Human Risk Management: Countering Social Engineering
Social engineering is the art of manipulating people so they give up confidential
information. Unlike technical hacks, social engineering exploits human psychology—
trust, fear, and urgency.
1. Common Social Engineering Techniques
Phishing: The most common attack, where emails mimic trusted brands to steal
credentials.
Spear Phishing: A highly targeted attack. For example, an attacker might research a
telco engineer on LinkedIn and send a fake "job offer" PDF that contains malware.
Vishing (Voice Phishing): Attackers call victims pretending to be IT support or bank
officials to extract sensitive details.
Baiting: Leaving a malware-infected USB drive in a public place like a company
cafeteria, hoping a curious employee will plug it in.
2. Psychological Triggers
Attackers often use "Urgency" (e.g., "Your account will be deleted in 2 hours") to
bypass a person's critical thinking. They may also use "Authority" (e.g., pretending to
be a CEO or a high-ranking manager) to pressure employees into bypassing standard
security protocols.
3. Establishing a Culture of Security
Technology alone cannot stop social engineering. Organizations must implement
continuous Security Awareness Training (SAT). This includes running simulated
phishing campaigns to test employee reactions and teaching them how to verify
requests through official communication channels. If a request feels unusual, the
policy should be "Stop, Look, and Verify."