Social engineering security testing in India — your technology is secure. Your people are your attack surface. We find out how exposed they are.
No technical security control prevents a motivated social engineer who understands your organisation, your people, and your culture. SIRI Security assesses the human layer — phishing, vishing, AI voice-clone impersonation, pretexting, and physical tailgating — with behaviour analysis, targeted training, and every finding documented under attorney-client privilege.
Getting the headline statistic right
There's no single "85% of attacks" figure that's simultaneously true and current. The real picture is still alarming.
Some social engineering content cites a flat "85% of cyberattacks begin with a human element" statistic as settled fact. That figure exists, but it isn't a clean, current number — it traces back to Verizon's 2021 Data Breach Investigations Report, or to a Gartner prediction for what 2026 might look like, not a confirmed current rate. Verizon's most recent 2025 DBIR puts the human-element share of confirmed breaches at roughly 60%, a genuinely lower figure than the commonly repeated one. What's stayed high and consistent, from Verizon and Okta data, is a separate figure: roughly 98% of attacks involve social engineering at some stage, even when it isn't the sole cause of the breach.
None of that nuance changes the underlying case for testing the human layer — if anything, distinguishing "human element in the breach" from "social engineering used somewhere in the chain" makes the argument more precise, not weaker. What's genuinely escalated with specificity is the AI-enabled version of this threat. Generative AI has collapsed the cost of convincing impersonation: a voice can be cloned from as little as three seconds of publicly available audio, and every recorded earnings call, conference talk, or podcast appearance an executive has ever given is training data sitting in the open. Real, documented cases have already moved seven-figure sums through live, real-time deepfake video-call impersonation of executives — this is not a hypothetical red team scenario anymore.
For any organisation with executives who've ever spoken publicly on record, the practical question isn't whether an AI voice-clone or deepfake attempt against your finance team is plausible — it's whether your verification processes would actually catch it before a transfer clears. That's precisely what a well-run vishing and deepfake simulation is designed to find out before a real attacker does.
Measure, not blame
Findings improve security culture — we don't name individuals in client-facing reports.
Where the human layer actually fails
No technical security control prevents a motivated social engineer who understands your organisation
These are the recurring gaps behind the successful social engineering compromises SIRI's practice finds most often.
Phishing simulations using generic templates miss the real threat
Monthly phishing simulations using standard templates train employees to spot the simulation, not the targeted, context-aware spear phishing that sophisticated attackers actually use against high-value targets.
Executive impersonation bypasses financial controls
Business email compromise attacks impersonating CEOs, CFOs, and legal counsel have resulted in crore-scale fraudulent transfers in Indian organisations. The attack succeeds through social pressure and authority manipulation, not technical exploitation.
Physical security is undermined by helpful employees
Technical perimeter security is bypassed daily through physical social engineering — tailgating through secure doors, posing as IT support, and exploiting employees' natural inclination to be helpful.
Privileged users are the highest-value targets
IT administrators, finance approvers, and executives with elevated system access are the primary targets of sophisticated social engineering. Standard awareness training is not calibrated to their specific threat profile.
What we assess
Social engineering testing across every human attack vector
From targeted spear phishing campaigns through vishing assessments, physical tailgating, and post-assessment security awareness training.
Phishing Simulation Campaigns
Realistic phishing campaigns calibrated to your sector, your organisation's public information, and current threat intelligence, far beyond generic template emails, to simulate the targeted attacks your highest-risk users actually face.
Spear Phishing & Executive BEC
Targeted spear phishing against identified high-value individuals — executives, IT administrators, and finance personnel — simulating the business email compromise attacks that consistently cause the largest financial losses.
Vishing (Voice Phishing) Assessment
Telephone-based social engineering campaigns, including AI voice-clone simulations, impersonating IT support, vendors, regulators, and colleagues to assess whether your employees protect sensitive information and system access over the phone.
Physical Tailgating & Impersonation
Controlled physical social engineering assessment — tailgating through secure access points, visitor impersonation, IT support pretexting, and dumpster diving, revealing physical vulnerabilities technical controls cannot address.
USB & Removable Media Drop
USB drive drop assessments in parking areas, reception, and common spaces, testing whether employees connect unknown devices to corporate systems. A consistently effective initial access vector.
Security Awareness Programme
Post-assessment security awareness training calibrated to the specific failure modes identified in your assessment, targeting the employee groups and behaviour patterns the exercise revealed as highest risk.
AI has changed the social engineering threat landscape
AI-powered social engineering testing
Generative AI has dramatically lowered the cost and increased the sophistication of social engineering attacks — enabling personalised phishing at scale, AI voice cloning for vishing, and deepfake video for executive impersonation. These attacks are no longer theoretical; they are being used against organisations in India and globally. We assess your organisation's resilience to next-generation AI-assisted social engineering, including AI voice-clone vishing simulations and deepfake-resistant employee awareness training, so your team is prepared for threats that are already in the wild.
Evidence, not guesswork
What the "human element" statistics actually say — by source and year
Different reports measure different things. Here's how to read the numbers accurately rather than reaching for the biggest one.
| Source | Figure | What it actually measures |
|---|---|---|
| Verizon DBIR 2021 | 85% | Human element present in analysed breaches that year — the figure most often quoted, now dated |
| Verizon DBIR 2025 | ~60% | Human element in confirmed breaches — the most current comparable figure |
| Verizon / Okta | ~98% | Attacks involving social engineering at any stage — broader measure, different question |
| Gartner (prediction) | 85% by 2026 | Forecast for human error/social engineering share of breaches — a prediction, not a measured rate |
Sources: Verizon Data Breach Investigations Report, 2021 and 2025 editions; Verizon/Okta social engineering data; Gartner human-risk forecasting commentary. Figures vary by methodology and reporting period — cite the specific source and year rather than a single unattributed percentage.
Client outcomes
Measurable results
Estimated exposure closed after a BEC simulation revealed the exact control gap a real attacker later attempted to exploit.
In a 500-employee financial services campaign, falling to 8% six months after targeted training.
With a fraudulent MD-impersonation wire transfer request, before verification controls were implemented.
The exact BEC attempt the simulation predicted was successfully stopped by the controls it prompted.
How we assess
Four phases from scoping to training
From OSINT reconnaissance through campaign execution, analysis, and targeted behaviour change training.
Intelligence gathering & scoping
OSINT reconnaissance of your organisation, social media mapping, public executive information, vendor relationships, and organisational structure — the same intelligence gathering a real attacker would conduct.
Week 1Campaign execution
Phishing, vishing, physical, and USB campaigns executed per agreed scope, with real-time tracking of click rates, credential entry, callback rates, physical access success, and device insertion events.
Weeks 2–3Analysis & legal risk mapping
Comprehensive analysis of campaign results — overall susceptibility rates, highest-risk employee groups, most effective attack techniques, and legal risk mapping of identified vulnerabilities to regulatory and contractual obligations.
Week 4Training & remediation
Targeted security awareness training calibrated to observed failure modes, specific guidance for high-risk employee groups, policy recommendations, and technical control recommendations where human behaviour cannot be reliably changed.
Week 4–5Case study · Executive BEC simulation
Manufacturing company prevents ₹1.8 Cr loss after BEC simulation reveals finance team vulnerability
SIRI Security conducted a targeted BEC simulation against the finance team of a Hyderabad manufacturing company, impersonating the MD and requesting an urgent wire transfer to a new vendor account. Three of five finance team members would have processed the transfer without the verification controls that the simulation revealed were missing.
The organisation implemented dual-approval controls, verbal verification requirements, and targeted training, preventing an identical real attack six months later — a direct demonstration that the simulation's finding was exactly the vulnerability a real attacker would go on to try.
Representative matters
Typical engagements
All matters described generically to protect client confidentiality.
34% to 8% click rate, post-training
Conducted a targeted phishing campaign across 500 employees, achieving a 34% click rate and 18% credential submission rate before security awareness training, reducing to 8% and 3% in a follow-up assessment six months after targeted training.
Auditor impersonation, manufacturing CFO
Targeted the CFO and Finance team of a manufacturing company with an OSINT-driven spear phishing campaign impersonating their auditor, demonstrating a realistic Business Email Compromise attack path.
Data centre floor access via tailgating
Gained physical access to a data centre floor through a combination of tailgating and pretexting as an equipment vendor, exposing critical infrastructure without any technical attack.
3 password resets via cloned voice
Conducted an AI voice-clone vishing simulation targeting the IT helpdesk, successfully obtaining password resets for 3 accounts by cloning the voice of a known manager using publicly available audio.
Why SIRI
Social engineering testing backed by legal authority and behavioural insight
Social engineering findings reveal sensitive information about individual employees. SIRI's legal practice ensures all assessment activities are properly authorised, ethically conducted, and fully protected by privilege.
All findings under legal privilege
Social engineering assessments produce sensitive findings about specific employees and their security behaviour. SIRI documents all findings under privilege, protecting individuals and the organisation from exposure in regulatory investigations.
Sector-specific threat intelligence
Our social engineering campaigns are built from threat intelligence specific to your sector and organisation, replicating the actual techniques used against companies like yours, not generic phishing templates.
Legal authorisation framework
All physical and digital social engineering activities conducted under a comprehensive legal authorisation framework, protecting your organisation from liability and ensuring assessed employees cannot claim they were unlawfully targeted.
Behaviour change focus
Our assessment output focuses on behaviour change, not just vulnerability identification, providing specific, actionable training recommendations based on the actual failure modes observed in your organisation.
The comparison
Without SIRI versus with SIRI
| Capability | Generic security awareness training | SIRI Security Social Engineering Assessment |
|---|---|---|
| Phishing realism | Template emails employees learn to recognise as simulations | Campaigns built from OSINT of your actual organisation — real context, real sophistication |
| Vector coverage | Digital threats only — physical and voice vectors untested | Full-scope: phishing, vishing, physical tailgating, impersonation, and USB drops |
| Threat calibration | Generic content not calibrated to your sector | Campaigns calibrated to the specific TTPs used against your sector |
| Employee data exposure | Individual susceptibility data recorded without legal protection | Findings documented under privilege — individuals protected from identification |
Frequently asked
Social engineering, answered directly
What percentage of cyberattacks actually start with a human element?
The figure depends on which report and which year — Verizon's 2025 Data Breach Investigations Report puts the human element at roughly 60% of confirmed breaches, down from higher figures in earlier years, while separate Verizon and Okta data suggests around 98% of attacks involve some social engineering component at any stage. An often-cited "85%" figure traces to Verizon's 2021 report or to a Gartner prediction for 2026, not a single current confirmed rate. What all of these sources agree on, regardless of the exact number, is that the human layer is involved in the clear majority of successful attacks — which is the premise this practice is built on, without needing to inflate any one statistic to make the point.
How real is the AI voice-clone and deepfake threat for Indian organisations specifically?
Very real and growing quickly. India is projected to see roughly 8 million deepfake images in 2025 alone, an increase of around 900% year on year according to I4C and industry estimates, and voice cloning requires as little as three seconds of publicly available audio — a bar every executive with a recorded earnings call, keynote, or podcast appearance has already cleared. The Indian government's deepfake takedown rules, effective February 2026, now require platforms to remove flagged deepfake content within 3 hours of a court or government order, reflecting how seriously the threat is now being treated at a regulatory level.
How do you avoid legal liability when testing employees with phishing or vishing simulations?
All physical and digital social engineering activities are conducted under a comprehensive legal authorisation framework that both protects the organisation from liability and ensures assessed employees cannot claim they were unlawfully targeted. Findings are documented under attorney-client privilege and reported at an aggregate, process level rather than by naming individuals, which is also how we avoid creating data that could later surface in an employment dispute.
Is social engineering testing punitive toward the employees who fail a simulation?
No. Our assessments are designed to measure susceptibility in order to improve it, not to embarrass or penalise individuals. Client-facing reports present aggregate metrics and process findings — the specific control gaps that allowed a simulation to succeed — rather than naming which employees clicked, called back, or opened a door. The goal is behaviour change and process improvement, not blame.
Do you test physical security alongside digital social engineering?
Yes. Full-scope engagements include physical tailgating, badge cloning, visitor impersonation, IT-support pretexting, and dumpster diving alongside phishing and vishing campaigns, since network security that resists digital attack is frequently accessible through physical means most assessments never test.
What happens after the assessment — do we get more than a list of who failed?
Every engagement includes a campaign report with aggregate metrics, process vulnerability findings (the control gaps that enabled success, such as no callback verification for password resets), and targeted training content built around the specific scenarios your employees actually fell for, not generic awareness slides.
Ready when you are
Your people are the most targeted element of your security architecture. Test them before attackers do.
Book a confidential social engineering assessment with SIRI Security. We will reveal your human attack surface with the sophistication of a real threat actor, and help you close the gaps.
Related services
Other ways SIRI Law LLP protects your human attack surface
Red teaming & adversary simulation
Social engineering as one vector in a full-scope adversary campaign.
Ransomware & crisis legal response
24/7 response if a phishing or BEC attempt succeeds against your team.
Employment & labour law
Employee monitoring and DPDPA-compliant training programme design.
Visit or contact us
SIRI Law LLP — Hyderabad, India
| Registered office | HITEC City, Madhapur, Hyderabad, Telangana 500081, India |
| Telephone | +91 79819 12046 |
| info@sirilawllp.com | |
| Other offices | New Delhi, India · Austin, Texas, USA · Online worldwide |
| Hours | Mon–Sat, 9:30 AM – 7:00 PM IST · Emergency line 24/7 |

