Social Engineering
Social engineering is the practice of manipulating people into giving up confidential information, access, or taking actions that compromise security.
Social engineering is the umbrella term for any attack that exploits human psychology rather than technical vulnerabilities. Instead of breaking through a firewall, the attacker convinces someone to open the door.
How it works
Social engineering attacks follow a common pattern:
- Research. The attacker gathers information about the target — job title, colleagues, tools used, recent events — from public sources like LinkedIn, company websites, and social media.
- Pretext development. Using that information, the attacker crafts a believable scenario: an urgent request from IT, a message from a vendor, a delivery notification.
- Engagement. The attacker delivers the pretext through one or more channels — email, phone, SMS, messaging apps, or in person — and creates urgency, authority, or trust to override the target's caution.
- Exploitation. The target acts: clicking a link, sharing credentials, transferring funds, or granting physical access.
Common social engineering techniques include phishing, vishing, smishing, pretexting, and baiting.
How to defend against it
Technical controls help — email filtering, MFA, endpoint protection — but they cannot stop every social engineering attempt. The target set is also widening: prompt injection applies the same manipulation playbook to the AI assistants employees increasingly rely on. Effective defense combines technology with human resilience:
- Continuous simulation testing across multiple channels to measure how employees respond to realistic attack scenarios. The NOUSEC simulation platform covers eight channels including email, voice, SMS, and deepfake.
- Targeted training based on actual behavior, not annual compliance videos. Employees who click should receive immediate, specific coaching on the red flags they missed.
- A reporting culture where flagging suspicious messages is easy, encouraged, and measured. The reporting rate is a better indicator of security culture than the click rate.
- Human risk measurement that quantifies susceptibility across the organization and tracks improvement over time using a Human Risk Score.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo