alphaPlan · Cybersecurity · Cheat-sheet 04
Social Engineering & the Human Factor
Social engineering targets the person, not the machine, and one habit beats it: slow down and verify anything unexpected through a separate, trusted channel.
Ideas to remember
- 01It is easier to ask a person for the key than to pick the lock, and trust, habit and pressure do most of the damage.
- 02Attackers pull four levers on purpose, authority, urgency, helpfulness and fear, so feelings answer before thinking does.
- 03Phishing, smishing and vishing are one trick through three doorways: email, text message and phone call.
- 04Business email compromise (BEC) is a patient, well written request to change payment details, and it targets a gap in your process.
- 05Physical tactics work too: tailgating, bin raiding, sticky note passwords and dropped USB sticks.
- 06A password manager stays silent on a fake page, and MFA still holds after your password has been talked out of you.
Words
- Social engineering
- Talking someone into handing over information or doing something they should not.
- Phishing
- A fake message, usually an email, built to look trustworthy so you click, open or type your password.
- Smishing
- The same trick by SMS or a messaging app.
- Vishing
- The same trick by phone call, now easy to fake with voice cloning.
- BEC
- Business email compromise: a real-looking invoice or note that redirects a real payment to the attacker.
- Tailgating
- Slipping through a secure door behind an authorised person.
Do this
- When a request comes with a countdown or a threat, pause, breathe, and verify on a separate, trusted channel.
- Confirm any change of bank details by phoning a number you already have on file, never one in the message.
- Make 'we always call to confirm a change of bank details' a written rule, not a personal favour.
- Let people badge in themselves, shred sensitive paper, and hand any found USB stick to IT unopened.
- Turn on MFA everywhere, starting with email, and deny any prompt you did not start.
Watch out
- The tell is rarely the logo; it is the request, since a real bank does not email you a link and ask you to log in urgently.
- Strong urgency is itself a red flag: a genuine request survives a five minute delay, a scam usually does not.
- If your password manager does not autofill, you may be on a look-alike page; that silence is a warning.
Found something unclear, outdated or improvable? Suggest an improvement