Social Engineering: Why People Remain the Reliable Attack Path

Attackers target people because it works more consistently than exploiting software. What reduces human risk, and what only appears to.

Why the human path stays open

Exploiting software requires finding a vulnerability that has not been patched in a system reachable from outside. Exploiting a person requires a plausible story. The second is more consistently available, which is why the large majority of incidents begin with someone being persuaded rather than something being hacked.

The levers being pulled

Effective social engineering rarely relies on technical trickery. It uses ordinary psychological pressure: authority, so the request appears to come from someone senior; urgency, so there is no time to verify; and helpfulness, since most people want to assist a colleague who is under pressure.

Common forms include business email compromise, where an attacker intercepts or imitates a genuine payment conversation; pretexting, where a fabricated scenario justifies an unusual request; and multi-factor fatigue, where repeated push notifications wear a user down into approving one.

Where awareness training falls short

Annual training that teaches people to spot bad grammar and suspicious links is calibrated to attacks from a decade ago. It does not prepare anyone for a fluent, well-researched message, and it does nothing at all for a convincing phone call.

Training also carries a structural weakness: it makes security an individual performance test. A programme that depends on every employee being alert every time will eventually fail, because attackers only need one success.

Designing so mistakes are survivable

  • Verification procedures for payment and access changes, using a known contact route rather than details supplied in the request
  • Dual authorisation above a threshold, so no single person can be manipulated into a large transfer
  • Phishing-resistant authentication, which protects users even when they are deceived
  • A reporting culture where raising a false alarm is treated as a good outcome
  • Realistic simulations used to measure programme health, not to penalise individuals

The goal is not a workforce that never makes a mistake. It is a system where an individual mistake does not become an incident.

Related in the Knowledge Base

Free Download

Know what an attacker sees before they do.

A practical exposure checklist covering the gaps that cause most breaches, plus what POPIA actually requires you to have in place.

Free PDF · No spam · Unsubscribe anytime

Send me the checklist