TEST EVERY CHANNEL YOUR PEOPLE ANSWER
This playbook shows which channel gets a stranger through, and which procedure let them.
What you get
platform.
Channel Coverage
Phone, SMS, chat, and in-person pretext run alongside email, naming the channel that got through.
Pretext Sources
Each pretext traces to its source artifact: the job post, the published PDF, the profile page.
Procedure Failures
Each success names the step that let it through: the skipped identity check, the missing callback.
Contact Sequence
Which contact came first, what it produced, and which later contact spent it.
Where it stops
These limits are set in the authorization before any contact is made, and no channel outside them is worked.
No deep single-vector email campaign
One inbox lure worked end to end, from the click into the access it opens, is a bigger scope than this operation.
No physical entry. In-person pretext stops at the conversation
Badge cloning, lock bypass, and rogue device drops are out of scope.
No training and no remediation
The record tells you which procedure failed.
No scoring of individuals
The output names channels, pretexts, and procedures, and it is not built to rank employees.
No contact outside the authorized population
No personal channels either, unless you put them in scope in writing.
Who this is for
Start testingSecurity Awareness Lead
Your click rate is down and you still cannot say whether anyone would stop a convincing pretext call to the service desk.
Red Team Lead
You want the human path run alongside the technical one, because that is where the intrusion actually starts.
CISO
Training completion is a compliance number. It is not an answer to what happens when somebody credible phones your staff.
Questions
How is social engineering testing different from a phishing simulation?
A phishing simulation measures who clicked an email. Social engineering testing works the channels beside email — phone, SMS, chat, in-person pretext — and aims at the procedure on the other end, such as the identity check a help desk performs before a password or MFA reset.
Is social engineering testing legal?
Social engineering testing is lawful when it runs under written authorization from someone empowered to grant it, against a population and a set of channels named in advance. Call recording is a separate question: consent law varies by country and by US state, so the authorization has to address it explicitly.
Do employees have to know it is coming?
No individual target needs to know, but someone must. The standard arrangement is a small authorized group who can call the operation off, plus a written stop condition. Telling everyone tests nothing; telling nobody leaves no one able to stop it.
How much does Cracken do on its own?
Cracken operations run under an operator command model: by default each action waits for operator approval, and a workspace policy can raise that ceiling to auto-execute what you have decided is safe. Social engineering contact will run under that same model, and nothing will be dialed or sent that you have not authorized.
Put a stranger in front of your service desk.
Give us the population and the channels you want covered. We will map the operation and say plainly what runs today and what does not.





