Back to Learning Hub

What Is Social Engineering?

Last updated: 2026-08-133 min read

How social engineering manipulates normal human behaviour to bypass security, the forms it takes, and how to build a verify-first culture.

Social engineering is psychological manipulation used to get past security. Rather than defeating a firewall, the attacker persuades a person to open the door — by exploiting urgency, authority, fear, curiosity, or plain helpfulness.

Phishing is social engineering delivered by message. The category is broader than that, and so is the defence.


The forms it takes

  • Phishing. The written form — email, SMS, chat. See what is phishing.
  • Vishing. A phone call, often impersonating IT support offering to fix a login problem, or a bank's fraud team. More on voice and SMS attacks.
  • Pretexting. Inventing a scenario that justifies the request — a new colleague needing access, an auditor needing records, a supplier updating their details.
  • Baiting. Leaving something enticing to be picked up, physical or digital, that carries the payload.
  • Tailgating. Following an authorised person through a door, usually while carrying something, because holding the door open is a reflex nobody wants to break.

Why it works on sensible people

The uncomfortable part is that social engineering does not exploit stupidity. It exploits the behaviours that make someone good at their job.

Helpfulness. Most people want to solve the problem in front of them. An attacker with a plausible problem is exploiting exactly that instinct.

Deference to authority. A request that appears to come from a senior figure carries weight that makes questioning it feel rude. A fake email from the "CEO" asking for an urgent transfer routinely gets past people who would refuse the same request from a stranger — see CEO fraud and whaling prevention.

Time pressure. Urgency removes the pause in which you would have noticed something. It is manufactured for that reason alone.

Reciprocity and familiarity. A small favour, a shared acquaintance, a few emails of harmless conversation first. Attackers invest in rapport because trust built over three messages is spent on the fourth.

Building a verify-first culture

The defence is not scepticism about everything, which is exhausting and unworkable. It is a narrow, specific habit applied to a small set of requests.

Define what always gets verified. Payments, bank detail changes, credential resets, access grants, and sensitive data requests. Anything in that list gets confirmed on a second channel, regardless of who appears to be asking.

Make verification the policy, not the individual's judgement. This is the part most organisations miss. If checking is a personal choice, refusing the CEO is a career risk. If it is written policy, the employee is complying rather than doubting — and that difference decides whether it actually happens.

Make reporting shame-free. People who fear looking foolish stay quiet, and silence is what turns a near miss into an incident. Reward the report, never punish the mistake.

Rehearse it. Show people what social engineering looks like in a safe setting, so a real attempt is not the first one they have ever seen.

One caution worth setting expectations on: no amount of training makes anyone immune. A well-researched attacker with time and a plausible story will occasionally succeed against anybody. The realistic goal is to shrink the window — fewer successes, caught faster, contained before they matter.


Related Learning

Ready to stop phishing attacks?

Run realistic phishing simulations and high-impact security awareness training with PhishSkill's automated platform.