A Report Designed for Multiple Audiences
Like our network and web application reports, social engineering deliverables are designed to be useful to multiple audiences, from leadership making risk decisions to HR teams managing employee follow-up to IT teams tuning email filters and security controls.
Campaign Overview and Statistics
For each campaign type conducted (email, phone, SMS, physical), the report includes high-level statistics: number of individuals tested, open rates, click rates, credential submission rates, and call interaction rates. Presented with clear visual charts that make trends and outliers immediately apparent.
Progression and Sophistication Analysis
Because Grid32's campaigns are staged, starting broad and escalating in sophistication, the report shows at what level of attack sophistication your defenses and users begin to fail. This is more actionable than a simple pass/fail rate.
Individual-Level Results
Where authorized by the client, individual-level results are included, identifying which users fell for which campaigns. This enables targeted follow-up training for the highest-risk individuals, which is significantly more effective than organization-wide generic training.
Technical Findings and Recommendations
The report also covers how email filtering systems performed, whether phishing infrastructure was detected, how quickly alerts were generated, and specific configuration recommendations for email security controls. Every report concludes with prioritized recommendations spanning technical controls, policy changes, and training recommendations.
Turning Results Into Training
A social engineering report is most valuable when it drives improvement, not blame. Aggregate results identify which departments and scenarios need attention, and targeted training addresses those specific gaps rather than lecturing everyone equally. Re-testing after training then measures whether behavior actually changed. Handled this way, each campaign becomes a data point in a program that steadily lowers human risk, instead of a one-time snapshot that embarrasses a few employees.
Frequently Asked Questions
What does a social engineering report include?
A social engineering report presents campaign statistics, an analysis of how the attack progressed and how sophisticated it was, individual and department-level results, and technical findings with recommendations. It is written for both leadership and the security team.
What metrics appear in a social engineering report?
Reports typically include click rates, credential submission, and reporting rates, along with trends by group and over time. These metrics quantify human risk and show whether awareness efforts are working.
How should results be shared with employees?
Results should educate, not shame. Aggregate findings and targeted, supportive training improve behavior, while singling out individuals damages trust. The report is structured to support constructive follow-up.
Find out exactly how your organization responds to attack.
Grid32's social engineering assessments deliver the detailed, actionable results your security program needs.
Build Your Quote →