Glossary

What is social engineering?

Social engineering is the manipulation of people, rather than technology, to get them to share information, grant access or move money.

Also known as
Human hacking, people-based attacks
Channels
Email, SMS, phone, chat apps, in person
Typical goal
Credentials, payments, data or physical access
Related term
Phishing

How it works

Research, pretext,
pressure, payoff.

  1. 01

    Research

    The attacker learns names, roles, suppliers and routines from public profiles, websites and earlier breaches.

  2. 02

    Pretext

    They build a believable story: an IT helpdesk fix, a supplier’s new bank account, a courier fee, a senior leader in a hurry.

  3. 03

    Pressure

    Urgency, authority or helpfulness pushes the target to act before checking.

  4. 04

    Payoff

    The target shares a code, enters a password, approves a payment or opens a door, often without realising anything happened.

How to defend against it

Slow down,
then verify.

Social engineering works by skipping the moment where you stop and check. The defence is a habit: pause, then confirm the request through a channel you already trust.

CHECKLIST

Before you act

  • Did I expect this request?
  • Is it asking for a code, password, payment or access?
  • Is someone rushing me or invoking authority?
  • Can I verify it through a known number or contact?
  • Have I reported it to my security team?

General guidance, not a complete security policy.

Questions buyers ask

Frequently asked questions.

What are the most common types of social engineering?

Phishing, vishing, smishing, pretexting, baiting and tailgating are the most widely discussed. Most combine a believable story with pressure to act quickly.

Why does social engineering work on smart people?

It targets normal, helpful behaviour rather than a lack of intelligence. Busy people under time pressure act on familiar-looking requests, which is exactly what attackers design for.

Does social engineering happen offline too?

Yes. It can happen in person, such as someone following staff through a secure door, or over the phone, as well as through digital messages.

Let’s connect the dots

See the human risk.
Change what happens next.

Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.

Book a demo