Quick answer
Social engineering is the umbrella term for scams that target people rather than technology — phishing, whaling, business email compromise, smishing and vishing are all forms of it. They exploit human instincts: trust, helpfulness, urgency and fear. The defence is a workplace culture where it's completely normal to slow down and verify.
THE LEVERS THEY PULL
It's psychology, not hacking.
Every social engineering attack leans on the same handful of human instincts:
- ▸ Authority. "This is the CEO" — we're wired to do what someone senior asks, quickly and without question.
- ▸ Urgency. "Do it now" — pressure is designed to stop you pausing to think or double-check.
- ▸ Fear. "Your account will be closed" — a threat pushes people into reacting rather than reasoning.
- ▸ Helpfulness. "Can you just let me in?" — most people genuinely want to be useful, and attackers exploit that goodwill.
- ▸ Familiarity. Impersonating a colleague, or a supplier you already trust, lowers your guard before the ask even arrives.
EVERYDAY EXAMPLES
What it looks like in real life.
These aren't rare, high-tech events — they're the everyday tricks that catch busy people:
- ▸ The fake "new bank details" invoice. A supplier emails to say their account has changed — and your payment lands in a scammer's account instead.
- ▸ The "IT support" phone call. A friendly voice claims there's a problem and talks a staff member into handing over a password or approving access.
- ▸ The person who tailgates staff through a secure door. Arms full, a warm smile — and they're inside a restricted area without ever showing a pass.
- ▸ A USB stick "lost" in the car park. Curiosity does the rest — plugging it in quietly installs malware on your network.
- ▸ A "new starter" asking for access they shouldn't have. Confident and plausible, they request logins or information no genuine newcomer would need.
WHY TECHNOLOGY ALONE CAN'T STOP IT
Filters can't screen a friendly voice.
No email filter catches a persuasive phone call or a perfectly reasonable-sounding request. Software can block a dodgy link, but it can't tell that the caller asking your accounts team to change some bank details is actually a scammer. When a request slips past the technology, your people are the last line of defence — so they need to be an informed and confident one.
BUILDING A HUMAN FIREWALL
Turn your team into the defence.
- Build a "verify, don't trust urgency" cultureMake checking the default response — especially when a request is pushing you to move fast. Slowing down is a strength, not a delay.
- Make it safe and normal to question requestsPeople should feel free to push back on an unusual ask, and to report a mistake without fear of blame. A hidden slip-up is far more dangerous than an honest one.
- Run regular, realistic awareness trainingShort, practical sessions — refreshed often — keep the latest tricks front of mind so staff recognise them in the moment.
- Back it with simple processesSmall habits do the heavy lifting: verify any payment or bank-detail change by phone using a known number, not the details in the email.
The goal isn't paranoia. It's to make "let me just verify that" a normal, praised response — especially when something feels urgent. A team that checks calmly and confidently is far safer than one that's simply anxious.