August 3, 2026 · Alastor InfoSec Team
Phishing Simulation and Social Engineering Testing in 2026: Why 68% of Breaches Still Start With a Human
Every major breach investigation report in 2026 tells the same story: attackers did not get in by breaking through a firewall or exploiting an unpatched server. They sent an email, someone clicked, and the rest followed. The Verizon 2026 Data Breach Investigations Report found that 68% of confirmed breaches involved a human element — phishing, pretexting, or credential theft through social engineering — and the median time between a phishing email landing in an inbox and the user clicking was just 21 seconds. Twenty-one seconds is not enough time for rational threat evaluation. It is enough time for a reflex.
Despite this, most Indian security teams still treat phishing simulation as an annual checkbox. One campaign, a few hundred emails, a click rate reported to the CISO, a note in the board pack. This approach does not produce behavioural change. It produces a metric that looks reassuring until the real attack lands.
The 2026 Social Engineering Threat Landscape
The numbers in 2026 are not trending in the right direction. 42% of organisations cite phishing and social engineering as their top cyber risk, according to Secureframe's 2026 Social Engineering Statistics report. Business email compromise (BEC) — where attackers impersonate a CEO, CFO, or supplier to authorise fraudulent wire transfers or credential disclosure — now accounts for more than $50 billion in losses globally since 2013, with individual incident losses regularly exceeding $500,000.
Pretexting, the technique behind most BEC attacks, now accounts for more than half of all social engineering incidents. Attackers spend hours or days constructing a believable scenario — a fake invoice from a real vendor, an urgent request from a spoofed executive email, a password reset link that mirrors the organisation's actual SSO portal — before making contact. AI tools have compressed the time required to build convincing pretexts from hours to minutes, and the quality of the output has improved dramatically. In 2026, the phishing email that arrives in a C-suite inbox is grammatically flawless, contextually accurate, and addresses the recipient by first name.
For Indian businesses, the specific threat vectors include BEC targeting finance teams with vendor impersonation (particularly relevant in manufacturing and e-commerce), credential phishing targeting cloud application logins (Office 365, Google Workspace, SAP portals), and vishing — voice phishing — directed at IT helpdesks to social-engineer password resets or MFA bypass. CERT-In has observed a significant increase in vishing incidents targeting Indian organisations in 2025–26, with attackers posing as internal IT support.
Why Annual Simulations Don't Produce Behavioural Change
The core problem with once-a-year phishing simulations is that they train short-term awareness, not durable vigilance. The research on this is clear: a user who receives a simulated phishing test and clicks the link is significantly less likely to click on a similar test in the following four to six weeks. But after that window closes, click rates return to baseline. If the next simulation runs twelve months later, the organisation is essentially starting over.
The stubborn median: even after repeated awareness training, 1.5% of employees consistently click on phishing simulation links in every campaign. This is the cohort that requires the most attention — not because they are careless, but because they are likely in high-pressure roles where rapid email response is expected and clicking links is normalised. Finance teams, executive assistants, and customer-facing staff fall into this category disproportionately.
A mature programme runs simulations continuously — not the same template every month, but a varied campaign library covering different pretexts (invoice fraud, IT support requests, package delivery notifications, regulatory compliance demands), different delivery vectors (email, SMS smishing, voice calls), and different complexity levels that escalate based on individual performance. The goal is not to catch employees out — it is to create a sustained low-level awareness that makes anomalous requests feel anomalous.
What Comprehensive Social Engineering VAPT Covers
Phishing simulation is one component of a full social engineering VAPT engagement. A thorough assessment also includes open-source intelligence (OSINT) reconnaissance — gathering publicly available information about target employees from LinkedIn, corporate websites, and social media to understand the quality of pretext an attacker could construct. The OSINT phase often surfaces more than clients expect: employee names and roles, vendor relationships, internal project names, and sometimes email address formats — all usable in a targeted spear-phishing campaign.
Physical security testing — attempting to tailgate into office premises, impersonating delivery personnel, or testing reception staff's adherence to visitor verification procedures — remains part of a complete social engineering engagement even in a largely remote-working environment. Indian offices frequently score poorly on tailgating controls, and CERT-In has included physical security requirements in its compliance guidelines for critical information infrastructure.
Vishing simulations — scripted phone calls to helpdesk and IT support staff attempting to socially engineer account access, password resets, or MFA bypass — are particularly valuable because these attacks are rising and are rarely tested. A skilled vishing assessor can obtain full account access at most organisations in a single call by combining urgency, insider knowledge from OSINT, and authority impersonation. Testing this vector and training the targeted staff is the only effective countermeasure.
Building a Phishing Simulation Programme That Works
The structure of an effective programme has four components. The first is a baseline assessment — an initial simulation campaign against all staff using a realistic but not the most sophisticated pretext, to establish the organisation's starting click rate and credential submission rate. This gives you a measurement baseline and identifies the highest-risk departments.
The second component is continuous simulation — a rolling campaign across the year using varied templates, targeting different groups at different intervals, with escalating sophistication as the programme matures. The 2026 benchmark for a well-run programme is a click rate below 5% sustained over 12 months. Most organisations start above 14%.
The third component is just-in-time training — delivering training content immediately to the user who clicked, at the moment of highest receptivity, rather than scheduling them into a quarterly compliance module three months later. Research consistently shows that training delivered within minutes of a simulated click produces significantly better retention than deferred training.
The fourth component is measurement and reporting — tracking click rates by department, by template type, by time of day, and over time, so security leaders can demonstrate programme effectiveness and identify persistent high-risk cohorts. Under DPDPA, demonstrating that you have implemented employee security training is part of showing "reasonable security safeguards" — and documented phishing simulation results constitute evidence of that training.
The DPDPA Connection
Section 8(5) of the DPDPA requires Data Fiduciaries to ensure that their employees and data processors handle personal data in a manner consistent with the Act's obligations. CERT-In's compliance framework similarly requires employee awareness training as a documented control. Both requirements are satisfied by a continuous, documented phishing simulation and security awareness programme — not by a once-yearly campaign with no follow-through.
More directly: the most common initial access vector in breaches that trigger DPDPA notification obligations is a phished credential. Reducing credential phishing success rates reduces the probability of a breach that triggers regulatory notification. It is the most cost-effective risk control available.
How We Run Phishing Simulation Engagements
Alastor InfoSec's phishing simulation and social engineering VAPT engagements are designed to be operationally realistic rather than formulaic. We build custom pretexts based on OSINT reconnaissance of your organisation — using the same information an attacker would use — so simulations reflect actual threat scenarios rather than generic templates. Our campaigns cover email, SMS (smishing), and voice (vishing), and we provide just-in-time training delivery integrated directly into the simulation workflow.
Engagement outputs include department-level click rate analysis, credential submission rates, individual risk profiling for highest-risk users, OSINT findings from reconnaissance, and remediation recommendations covering both technical controls (email filtering, MFA enforcement, helpdesk verification procedures) and training programme design. Results map directly to DPDPA Section 8(5) and CERT-In employee awareness requirements.
Our red team engagements go further — combining phishing with physical access testing and post-click payload simulation to show the full attack chain, from initial email to data exfiltration, in your specific environment.
The statistics are unambiguous: the most effective way to reduce breach probability in 2026 is to reduce social engineering susceptibility. No firewall upgrade or SIEM deployment produces returns comparable to a mature, continuous phishing simulation programme — because most attackers will not bother breaking your perimeter if they can walk through the front door instead.
To discuss a phishing simulation engagement or full social engineering VAPT, contact us at [email protected] or learn more about our red team capabilities at /features/phishing-simulation.