Social engineering is the manipulation of people into divulging confidential information or performing actions that compromise security, exploiting human psychology rather than technical vulnerabilities. It includes techniques such as phishing, pretexting, baiting and impersonation that bypass technical controls by targeting trust, urgency and authority. It is one of the most effective and prevalent attack vectors in cybersecurity.

Overview

  • Social engineering targets the human element, often the weakest link in a security posture.
  • Attackers exploit trust, urgency, fear, authority and the desire to be helpful.
  • Because it sidesteps technical defences, it remains effective even against well-hardened systems.
  • Defence depends as much on awareness, culture and process as on technology.

Mechanisms

  • Phishing and spear-phishing use deceptive messages to harvest credentials or deliver Malware.
  • Pretexting fabricates a plausible scenario to extract information or access.
  • Baiting offers something enticing to provoke a risky action.
  • Impersonation and tailgating exploit physical and procedural trust.

Applications

  • Authorised assessment through Penetration Testing and red-team exercises.
  • Security-awareness training and simulated phishing campaigns.
  • Threat modelling that accounts for human-targeted attack paths.

Provenance