GetPentest

Social engineering and phishing testing

There are two products here with very different price tags. One is a subscription that phishes your staff every month. The other is a person on the phone talking your service desk into resetting a password. Most companies buy the second when they needed the first.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

A social engineering engagement in Canada costs between $5,000 and $20,000 CAD and runs three to eight tester days, depending on whether it is a phishing campaign alone or includes voice calls and a pretext to reach something specific. A phishing simulation platform, which is a different purchase entirely, costs roughly $3 to $8 CAD per user per year and runs continuously. For most companies under a few hundred staff the platform is the better buy and the engagement is a luxury. Awareness is a habit, not an event.

$3 to $8 CAD per user per year for a simulation platform, against $5,000 to $20,000 CAD for one engagement

The two products, and which one you need

They answer different questions. A platform answers whether your staff, in aggregate, are getting better at spotting a generic lure over time. An engagement answers whether a determined person with a plausible story can get a specific thing out of a specific team this month. Those are not degrees of the same product.

Phishing simulation platform against a social engineering engagement
Simulation platformSocial engineering engagement
What it measuresAggregate staff behaviour, trending over monthsWhether one attack path works, once
MethodTemplated emails on a schedule, automatedA tester researching your company and writing bespoke lures
RunsContinuously, monthly or quarterlyOnce, over one to two weeks
Typical Canadian cost$3 to $8 CAD per user per year$5,000 to $20,000 CAD per engagement
Includes voice callsRarely, and usually as an expensive add-onYes, if scoped
Produces an auditor-ready artifactYes, a training and testing recordYes, a report
Tells you if the service desk will reset a passwordNoYes, and this is the reason to buy one
Improves behaviourYes, through repetitionNo. One campaign changes nothing on its own

For most Canadian companies: buy the platform, run it for a year, and commission an engagement only if you have a specific worry a platform cannot reach. Wire transfer approval, service desk password resets and vendor payment changes are the three places where a bespoke pretext finds something a templated email never will.

What a real engagement contains

Phishing, but written for you

The difference between a platform email and an engagement email is research. A tester reads your website, your job postings, your LinkedIn presence and your public filings, then writes a lure that references a real project, a real vendor or a real internal system by name. That is the version that works, and why it costs tester days rather than cents per user.

Vishing, which is where the failures are

Voice calls to your service desk or your finance team, usually pretending to be a staff member locked out of an account or an executive travelling and in a hurry. Vishing succeeds far more often than email in most organisations. The pressure is real time and the person answering has been trained to be helpful. If you only scope one technique, this is the one that produces a finding worth acting on.

Pretexting and physical entry

Talking a way into a building, which overlaps with physical penetration testing and is normally scoped alongside it rather than separately. If your objective is to find out whether a stranger in a courier jacket reaches the server room, that is a physical engagement with a social engineering component, and it needs the authorisation paperwork described on that page.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

Click rate is the wrong number

Almost every phishing report leads with click rate, and almost every one is worse for it. Click rate measures how convincing that particular email was, which is a property of the tester's writing rather than of your company. Send a better lure and the number goes up. Send a worse one and it goes down. Either way, you have measured the email.

The number that means something is report rate: the proportion of recipients who told somebody. A company where 40 percent clicked and 55 percent reported is in far better shape than one where 8 percent clicked and nobody said anything, because the second company has no idea when it is under attack. Ask for these instead.

  1. Report rate, as a proportion of everyone who received the email, not of those who clicked.
  2. Time to first report, measured from the moment the first message was delivered. Under fifteen minutes is a working process.
  3. What your security team did with the first report, and how long it took them to pull the remaining copies from mailboxes.
  4. Credential submission rate, separately from click rate, because opening a link and typing a password into it are different failures.
  5. Repeat behaviour across campaigns, which is the only metric that shows whether anything is improving.

Do not use the results for discipline

Naming individuals who clicked, or attaching results to performance reviews, ends your reporting culture in a single campaign. Staff stop reporting because reporting reveals that they nearly fell for it. The whole value of the exercise is people telling you quickly, and you cannot buy that back once you have taught them not to. If your organisation cannot commit to aggregate-only reporting in writing before the campaign, do not run it.

Testing named employees means collecting personal information about their behaviour at work, and Canadian law on that is not uniform. Which statute applies depends on where you operate and what kind of business you are. Buyers rarely check before commissioning.

Whose personal information rules cover your employees
Your situationWhat governs employee personal information
Federally regulated business, such as a bank, telecom or airlinePIPEDA covers employee personal information directly
Private employer in QuebecQuebec's private sector law, as amended by Law 25, covers employee personal information
Private employer in British Columbia or AlbertaThe provincial PIPA in each province covers employee personal information
Private employer in Ontario or most other provincesNo general private-sector statute covers employee personal information. Your collective agreement and common law obligations still do
Public sector employer, any provinceThe provincial public sector access and privacy statute applies

A Quebec or BC employer has a legal analysis to do that an Ontario employer does not, and a unionised workplace anywhere has a collective agreement to check regardless of statute. The collection has to be for a purpose a reasonable person would consider appropriate, the results should be held in aggregate, and your privacy officer should have seen the plan. If you are already working through Law 25 obligations, fold this into the same review rather than treating it as a separate question.

What the authorisation must say

Social engineering is the engagement most likely to end with a tester explaining themselves to somebody who did not know. Work through this before the campaign starts, not after.

0 of 0 confirmed ·

The credential handling line is the one people skip. If your tester captures real passwords, those passwords are personal information under whichever statute applies to you, and they need to be stored and destroyed accordingly. Ask where the collection platform runs. A US-hosted tool holding your staff credentials raises the question covered on data residency during a penetration test.

Who should not buy an engagement

If you have never run a phishing simulation, do not start with a bespoke engagement. You already know the answer: some of your staff will click, and you will have spent $12,000 CAD to learn it. Buy the platform, run four campaigns, fix the service desk verification process, then commission an engagement to test whether the fix holds.

Do not buy one because a framework asked. No framework requires social engineering testing by name. ISO 27001 Annex A expects awareness training and evidence that it happened. A recurring platform satisfies that at a fraction of the price, and SOC 2 auditors ask for awareness evidence, not a red team narrative. And do not buy one during a layoff, a restructure or a contract dispute, whatever the security merit. The engagement will be read as surveillance, and it will be remembered longer than the findings.

Work out which of the two you need

Tell us your headcount, where your staff are and what you are worried about, and we will say whether this is a subscription or an engagement.

Get matched

Common questions

Do we have to tell staff we are running a phishing test?

Tell them the program exists, do not tell them when a campaign runs. A general notice in your acceptable use policy or your onboarding, saying that the company periodically tests staff with simulated phishing and that results are used in aggregate, gives you the transparency the privacy statutes expect without warning anyone about a specific email. Announcing each campaign in advance makes the exercise meaningless.

Is social engineering testing legal in Canada?

Yes, with authorisation from someone who has authority over the people and systems being tested. The complications are privacy and employment law rather than criminal law: employee personal information is regulated differently by province, unionised workplaces have collective agreements that may speak to monitoring, and impersonating a real third party such as a named bank or government agency creates separate problems you should avoid entirely.

Can the tester impersonate our CEO?

They can impersonate the role, and it is usually the most effective pretext available. Using the actual name of a real executive needs that person's own written agreement, not just the company's, because their reputation is being used. Impersonating an external organisation such as a bank, the Canada Revenue Agency or a real supplier is a different matter and reputable firms decline it.

What is a good report rate?

Above 30 percent of all recipients is a working reporting culture, and above 50 percent is unusual and good. The absolute number matters less than the direction across campaigns and the time to the first report. A company that moved from 12 percent to 35 percent over a year has bought something real. A company sitting at 40 percent for three years has plateaued and should change what it is testing rather than run the same campaign again.

Does this count as our annual penetration test?

No, and any firm suggesting it does is selling you something. Social engineering tests people. Your auditor, your customer questionnaire and your insurer are asking about systems, which means an authenticated test of the application or network that holds their data. The distinction between the two products is covered on types of penetration test, and what an auditor actually expects is on SOC 2 requirements.