CyberPlay editorial team · Published · Updated · 8 min read
Guide and exercises in English

Social engineering training exercises let employees rehearse the awkward moment when someone asks them to bypass a normal check. The requester may sound helpful, senior, familiar or urgent. A useful exercise gives the employee a practical way to pause, verify through a trusted route and continue or escalate without having to prove that the requester is an attacker.
This guide includes three original dialogue cards and a shared verification process. Run them as announced role-plays using fictional people, accounts and company records. The aim is to practise the decision and uncover gaps in local procedures. No one needs to impersonate a real executive, collect passwords or surprise colleagues with an unannounced call.
What you’ll take away
- Practise a usable response to pressure, not just recognition of a scam label.
- Obtain verification contacts independently of the suspicious request.
- A familiar voice or convincing video is insufficient authorisation for a sensitive action.
- Make safe escalation practical and support employees who use it.
2. Define what counts as a trusted verification channel
A trusted channel is selected independently of the new request: an established supplier record, the approved staff directory, a known service desk portal or a contact already verified through the organisation’s process. A number inside a suspicious email is part of the same unverified request. Moving from that email to that number changes the medium, not the basis of trust.
Check the organisation’s actual directories before the exercise. If the right contact cannot be found, assign someone to fix that. Provide a fallback for time-sensitive situations and out-of-hours work. The learner needs a realistic alternative to compliance, not an instruction to “verify” with no way to do so.
3. Dialogue card: the helpful IT caller
Original fictional dialogue: Caller: “I am from support. We are fixing the meeting system before your next call.” Employee: “I have not raised a ticket.” Caller: “That is why I am contacting you. Read the sign-in code from your phone and I can finish.” The facilitator tells the learner that the employee has not initiated recovery and can access the known support directory.
A useful response is: “I cannot provide that code. I will contact the service desk through the normal route and refer to this request.” Practise saying it aloud. The learner can remain polite without accepting the caller’s claim. Add a second line in which the caller insists that delay will affect the team, and ask whether the verification route changes.
4. Dialogue card: the supplier’s new bank account
Original fictional dialogue: Supplier contact: “Our bank details changed. Please use the new account for today’s invoice.” Employee: “I need to follow our supplier-change procedure.” Supplier contact: “Our finance director has approved it; call the number in this message if necessary.” Context: the employee has an existing supplier record with a verified contact and an internal approval workflow.
The appropriate response is to keep the existing record unchanged until verification and approval are complete. The FBI recommends checking changes to account numbers or payment procedures through verification with the requester. In this exercise, make the independent contact source visible so the learner can demonstrate which record they use.

Expand image · Game screenshot · English interface
- Compare the changed details
Check which payment details changed and whether the request matches the expected invoice and work.
- Compare with trusted records
Compare with a trusted invoice, then verify changed bank details through the supplier contact already on record.
Section sources: Business Email Compromise
5. Dialogue card: a familiar voice asks for an exception
Original fictional dialogue: A voice message appears to come from a senior manager: “I need you to arrange a confidential payment before the meeting. I cannot speak now. Use the details in the follow-up message and keep this between us.” The learner’s role normally requires a separate approval before any such payment.
The employee should use the established approval process and an independently verified contact. The FBI has documented impersonation campaigns using AI-generated voice messages and recommends independent identity checks. A voice that sounds familiar is not a replacement for authorisation. The exercise should work whether the recording is synthetic, imitated or simply a genuine person asking for an unauthorised exception.
Section sources: Senior U.S. Officials Continue To Be Impersonated in Malicious Messaging Campaign
6. Use this five-step verification flow
Keep the flow short enough to practise in conversation. Adapt the reporting and approval steps to the actual task. For a low-consequence routine request, the normal process may already provide the necessary assurance. For a consequential change, make the independent check explicit and document the approval in the authorised system.
| Step | Question | Action |
|---|---|---|
| Pause | What action am I being asked to take? | Hold the sensitive action while checking it. |
| Locate | Where is the independently verified contact or process? | Use the existing directory, supplier record or approved portal. |
| Verify | Is the request authentic and expected? | Confirm through that route without using new contact details supplied by the requester. |
| Authorise | Does the process permit me to perform this action? | Obtain the required approval; identity alone does not grant authority. |
| Report or proceed | What did the check establish? | Escalate concerns or complete the legitimate task through the approved workflow. |
7. Run the role-play so everyone can practise
Use groups of three: requester, employee and observer. Give the requester the dialogue, give the employee the context and contact options, and give the observer the five-step flow. Rotate roles after a short debrief. The observer records actions and reasoning, not the employee’s acting ability or confidence. A written response should be available for anyone who prefers it.
Keep the request realistic but avoid personal threats, humiliation or references to someone’s private circumstances. Explain that the session is an exercise and make the boundaries clear. Use fictional account details and do not ask participants to send messages or approvals in real business systems. The practical output is a rehearsed response and a clearer process.
8. Include a legitimate request that passes the checks
Give one group a control scenario: the employee uses the existing support portal, confirms a ticket they initiated and receives instructions that match the approved procedure without disclosing a secret to a caller. Or finance independently verifies a supplier change and receives the required internal approval. The correct outcome is to complete the permitted task.
Ask what evidence made proceeding reasonable. This prevents the exercise from becoming an automatic refusal drill. The point is to make verification part of competent work. If the approved process is so slow that routine tasks cannot proceed, record that as a process problem for the owner to resolve rather than asking employees to improvise exceptions.
9. Debrief the pressure and the practical barrier
Ask each employee which part of the request made pausing difficult and what helped them maintain the check. The answer may involve hierarchy, deadlines, a desire to be helpful or uncertainty about policy. Let managers practise responding supportively when an employee verifies their request. A rule is easier to follow when senior people demonstrate that it applies to them too.
Record the barriers found: missing directory entries, unclear approval authority, inaccessible reporting tools or disagreement about emergency procedures. Give each one an owner and due date. Preserve only the information needed to improve the programme. There is little value in publicly ranking employees by how convincingly they resisted a fictional caller.
10. Follow the conversation with varied practice
Use the CyberPlay social-engineering directory to choose an interactive scenario that involves a similar decision. Read the game description and explain where its mechanics relate to the organisation’s actual process. A role-play rehearses language and coordination; a game can provide another opportunity to make choices and inspect consequences.
Later, change the channel or the requested exception and observe the first response. Ask whether the employee still finds an independent contact and follows the approval rule. Report performance on that exercise honestly. A successful conversation or a high game score does not establish that the organisation has eliminated impersonation risk.

Expand image · Game screenshot · English interface
- Reject an uninitiated request
Deny a sign-in approval you did not initiate, even if another message urges you to accept.
- Report through official support
Contact the established helpdesk or security team and explain when the unexpected approval requests appeared.
Put the decision into practice
Explore social engineering games, then rehearse the verification phrase and trusted contact route your own team would use.
Explore social engineering gamesSources and further reading
- Phishing scams: how to spot and report them — UK National Cyber Security Centre. Accessed 2026-09-13
- Business Email Compromise — Federal Bureau of Investigation. Accessed 2026-09-13
- Senior U.S. Officials Continue To Be Impersonated in Malicious Messaging Campaign — Federal Bureau of Investigation. Accessed 2026-09-13
Keep exploring
- Phishing email examples for training: inspect, verify and report
Use fictional phishing email examples for HR, invoices, deliveries and sign-ins, plus legitimate controls. Each includes a safe decision, verification route and debrief.
EN · 8 min read - AI security awareness training: safer workplace decisions about tools and data
Build practical AI security awareness training for employees: approved tools, sensitive inputs, output verification, connected permissions and original decision cards.
EN · 8 min read - Security awareness training topics: choose by role and workplace risk
Choose employee security awareness topics by role and workplace risk. Use a practical curriculum matrix for phishing, accounts, data, physical access, AI and reporting.
EN · 9 min read - Unexpected MFA request? What to do when you did not sign in
Received an MFA prompt you did not initiate? Learn when to deny it, verify a support call, report an accidental approval and practise the decision in English.
EN · 8 min read - QR-code phishing training: check the destination before the decision
Teach employees to handle QR-code phishing with destination checks, independent verification and realistic parking, workplace poster and sign-in exercises.
EN · 8 min read - Ransomware tabletop exercise for non-technical teams: a facilitator guide
Run a ransomware tabletop for non-technical teams with fictional injects, clear roles, escalation decisions, continuity questions and a downloadable facilitator pack.
EN · 8 min read
