📞 Call Now 💬 WhatsApp 📋 Report
⚖️
SIRI Law LLP
● Typically replies within 30 min
👋 Hi! How can SIRI Law LLP help you today?

We offer expert legal and cybersecurity advisory. Tap below for a confidential chat.
SIRI Law · Now
💬  Start Chat on WhatsApp
Social Engineering Security Testing in India | Phishing, Vishing, BEC — SIRI Law LLP
Social Engineering Security Testing · Hyderabad, India

Social engineering security testing in India — your technology is secure. Your people are your attack surface. We find out how exposed they are.

No technical security control prevents a motivated social engineer who understands your organisation, your people, and your culture. SIRI Security assesses the human layer — phishing, vishing, AI voice-clone impersonation, pretexting, and physical tailgating — with behaviour analysis, targeted training, and every finding documented under attorney-client privilege.

₹1.8 CrEstimated loss prevented in our BEC simulation case study below
~900%YoY growth in India's deepfake image volume, projected for 2025
3 hrsPlatform takedown window under India's Feb 2026 deepfake rules
3 secOf public audio needed to clone an executive's voice convincingly
The social engineering threat clock
Live tracking · scroll to see every relevant development
Standing
Verizon DBIR
2025 report: roughly 60% of confirmed breaches involve a human element — down from higher figures cited in some earlier and often-repeated stats.
Growing fast
2025
India projected to see approximately 8 million deepfake images, roughly 900% year-on-year growth, per I4C and industry estimates.
Trivial barrier
3 seconds
Of publicly available audio is sufficient to clone a voice convincingly — a bar every executive with a recorded talk, podcast, or earnings call has already cleared.
New rule
FEB 2026
India's deepfake takedown rules take effect, requiring platforms to remove flagged deepfake content within 3 hours of a court or government order.
Documented
Global
Real deepfake CEO fraud cases have moved seven-figure sums via live, real-time video-call impersonation — no longer a hypothetical threat model.
Standing
98%
Of cyberattacks involve social engineering at some stage, per Verizon/Okta data — even when the initial technical vector is something else entirely.

Getting the headline statistic right

There's no single "85% of attacks" figure that's simultaneously true and current. The real picture is still alarming.

Some social engineering content cites a flat "85% of cyberattacks begin with a human element" statistic as settled fact. That figure exists, but it isn't a clean, current number — it traces back to Verizon's 2021 Data Breach Investigations Report, or to a Gartner prediction for what 2026 might look like, not a confirmed current rate. Verizon's most recent 2025 DBIR puts the human-element share of confirmed breaches at roughly 60%, a genuinely lower figure than the commonly repeated one. What's stayed high and consistent, from Verizon and Okta data, is a separate figure: roughly 98% of attacks involve social engineering at some stage, even when it isn't the sole cause of the breach.

None of that nuance changes the underlying case for testing the human layer — if anything, distinguishing "human element in the breach" from "social engineering used somewhere in the chain" makes the argument more precise, not weaker. What's genuinely escalated with specificity is the AI-enabled version of this threat. Generative AI has collapsed the cost of convincing impersonation: a voice can be cloned from as little as three seconds of publicly available audio, and every recorded earnings call, conference talk, or podcast appearance an executive has ever given is training data sitting in the open. Real, documented cases have already moved seven-figure sums through live, real-time deepfake video-call impersonation of executives — this is not a hypothetical red team scenario anymore.

India's regulatory response has arrived, specifically
India is projected to see roughly 8 million deepfake images in 2025 alone, an increase of around 900% year on year according to I4C and industry estimates. The government's response followed: deepfake takedown rules effective February 2026 now require platforms to remove flagged deepfake content within 3 hours of a court or government order — a fast, specific compliance clock that mirrors the urgency organisations should already be applying to their own executive-impersonation defences.

For any organisation with executives who've ever spoken publicly on record, the practical question isn't whether an AI voice-clone or deepfake attempt against your finance team is plausible — it's whether your verification processes would actually catch it before a transfer clears. That's precisely what a well-run vishing and deepfake simulation is designed to find out before a real attacker does.

SIRI Law LLP social engineering security assessment

Measure, not blame

Findings improve security culture — we don't name individuals in client-facing reports.

Where the human layer actually fails

No technical security control prevents a motivated social engineer who understands your organisation

These are the recurring gaps behind the successful social engineering compromises SIRI's practice finds most often.

01 — TEMPLATES

Phishing simulations using generic templates miss the real threat

Monthly phishing simulations using standard templates train employees to spot the simulation, not the targeted, context-aware spear phishing that sophisticated attackers actually use against high-value targets.

02 — BEC

Executive impersonation bypasses financial controls

Business email compromise attacks impersonating CEOs, CFOs, and legal counsel have resulted in crore-scale fraudulent transfers in Indian organisations. The attack succeeds through social pressure and authority manipulation, not technical exploitation.

03 — PHYSICAL

Physical security is undermined by helpful employees

Technical perimeter security is bypassed daily through physical social engineering — tailgating through secure doors, posing as IT support, and exploiting employees' natural inclination to be helpful.

04 — PRIVILEGED USERS

Privileged users are the highest-value targets

IT administrators, finance approvers, and executives with elevated system access are the primary targets of sophisticated social engineering. Standard awareness training is not calibrated to their specific threat profile.

What we assess

Social engineering testing across every human attack vector

From targeted spear phishing campaigns through vishing assessments, physical tailgating, and post-assessment security awareness training.

01 / PHISHING

Phishing Simulation Campaigns

Realistic phishing campaigns calibrated to your sector, your organisation's public information, and current threat intelligence, far beyond generic template emails, to simulate the targeted attacks your highest-risk users actually face.

02 / SPEAR/BEC

Spear Phishing & Executive BEC

Targeted spear phishing against identified high-value individuals — executives, IT administrators, and finance personnel — simulating the business email compromise attacks that consistently cause the largest financial losses.

03 / VISHING

Vishing (Voice Phishing) Assessment

Telephone-based social engineering campaigns, including AI voice-clone simulations, impersonating IT support, vendors, regulators, and colleagues to assess whether your employees protect sensitive information and system access over the phone.

04 / PHYSICAL

Physical Tailgating & Impersonation

Controlled physical social engineering assessment — tailgating through secure access points, visitor impersonation, IT support pretexting, and dumpster diving, revealing physical vulnerabilities technical controls cannot address.

05 / USB

USB & Removable Media Drop

USB drive drop assessments in parking areas, reception, and common spaces, testing whether employees connect unknown devices to corporate systems. A consistently effective initial access vector.

06 / TRAINING

Security Awareness Programme

Post-assessment security awareness training calibrated to the specific failure modes identified in your assessment, targeting the employee groups and behaviour patterns the exercise revealed as highest risk.

AI has changed the social engineering threat landscape

AI-powered social engineering testing

Generative AI has dramatically lowered the cost and increased the sophistication of social engineering attacks — enabling personalised phishing at scale, AI voice cloning for vishing, and deepfake video for executive impersonation. These attacks are no longer theoretical; they are being used against organisations in India and globally. We assess your organisation's resilience to next-generation AI-assisted social engineering, including AI voice-clone vishing simulations and deepfake-resistant employee awareness training, so your team is prepared for threats that are already in the wild.

Evidence, not guesswork

What the "human element" statistics actually say — by source and year

Different reports measure different things. Here's how to read the numbers accurately rather than reaching for the biggest one.

Source Figure What it actually measures
Verizon DBIR 2021 85% Human element present in analysed breaches that year — the figure most often quoted, now dated
Verizon DBIR 2025 ~60% Human element in confirmed breaches — the most current comparable figure
Verizon / Okta ~98% Attacks involving social engineering at any stage — broader measure, different question
Gartner (prediction) 85% by 2026 Forecast for human error/social engineering share of breaches — a prediction, not a measured rate

Sources: Verizon Data Breach Investigations Report, 2021 and 2025 editions; Verizon/Okta social engineering data; Gartner human-risk forecasting commentary. Figures vary by methodology and reporting period — cite the specific source and year rather than a single unattributed percentage.

Client outcomes

Measurable results

₹1.8 Cr
Loss prevented, one engagement

Estimated exposure closed after a BEC simulation revealed the exact control gap a real attacker later attempted to exploit.

34% → 8%
Click rate, before/after training

In a 500-employee financial services campaign, falling to 8% six months after targeted training.

3 of 5
Finance team members would have complied

With a fraudulent MD-impersonation wire transfer request, before verification controls were implemented.

6 months
Later, real attack deflected

The exact BEC attempt the simulation predicted was successfully stopped by the controls it prompted.

How we assess

Four phases from scoping to training

From OSINT reconnaissance through campaign execution, analysis, and targeted behaviour change training.

01

Intelligence gathering & scoping

OSINT reconnaissance of your organisation, social media mapping, public executive information, vendor relationships, and organisational structure — the same intelligence gathering a real attacker would conduct.

Week 1
02

Campaign execution

Phishing, vishing, physical, and USB campaigns executed per agreed scope, with real-time tracking of click rates, credential entry, callback rates, physical access success, and device insertion events.

Weeks 2–3
03

Analysis & legal risk mapping

Comprehensive analysis of campaign results — overall susceptibility rates, highest-risk employee groups, most effective attack techniques, and legal risk mapping of identified vulnerabilities to regulatory and contractual obligations.

Week 4
04

Training & remediation

Targeted security awareness training calibrated to observed failure modes, specific guidance for high-risk employee groups, policy recommendations, and technical control recommendations where human behaviour cannot be reliably changed.

Week 4–5

Case study · Executive BEC simulation

Manufacturing company prevents ₹1.8 Cr loss after BEC simulation reveals finance team vulnerability

SIRI Security conducted a targeted BEC simulation against the finance team of a Hyderabad manufacturing company, impersonating the MD and requesting an urgent wire transfer to a new vendor account. Three of five finance team members would have processed the transfer without the verification controls that the simulation revealed were missing.

The organisation implemented dual-approval controls, verbal verification requirements, and targeted training, preventing an identical real attack six months later — a direct demonstration that the simulation's finding was exactly the vulnerability a real attacker would go on to try.

₹1.8 CrEstimated loss prevented
3 of 5Finance team members would have complied
6 monthsReal BEC attempt deflected post-training
BEC simulation Finance team Executive impersonation Process controls
BEC simulation engagement conducted by SIRI Law LLP

Representative matters

Typical engagements

All matters described generically to protect client confidentiality.

Phishing Campaign — Financial Services

34% to 8% click rate, post-training

Conducted a targeted phishing campaign across 500 employees, achieving a 34% click rate and 18% credential submission rate before security awareness training, reducing to 8% and 3% in a follow-up assessment six months after targeted training.

Executive Spear Phishing

Auditor impersonation, manufacturing CFO

Targeted the CFO and Finance team of a manufacturing company with an OSINT-driven spear phishing campaign impersonating their auditor, demonstrating a realistic Business Email Compromise attack path.

Physical Intrusion Assessment

Data centre floor access via tailgating

Gained physical access to a data centre floor through a combination of tailgating and pretexting as an equipment vendor, exposing critical infrastructure without any technical attack.

AI Vishing Simulation

3 password resets via cloned voice

Conducted an AI voice-clone vishing simulation targeting the IT helpdesk, successfully obtaining password resets for 3 accounts by cloning the voice of a known manager using publicly available audio.

Why SIRI

Social engineering testing backed by legal authority and behavioural insight

Social engineering findings reveal sensitive information about individual employees. SIRI's legal practice ensures all assessment activities are properly authorised, ethically conducted, and fully protected by privilege.

01 — Privilege

All findings under legal privilege

Social engineering assessments produce sensitive findings about specific employees and their security behaviour. SIRI documents all findings under privilege, protecting individuals and the organisation from exposure in regulatory investigations.

02 — Realism

Sector-specific threat intelligence

Our social engineering campaigns are built from threat intelligence specific to your sector and organisation, replicating the actual techniques used against companies like yours, not generic phishing templates.

03 — Authorisation

Legal authorisation framework

All physical and digital social engineering activities conducted under a comprehensive legal authorisation framework, protecting your organisation from liability and ensuring assessed employees cannot claim they were unlawfully targeted.

04 — Outcomes

Behaviour change focus

Our assessment output focuses on behaviour change, not just vulnerability identification, providing specific, actionable training recommendations based on the actual failure modes observed in your organisation.

The comparison

Without SIRI versus with SIRI

Capability Generic security awareness training SIRI Security Social Engineering Assessment
Phishing realism Template emails employees learn to recognise as simulations Campaigns built from OSINT of your actual organisation — real context, real sophistication
Vector coverage Digital threats only — physical and voice vectors untested Full-scope: phishing, vishing, physical tailgating, impersonation, and USB drops
Threat calibration Generic content not calibrated to your sector Campaigns calibrated to the specific TTPs used against your sector
Employee data exposure Individual susceptibility data recorded without legal protection Findings documented under privilege — individuals protected from identification

Frequently asked

Social engineering, answered directly

What percentage of cyberattacks actually start with a human element?

The figure depends on which report and which year — Verizon's 2025 Data Breach Investigations Report puts the human element at roughly 60% of confirmed breaches, down from higher figures in earlier years, while separate Verizon and Okta data suggests around 98% of attacks involve some social engineering component at any stage. An often-cited "85%" figure traces to Verizon's 2021 report or to a Gartner prediction for 2026, not a single current confirmed rate. What all of these sources agree on, regardless of the exact number, is that the human layer is involved in the clear majority of successful attacks — which is the premise this practice is built on, without needing to inflate any one statistic to make the point.

How real is the AI voice-clone and deepfake threat for Indian organisations specifically?

Very real and growing quickly. India is projected to see roughly 8 million deepfake images in 2025 alone, an increase of around 900% year on year according to I4C and industry estimates, and voice cloning requires as little as three seconds of publicly available audio — a bar every executive with a recorded earnings call, keynote, or podcast appearance has already cleared. The Indian government's deepfake takedown rules, effective February 2026, now require platforms to remove flagged deepfake content within 3 hours of a court or government order, reflecting how seriously the threat is now being treated at a regulatory level.

How do you avoid legal liability when testing employees with phishing or vishing simulations?

All physical and digital social engineering activities are conducted under a comprehensive legal authorisation framework that both protects the organisation from liability and ensures assessed employees cannot claim they were unlawfully targeted. Findings are documented under attorney-client privilege and reported at an aggregate, process level rather than by naming individuals, which is also how we avoid creating data that could later surface in an employment dispute.

Is social engineering testing punitive toward the employees who fail a simulation?

No. Our assessments are designed to measure susceptibility in order to improve it, not to embarrass or penalise individuals. Client-facing reports present aggregate metrics and process findings — the specific control gaps that allowed a simulation to succeed — rather than naming which employees clicked, called back, or opened a door. The goal is behaviour change and process improvement, not blame.

Do you test physical security alongside digital social engineering?

Yes. Full-scope engagements include physical tailgating, badge cloning, visitor impersonation, IT-support pretexting, and dumpster diving alongside phishing and vishing campaigns, since network security that resists digital attack is frequently accessible through physical means most assessments never test.

What happens after the assessment — do we get more than a list of who failed?

Every engagement includes a campaign report with aggregate metrics, process vulnerability findings (the control gaps that enabled success, such as no callback verification for password resets), and targeted training content built around the specific scenarios your employees actually fell for, not generic awareness slides.

Ready when you are

Your people are the most targeted element of your security architecture. Test them before attackers do.

Book a confidential social engineering assessment with SIRI Security. We will reveal your human attack surface with the sophistication of a real threat actor, and help you close the gaps.

or call +91 79819 12046 — Mon–Sat, 9 AM – 7 PM IST

Visit or contact us

SIRI Law LLP — Hyderabad, India

Registered officeHITEC City, Madhapur, Hyderabad, Telangana 500081, India
Telephone+91 79819 12046
Emailinfo@sirilawllp.com
Other officesNew Delhi, India · Austin, Texas, USA · Online worldwide
HoursMon–Sat, 9:30 AM – 7:00 PM IST · Emergency line 24/7
© SIRI Law LLP · Hyderabad, Telangana

All security testing is conducted under a signed rules-of-engagement agreement with explicit written authorisation from the asset owner. Findings are confidential and delivered only to authorised client representatives. References to human-element breach statistics, deepfake growth figures, and India's 2026 takedown rules reflect publicly available information as of publication and remain subject to further data revision; confirm current figures before relying on any specific statistic. Case study and representative matter details are described generically to protect client confidentiality. This page does not constitute legal advice. SIRI Law LLP is a registered law firm under the Limited Liability Partnership Act 2008, practising under the Advocates Act 1961; complaints regarding professional conduct may be directed to the Bar Council of Telangana.

Scroll to Top