one-time, for one full sitting and report. Commercial security-awareness platforms are sold as annual per-seat subscriptions and measure click rates rather than judgment. Organisations can assess teams through AssessAll credits at 15 credits per person.

One of the AssessAll applied-judgment assessments

Each one takes a single capability, puts you inside the situations where it is actually tested, and scores your choices against published evidence — with a report designed for that capability alone, not a template. They span hiring, compliance, education, operations and personal skill.

Browse the catalogue

Methodology: Measures applied judgment against social engineering through original situational items keyed to published evidence: Cialdini's principles of influence as the pretext taxonomy (1984; 2001) and their documented use in phishing lures (Workman, 2008), the persuasion-in-phishing findings on authority and urgency cues (Vishwanath et al., 2011; Wright & Marett, 2010), the Suspicion-Cognition-Automaticity model of phishing susceptibility (Vishwanath, Harrison & Ng, 2018), habituation and warning fatigue in security dialogs (Anderson et al., 2016), business email compromise and invoice-redirection patterns as publicly reported by national fraud and cyber agencies, out-of-band verification guidance in authentication practice (NIST SP 800-63 series), security-culture and reporting-behaviour research including the protection-motivation account of security intentions (Boss et al., 2015), just-culture reporting and the effect of blame on disclosure (Dekker, 2007), signal-detection framing of user warnings, physical-security research on tailgating and shoulder surfing, and public reporting on synthetic-voice and deepfake-enabled vishing. All items are original works; no vendor's simulation library or trademarked instrument is reproduced, and no affiliation is claimed.