Social Engineering Roleplay

Recognize and resist phishing, pretexting, smishing, and social engineering attacks by practicing them live. The JoySuite assistant Joy plays the attacker from your own security-awareness material, then debriefs you on the red flags you caught and the ones you missed.

For All Employees Security Teams Finance & Executive Teams Compliance Officers
Sample prompt to Joy's Assistant

/roleplay a social-engineering attack from our security-awareness playbook: [an urgent call from a supplier changing bank details]. Play the attacker, then debrief me on the red flags I caught and missed.

What it can look like

/roleplaya social-engineering attack from our security-awareness playbook: an urgent call from a supplier changing bank details. Play the attacker, then debrief me on the red flags I caught and missed.

You're on the finance line; I'll play Joy, a caller posing as your supplier, drawn from your security-awareness playbook and the attacks your team has logged. I'll stay in character, then debrief you. It's month-end close, and the caller sounds calm and well-briefed.

Joy, from your supplier
Quick one before your close. We've switched banks, so today's invoice needs a new account. I'll read you the details; can you update the payee before the run?
I can't change bank details from a call. Any account change gets verified through the contact on file before anything is paid.
Joy
Of course, but the run closes in an hour and your AP lead already knows. Can you just make the change and note it?

Coaching

  • You spotted the core red flag, an unverified bank-detail change under time pressure, which is the exact pattern in the business-email-compromise cases your team logged last year.
  • Insisting on the callback-to-known-contact rule instead of the number the caller offers is the move that actually stops this attack. Don't let "your AP lead already knows" talk you out of it.
  • One you missed: the pretext leaned on real month-end context, so the caller did homework. Flag that reconnaissance to security; it often means the account is already being probed.

Want the same pretext delivered as a polished email thread instead of a call?

Point it at your own phishing library and run a smishing round for the mobile-heavy roles.

An illustrative example. Your output will reflect your own sources, data, and prompts. This is an abridged sample. A live /roleplay runs one turn at a time and keeps going for as long as you practice.

Learn by experiencing attacks (safely)

Your employees click on phishing links, then feel embarrassed when caught. Traditional training shows videos they forget. Real attackers use sophisticated pretexting, urgency, and authority tricks that a slideshow can't prepare anyone for. You need practice, not lectures.

  1. Point Joy at your material

    Upload your security-awareness playbook, real attacks your team has logged, and your verification procedures to the Knowledge Center, or connect the source. Joy grounds every pretext and debrief in your actual material.

  2. Start the roleplay

    Run Joy's /roleplay command and name the attack you want to face: a phishing email, an urgent IT call, a vendor impersonation. Joy sets the scene and plays the attacker.

  3. Practice live

    Joy stays in character, using real manipulation tactics (urgency, authority, a believable pretext) and responds to your moves in real time. You make the calls, and nothing is at risk.

  4. Get coaching and run it again

    After the exchange Joy steps out to debrief: the red flags you caught, the ones you missed, and how to report them. Vary the pretext or channel and go again.

  5. Make it one click for your team

    Save this ask as a custom command on the assistant your team already uses and customize it, so anyone can run the same drill in one step.

Make it yours

Realistic Simulations

Joy plays convincing attackers using actual manipulation tactics from phishing, pretexting, and smishing.

Instant Feedback

After each exchange, employees see what red flags they spotted and which ones they missed.

Vary and Repeat

Face the same pretext until spotting it is automatic, then switch the channel (email, SMS, a phone call) for a fresh drill every time.

Adaptive Scenarios

Scenarios respond to employee actions in real-time, creating unique learning experiences each session.

Phishing Email Practice

Practice identifying malicious emails: spotting fake sender addresses, suspicious links, and urgency tactics.

Smishing (SMS Phishing)

Practice identifying malicious text messages claiming to be from banks, delivery services, or IT, and knowing when not to click.

Pretexting Scenarios

Practice resisting elaborate cover stories designed to build trust before requesting sensitive information.

Executive Impersonation

Practice recognizing CEO fraud and business email compromise attempts that create false urgency.

Frequently Asked Questions

How does AI help with phishing awareness training?

JoySuite's AI plays realistic attackers using actual manipulation tactics. Employees practice responding to phishing, pretexting, and social engineering attempts in a safe environment with instant feedback on what they did right and wrong.

Is this more effective than phishing simulations?

Traditional phishing tests catch people but don't teach them. Roleplay training helps employees understand the tactics firsthand. One customer reduced click rates from 23% to under 5% after implementing roleplay training.

What types of social engineering attacks can employees practice?

Phishing emails, smishing (SMS phishing), pretexting (elaborate cover stories), CEO fraud, business email compromise, IT support impersonation, and vendor impersonation scenarios.

How do I make this available to my whole team?

Save the roleplay as a custom command on the assistant your team already uses, so anyone can start the same drill in one click. Point high-risk roles like finance or executives at the pretexts that target them, and run it as often as the reps are useful.

Does the training use real attack examples?

Yes. Upload real attacks your organization has seen, industry-specific threats, and common patterns. The AI generates scenarios based on actual tactics attackers use.

Ready to build your human firewall?

Join the waitlist and be first to try this workflow when JoySuite launches.