Roughly 90% of successful cyberattacks start with a human error. And the most dangerous version of that error is the one made in good faith because someone convinced the employee it was the right thing to do. That’s the
Social Engineering Training for Employees : exploiting trust, urgency, or fear to extract information or an action that damages the organization. To address it directly, Taqueen built something the corporate training space in Saudi Arabia hadn’t really seen before the Social Engineer vs Detective station, where the lesson isn’t delivered to participants but performed by them.
Picture a genuine role-play between two players: one sits in the red booth as the ‘attacker,’ the other in the blue booth as the ‘detective.’
The attacker holds a pre-written scenario card a story, a request, a claim that specifically designed to manipulate the other side.
The detective has to listen, analyze, and decide: is this a legitimate request, or a manipulation attempt in progress?
The scenarios range across fully realistic situations: an ‘IT support’ caller asking for a password to fix an urgent issue, someone claiming to be ‘from HR’ asking to confirm personal details for a promotion form, a ‘vendor’ requesting access to a shared file to finish an urgent contract.
Other participants watch and vote in real time did the detective catch the attempt or not?

Lectures about social engineering tell you what to watch for. This station makes you live it from both sides.
When an employee sits in the attacker’s booth, they understand for the first time how a manipulative request gets constructed to sound logical, urgent, and convincing. That inside-out understanding changes how they respond to similar situations at work in a way a warning slide never could.
And when they sit in the detective’s booth, they practice the harder skill: healthy suspicion without being rude to the person on the other side. How do you ask verification questions professionally? How do you handle a request marked ‘extremely urgent’ without caving to the time pressure?
The audience benefits too watching an attempt unfold from an observer’s seat builds calm, critical analysis skills that are harder to develop when you’re the one under pressure.
Through the Social Engineer vs Detective experience, participants get familiar with the tactics that show up most often in the Saudi corporate context:
Impersonating internal IT: ‘This is IT, there’s a problem with your account, I need your password to fix it.’ One of the most effective tactics because it exploits trust in an internal department.
Manufactured urgency: ‘This is extremely time-sensitive, the manager is waiting, we don’t have time for the usual process.’ Time pressure shuts down critical thinking fast.
Exploiting kindness: ‘No one else can help me, you’re the only one who can.’ The natural instinct to help others becomes a tool in the attacker’s hands.
Appeal to authority: ‘This request is coming directly from senior management.’ Invoking rank makes employees hesitant to question or verify.
Partial-but-true information: the attacker already knows your name, your manager’s name, and your current project pulled from LinkedIn which makes the whole approach feel credible.
The real impact of this station shows up in concrete, everyday behaviors after the event: employees start verifying the identity behind any ‘urgent’ request instead of reacting immediately. Teams adopt simple verification habits ‘I’ll call you back on the official number to confirm.’ People feel comfortable saying ‘I can’t confirm this without going through the official channel’ without feeling embarrassed about it.
That behavioral shift is the real goal behind everything Taqueen builds not just awareness that social engineering exists, but the reflexes that protect the organization even when the employee isn’t consciously thinking about security at all.
Social engineering rarely shows up in a breach report as its own line item, which is part of why it’s chronically underestimated. It shows up disguised as a phishing incident, a fraudulent wire transfer, or a leaked credential but trace almost any of those back to the first step, and there’s usually a phone call, an email, or a message that convinced someone to lower their guard.
The financial exposure isn’t limited to the direct loss either; incident response, regulatory reporting obligations under NCA frameworks, and the reputational cost of a public disclosure often outweigh the initial fraud amount several times over.
What makes this particularly relevant for the Saudi market right now is the pace of digital transformation across both government and private sectors. As more services move online and more employees handle sensitive data digitally, the attack surface for social engineering grows in parallel and attackers have shown they adapt their scripts quickly to local context, referencing Saudi bank names, government portal names, and even Ramadan or Hajj-season promotions to make their approaches more convincing to a distracted or time-pressed employee.
Many organizations already run periodic phishing simulations a fake email goes out, and IT tracks who clicks. That’s a useful data point, but it only tests one narrow channel and one narrow moment.
Social Engineer vs Detective covers ground a phishing simulation structurally can’t: phone-based pretexting, in-person impersonation, and the kind of multi-step manipulation that builds trust over several interactions before making the actual ask.
It also captures something phishing simulations miss entirely how someone behaves when they’re put on the spot verbally, in real time, with no delete button and no time to think it over quietly at their desk. That live, verbal pressure is exactly the condition under which most real social engineering attacks succeed, which is why rehearsing it live, even in a game format, closes a gap that email-based testing leaves wide open.
The station’s real value shows up weeks later, not on the day itself. Taqueen encourages clients to pair the experience with a simple, written verification policy that employees can point to afterward something as short as: any request involving credentials, payments, or personal data gets confirmed through a known official channel before action is taken, no exceptions, regardless of how senior the requester claims to be.
Organizations that reinforce this with visible internal messaging in the weeks following the event tend to see the habit stick far longer than those that treat the station as a one-off activity. A short follow-up email referencing specific moments from the day, or a poster near common workspaces reminding staff of the verification habit, keeps the lesson active instead of letting it fade the way most training does within a month.
Some organizations initially ask why they need a physical booth experience when they could simply distribute a written case study describing a social engineering incident and the lessons learned.
The honest answer is that reading about someone else’s mistake and making the decision yourself, live, activate very different parts of memory.
A written case study is processed the way any other document is processed skimmed, filed away, mostly forgotten.
Sitting in the blue booth and having to decide, out loud, in front of an audience, whether the person across from you is lying puts the employee’s own judgment on the line in a way reading never does.
That difference is precisely why Taqueen built the station as a face-to-face format rather than a video-based or written exercise. The discomfort of being watched while making the call is uncomfortable in the moment, but it’s exactly that discomfort that makes the lesson durable afterward.
Government entities and regulated organizations in Saudi Arabia typically already have some form of documented awareness training tied to NCA Essential Cybersecurity Controls. Social Engineer vs Detective isn’t meant to replace that documentation it’s meant to be the part of the program that actually changes behavior rather than just satisfying a reporting requirement.
Many clients fold participation data from this station directly into their existing compliance records, using it as evidence of active, hands-on engagement rather than passive attendance.
This dual role genuine behavior change plus a documentable training activity is one of the more practical reasons government clients in particular tend to request this station specifically when planning their annual awareness cycle.
Taqueen strongly encourages every participant to sit in both booths across the course of an event, rather than staying in whichever role feels more comfortable. The pattern that shows up almost every time is that people who felt confident as a ‘detective’ often struggle more than they expected once they switch to the attacker’s chair and have to construct a convincing pretext themselves.
That struggle is informative it usually means their earlier confidence was based on hindsight bias, recognizing a scripted scenario as suspicious because they knew it was a test, rather than a genuinely sharpened instinct for spotting manipulation under real ambiguity.
Running both sides back to back, in the same session, is part of why the lesson tends to be more honest than a one-directional test. It’s much harder to overestimate your own resistance to manipulation after spending five minutes trying, and mostly succeeding, to manipulate someone else using the same techniques attackers rely on every day.
Facilitators often note that the debrief conversation after both rounds tends to be the most candid part of the entire station.
Once someone has played the attacker and felt how easy it was to construct a convincing lie, they talk about their own past behavior messages they answered too quickly, requests they didn’t question with noticeably more honesty than they would in a standard feedback survey.
That candor is, in its own way, one of the more valuable outputs of the whole session, since it gives facilitators a genuine read on where an organization’s real vulnerabilities sit, straight from the people who actually handle those requests every day.
A: Yes, and non-technical staff often benefit the most, since they’re typically the most frequently targeted by social engineering attempts. The scenarios reflect everyday situations they’re likely to encounter at work, from a suspicious phone call to a message that looks like it came from a colleague.
A: Taqueen’s cybersecurity specialists build the scenarios based on documented social engineering attacks relevant to the Saudi and Gulf context, drawing on real reported incident patterns rather than generic templates borrowed from unrelated markets, and refreshing the scenario bank periodically as new tactics emerge.
A: Absolutely — it’s a core part of the full Interactive Cybersecurity Awareness Event and typically follows the Cyber Expert Station so participants can put what they just learned into practice immediately, while the context from that earlier conversation is still fresh.
A: Watching from the audience’s perspective builds critical analysis skills. Observers often evaluate the attempt more accurately than the person directly in the moment, precisely because they’re not under the same pressure, and many report noticing manipulation tactics they hadn’t consciously registered before watching someone else navigate them live.
A: Each role lasts 3 to 5 minutes, with the option to switch roles. In larger events, the station can run continuously throughout the day, with facilitators rotating fresh pairs of participants through as foot traffic allows.
To know more about about products from Here
The best way to protect your employees from social engineering is to let them experience it firsthand, safely, and from both sides of the conversation. Taqueen’s Social Engineer vs Detective station does exactly that — in a way nobody forgets, and in a way that shows up later in how people actually respond to a suspicious call at their own desk.