Threats

What is Social engineering?

Definition

Manipulating people, rather than technology, into breaking security procedures, such as sharing passwords, approving access or making payments.

How it works

Social engineering covers phishing, phone-based attacks (vishing), SMS (smishing), help-desk impersonation and in-person pretexts. Attackers exploit urgency, authority and helpfulness.

Help-desk impersonation, where an attacker calls IT pretending to be an employee to reset MFA, has become a common route to account takeover.

Key points

  • Targets people and processes, not systems
  • Includes phishing, vishing, smishing and pretexting
  • Help desks are a frequent target
  • Verification procedures are the main defence

Common questions

Can social engineering be tested?

Yes. Phishing simulations and authorised social engineering assessments test how people and processes respond.

What is the best single control?

Clear verification steps for any request involving credentials, access or money.

Talk to someone who does this every day

Questions about Social engineering? Our team will give you a straight answer.

Contact us