Glossary
Social engineering
Social engineering is the manipulation of people so that a victim discloses information or performs an action that undermines the security of an organization.
The most common forms are email impersonation (phishing) and its targeted variants, attacks by phone and messaging, invented backstories used to build trust (pretexting), business email compromise aimed at redirecting payments, planted storage media, tailgating into controlled premises, and wearing a target down with repeated multi-factor prompts. Synthetic voice and video are increasingly used as well.
The attack does not exploit stupidity but the mechanisms everyday work depends on: authority, time pressure, the wish to be helpful, reciprocity, scarcity and fear of consequences. Attackers build credibility from open sources and the organization's digital footprint — names of executives, reporting lines, suppliers, projects and absences.
The most effective countermeasure is not a warning but a procedure independent of the channel the request arrived on: verification through a second path using a number from the internal directory, dual authorization for changes to payment details and for transfers, and clear rules on who may approve what. This is supported by training with simulations, technical controls such as email authentication, phishing-resistant multi-factor authentication and least privilege, and a culture in which reporting a mistake is fast and free of sanction.
Simulated attacks on employees involve processing personal data and touch the employment relationship, so they must be planned lawfully and ethically: agree the scope in advance, inform worker representatives, report results in aggregate rather than as an assessment of individuals, and collect the minimum data about participants.
Ready to strengthen security across your organization?
Contact us to see how our turnkey solutions can build a safer, more resilient organization.
