Common techniques
Phishing is the most common form, but there are others. Pretexting builds a believable story, such as a fake supplier or IT support call. Baiting leaves an infected USB drive or offers a free download. Tailgating follows an employee through a secure door. Vishing uses phone calls, increasingly with AI generated voices that imitate real people.
Why it works
These attacks rely on urgency, authority, helpfulness and routine. A request that seems to come from a manager, arrives at a busy moment and asks for something ordinary is hard to question.
How to reduce the risk
Regular awareness training with realistic examples, verification procedures for payments and access changes (for example, confirming by a separate channel), MFA so stolen credentials are not enough, and a culture where people feel comfortable reporting and double checking.
Where it shows up in compliance
Awareness training is required by ISO 27001, the ENS and NIS2, and physical access controls address the in person techniques.




