Social Engineering
Social engineering is the psychological manipulation of people into performing actions or divulging confidential information. Rather than exploiting technical vulnerabilities, social engineers exploit human nature: trust, helpfulness, fear, and urgency.
Common techniques
Phishing: mass emails designed to trick recipients into clicking malicious links or providing credentials. Spear phishing: highly targeted emails crafted for specific individuals using personal information. Vishing (voice phishing): phone calls impersonating trusted entities like banks or IT support. Smishing: SMS-based phishing messages. Pretexting: creating a fabricated scenario to engage a victim and extract information. Baiting: offering something enticing (like a free USB drive) loaded with malware. Tailgating: physically following authorized personnel into restricted areas.
Why it works
Humans are wired to trust, help, and comply with authority. Social engineers exploit cognitive biases: authority bias (complying with perceived authority figures), urgency (acting without thinking when pressured), reciprocity (feeling obligated to return favors), and social proof (following what others appear to be doing). Even security-aware individuals can be caught off guard by sophisticated social engineering.
Building resilience
Regular security awareness training with realistic simulations. Establish clear verification procedures for sensitive requests (password resets, wire transfers, data access). Create a culture where employees feel safe reporting suspicious interactions without fear of punishment. Deploy technical controls that reduce the impact of successful social engineering (MFA, email filtering, DLP). Test regularly with simulated social engineering attacks.
Discuss this with a senior responder.
Discuss this with a senior responderNeed incident response?
- Two-hour SLA
- Dutch senior responders