GlossarySecurity awareness

Social engineering

Short answer

Social engineering is the manipulation of people into giving away information, access or money, by exploiting trust, urgency or authority rather than technical flaws. Phishing is its most common form, but it also includes phone calls, impersonation and physical intrusion.

Common techniques

Phishing is the most common form, but there are others. Pretexting builds a believable story, such as a fake supplier or IT support call. Baiting leaves an infected USB drive or offers a free download. Tailgating follows an employee through a secure door. Vishing uses phone calls, increasingly with AI generated voices that imitate real people.

Why it works

These attacks rely on urgency, authority, helpfulness and routine. A request that seems to come from a manager, arrives at a busy moment and asks for something ordinary is hard to question.

How to reduce the risk

Regular awareness training with realistic examples, verification procedures for payments and access changes (for example, confirming by a separate channel), MFA so stolen credentials are not enough, and a culture where people feel comfortable reporting and double checking.

Where it shows up in compliance

Awareness training is required by ISO 27001, the ENS and NIS2, and physical access controls address the in person techniques.

Related terms

Keep reading on this topic

Turning employees into an active line of defence: awareness training, phishing simulation, device and identity hygiene, and SaaS access control.

Go to the topic hub