Cyber attackers look for more than technical vulnerabilities. They look for the person who can let them in.

Through an email, text message, phone call or impersonation of a familiar contact, they try to persuade employees to share information, open a file, click a link or take an unsafe action.

Consienta, part of Yael Group’s Cyber Division, designs and runs simulations based on real-world attack methods. Tailored to the organization, its audiences and relevant threats, they test actual responses in a controlled setting.

Why Run Attack Simulations?

Knowing the warning signs does not always predict behavior. Even trained employees may respond differently when a message appears credible, relates to their role or creates urgency.

Simulations test what employees do: whether they recognize an impersonation attempt, avoid the requested action and report it through the right channel. This reveals gaps that training alone may miss and supports decisions based on data.

Types of Simulations

Phishing simulations
Campaigns simulate malicious emails and test responses to impersonation, suspicious links, attachments and unusual requests.

Scenarios can reflect the organization’s work, specific roles and different times of year. They are conducted under controlled conditions while protecting participants’ privacy.

Smishing simulations
Exercises simulate fraud through SMS or instant messages. They test responses to links, requests for information and prompts to act urgently.

Vishing simulations
Impersonation calls simulate contact from a supplier, service representative, colleague or internal team. They test identity verification, willingness to share information and responses to pressure or unusual requests.

Combined social engineering exercises
Scenarios use several communication channels and impersonation methods to recreate a more complex attack. For example, an email may be followed by a phone call, or a message may draw on information gathered from public sources.

These exercises test reporting, escalation and coordination between employees and security teams, as well as responses to emerging AI-related threats.

Open-Source Exposure Assessments (OSINT)

Before a simulation, Consienta can review business and personal information available from public sources that attackers could use to craft a credible, targeted approach.

The assessment identifies exposure relating to the organization, employees and key personnel. It shows how that information could be used in a social engineering attack and informs recommendations to reduce exposure.

A Tailored, Controlled Process

Scenario planning
Define the simulation’s goals, target audiences, attack channels, complexity and measures of success based on the organization’s risk profile.

Controlled execution
Run the simulation in coordination with relevant teams, protecting privacy and confidentiality, keeping the exercise proportionate and avoiding disruption to business operations.

Measurement and analysis
Track actions such as opening messages or files, clicking links, sharing information and reporting the attempt. Analysis reveals trends, at-risk groups and gaps in reporting processes.

Recommendations and next steps
A summary report presents findings, insights and practical recommendations. The results can guide targeted training, stronger reporting processes and follow-up simulations to measure improvement.

What Does the Organization Gain?

The simulations provide a practical view of how employees respond to impersonation attempts, helping the organization:

  • Identify behavior patterns and vulnerabilities.
  • Find groups and roles at greater risk.
  • Test reporting and escalation processes.
  • Target training based on the findings.
  • Measure trends and improvement over time.
  • Strengthen its response to attacks that exploit the human factor.