The human element is often the weakest link in any corporate security system. Social engineering refers to psychological manipulation to trick users into disclosing private credentials.

1. Phishing & Spear Phishing

Phishing is the sending of fraudulent emails designed to look like trusted sources (banks, utility companies, IT departments). Spear phishing targets specific high-value individuals using personalized information.

2. Pretexting & Baiting

Pretexting involves creating an invented scenario (a pretext) to persuade target victims to perform an action (e.g. pretending to be an auditor). Baiting leaves malware-infected USB drives in public locations, counting on curiosity to drive installation.

3. Preventive Actions

  • Implement regular, interactive security awareness training campaigns.
  • Enforce strict policies regarding verification of identity before resetting user credentials.