What is Social engineering?
Social engineering is manipulating a person into handing over information, access or money themselves. The attacker plays on trust, authority, fear, curiosity and urgency. Phishing, vishing and pretexting are all forms of social engineering.
Social engineering walks around technical controls: the strongest password is useless if an employee reads it out to "IT". Defending against it is a habit: verify before you give anything away.
How to spot it
- Emotional pressure or unexpected kindness
- Borrowed authority: "the director told me to"
- A request to break a rule "just this once"
What to do
- Pause and verify identity through another channel
- Say no politely but firmly
- Report it, even if you gave nothing away
Related courses
- Social engineeringSocial engineering techniques and defence: verifying calls, emails and identities, and checking links.
- Social engineering: advancedA scenario-based course: analysing phishing and smishing, and defence strategies.
- Why we fall for scamsEmotional triggers, abuse of trust and authority, and building a mental barrier against manipulation.
- Conversation securityWhat counts as oversharing, how information is coaxed out of people and how to say no politely.
Terms on this topic
More topics
Start with your team's risk baseline
15-30 employees, one phishing simulation and a one-page report for management. No annual commitment.