Saltar al contenido
02 · Auditoría02 · Auditing

Ingeniería SocialSocial Engineering

Campañas de phishing, vishing, smishing y pretexting.Phishing, vishing, smishing and pretexting campaigns.

Informes por departamentoReporting by department 2.4 · Auditorías Especializadas2.4 · Specialised Audits

¿Qué es este servicio?What is this service?

Es la prueba del factor humano mediante campañas controladas: correos de phishing, llamadas de vishing, mensajes de smishing y pretextos presenciales, todo con autorización y con métricas por área.

Testing the human factor through controlled campaigns: phishing emails, vishing calls, smishing messages and in-person pretexts, all authorised and measured by department.

¿Para qué se usa?What is it used for?

Permite medir con datos, no con suposiciones, qué tan expuesta está la organización al vector de entrada más usado. Lo importante no es cuánta gente hace clic sino cuánta reporta: una organización donde el veinte por ciento hace clic pero alguien avisa en tres minutos está mejor que una donde nadie hace clic y nadie reporta nada.

It measures with data rather than assumptions how exposed the organisation is to the most used entry vector. What matters is not how many people click but how many report: an organisation where twenty per cent click but somebody raises the alarm in three minutes is in better shape than one where nobody clicks and nobody reports anything.

Qué beneficios traeBenefits it delivers

  • Da una métrica objetiva y comparable en el tiempo, que sirve para justificar la inversión en concienciación.
  • Mide la tasa de reporte, que es el indicador que de verdad protege y que casi nadie sigue.
  • Identifica áreas y perfiles que necesitan refuerzo específico, en vez de formar a todos por igual.
  • Prueba de paso los controles técnicos: si el correo llegó a la bandeja, el filtro también falló.
  • Provides an objective metric comparable over time, useful to justify awareness investment.
  • Measures the reporting rate, the indicator that genuinely protects and that almost nobody tracks.
  • Identifies departments and profiles needing specific reinforcement instead of training everyone identically.
  • Incidentally tests the technical controls: if the email reached the inbox, the filter failed too.

¿En qué momentos es obligatorio?When is it mandatory?

Costa RicaCosta Rica

  • No hay obligación legal específica en Costa Rica.
  • Conviene atender el marco laboral y de protección de datos: la campaña trata datos de empleados, así que hay que definir bien la finalidad y evitar usar los resultados para sancionar de forma individual.
  • El respaldo de recursos humanos se consigue antes de empezar, no después.
  • There is no specific legal obligation in Costa Rica.
  • Employment and data protection law apply: the campaign processes employee data, so the purpose must be clearly defined and results must not be used to sanction individuals.
  • Human resources should be brought on board before the campaign starts, not afterwards.

InternacionalInternational

  • PCI-DSS y ISO 27001 exigen programas de concienciación, aunque no exigen simulacros de phishing en concreto.
  • El RGPD condiciona el tratamiento de datos de empleados durante la campaña, incluida la información de quién hizo clic.
  • Muchas aseguradoras preguntan por la frecuencia de las campañas de simulación.
  • PCI-DSS and ISO 27001 require awareness programmes, though they do not specifically require phishing simulations.
  • The GDPR conditions the processing of employee data during the campaign, including who clicked.
  • Many insurers ask about simulation campaign frequency.

Requisitos mínimosMinimum requirements

  • Autorización escrita de la dirección y coordinación con recursos humanos y con legal antes de lanzar la campaña.
  • Listado de destinatarios y definición de qué áreas entran.
  • Permitir el correo de la campaña en los filtros si se quiere medir al usuario y no al filtro; si se quiere medir el filtro, no se permite.
  • Acordar de antemano que los resultados individuales no se usan para sancionar.
  • Written management authorisation and coordination with human resources and legal before the campaign is launched.
  • A recipient list and definition of which departments are in scope.
  • Allowlisting the campaign email if the goal is to measure users rather than filters; if the goal is the filter, no allowlisting.
  • Agreeing up front that individual results will not be used for disciplinary action.

Plazo típico de entregaTypical delivery time

2 a 5 semanas 2 to 5 weeks rango habitual del mercado usual market range

El rango habitual del mercado por campaña va de dos a cinco semanas contando diseño del pretexto, ejecución escalonada e informe. El vishing y el pretexto presencial suman una o dos semanas más por la logística. Como programa continuo, lo habitual es una campaña cada uno o dos meses.

The usual market range per campaign runs from two to five weeks including pretext design, staggered execution and reporting. Vishing and in-person pretexting add one or two weeks for logistics. As an ongoing programme, one campaign every one or two months is typical.

NomenclaturaTerminology

Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.

PhishingPhishing
Engaño por correo para que la víctima entregue credenciales o ejecute algo. Email-based deception to make the victim hand over credentials or run something.
VishingVishing
El mismo engaño por llamada telefónica. The same deception conducted over a phone call.
SmishingSmishing
El mismo engaño por mensaje de texto o mensajería instantánea. The same deception conducted over text or instant messaging.
PretextoPretexting
La historia que sostiene el engaño y lo hace creíble. The story that sustains the deception and makes it credible.
Tasa de reporteReport rate
Porcentaje de personas que avisan del intento. Es la métrica que mejor predice la resistencia real. The percentage of people who report the attempt. It is the metric that best predicts real resilience.