Social Engineering Defense
Social engineering targets people, not computers. Learn to recognize manipulation over the phone, by text, and in person, and master the verify-first defense strategy.
What You Will Learn
Social engineering is the art of manipulating people into breaking security rules. Unlike phishing, which uses email, social engineering can happen over the phone, in person, through text messages, or even through social media. This module teaches you to recognize and resist manipulation.
- Social engineering basics: why attackers target people, not computers
- Pretexting: fake scenarios designed to gain your trust
- Vishing (voice phishing): phone-based attacks
- Smishing (SMS phishing): text-based attacks
- Defense strategies: how to verify and respond
Why Attackers Target People
It is easier to trick a person than to hack a system. Attackers know that firewalls, encryption, and antivirus are strong, but people can be manipulated. Social engineering exploits human nature: our desire to be helpful, our respect for authority, and our fear of getting in trouble.
The key defense is simple: verify before you act. No matter how urgent, official, or friendly the request seems, take a moment to confirm through a trusted channel.
Quick Check
Someone calls your office claiming to be from your IT support company. They say they need your password to fix a server issue. What should you do?
Pretexting: The Fake Scenario
Pretexting is when an attacker creates a believable story to get you to lower your guard. They might pretend to be a vendor doing an audit, a new employee who lost their badge, or a delivery person who needs access to a secure area. The story is designed to make you feel like helping is the right thing to do.
Common pretexts include: a software vendor calling about a license renewal, a person claiming to be from the fire department inspecting extinguishers, or someone posing as a board member visiting from out of town.
Vishing: Voice Phishing
Vishing attacks happen over the phone. The caller may sound professional, knowledgeable, and urgent. They may know your name, your role, and details about your organization. They use this information to build trust and pressure you into acting.
Common Vishing Scenarios
- Tech support scam: Caller claims to be from Microsoft or your IT team and says your computer has a virus. They ask for remote access or your password.
- Government impersonation: Caller claims to be from the IRS, Medicare, or a state agency and threatens penalties if you do not verify information immediately.
- Vendor verification: Caller claims to be from a vendor and asks you to confirm account numbers, payment details, or employee information.
- Executive impersonation: Caller claims to be your CEO or board member and asks for urgent, confidential help with a payment or data request.
Quick Check
You receive a text message saying your package delivery failed and you need to click a link to reschedule. You are not expecting a package. What is this?
Smishing: SMS Phishing
Smishing attacks come through text messages. They are growing rapidly because people tend to trust text messages more than emails and are more likely to click links quickly. Common smishing messages include fake package delivery notices, bank fraud alerts, and prize notifications.
Your Defense Strategy
The Verify-First Rule
- Slow down. Urgency is the attacker’s weapon. Take a breath and think before you act.
- Verify through a different channel. If someone calls claiming to be from IT, hang up and call IT directly using the number you have on file.
- Never share passwords or MFA codes. No legitimate organization will ever ask for these over the phone, by text, or by email.
- Question authority. Just because someone sounds official does not mean they are. Verify before you comply.
- Report suspicious contacts. Tell your IT team or STM about any suspicious calls, texts, or visits. Patterns help identify attack campaigns.
How This Looks in Your Industry
Healthcare Practices
Attackers may call claiming to be from Medicare, your EHR vendor, or a hospital partner. They may ask for provider NPI numbers, patient information, or login credentials. HIPAA requires you to verify identity before sharing PHI. When in doubt, do not share.
Legal Firms
Attackers may impersonate clients, opposing counsel, or court personnel. They may request case files, settlement details, or wire transfers. Verify all unusual requests by calling the person at a known number.
Nonprofits
Attackers may impersonate grantors, donors, or board members. They may request financial reports, donor lists, or changes to banking information. Verify any financial or data request through established channels.
Daycares and Schools
Attackers may impersonate parents, state licensing inspectors, or education vendors. They may request student records, parent contact information, or access to the building. Verify identity before sharing any information or granting access.
Key Takeaways
- Social engineering targets people, not computers. It exploits helpfulness, authority, and urgency.
- Never share passwords or MFA codes with anyone. No legitimate organization will ever ask for them.
- Verify through a different channel. If someone calls claiming to be from IT, hang up and call IT directly.
- Vishing (phone), smishing (text), and pretexting (fake scenarios) are all social engineering tactics.
- Slow down. Urgency is the attacker’s weapon. Taking a moment to verify is your best defense.
Module Quiz
Complete this quiz to test your understanding of the module. Answers are provided below each question.
1. Someone calls your office claiming to be a fire inspector who needs to check your extinguishers. They ask to be let into your server room. What should you do?
2. You get a text from your bank saying your card has been frozen due to suspicious activity. It provides a link to verify your identity. What should you do?
3. An email from your CEO asks you to buy $1,000 in gift cards for a client emergency and send the codes via email. The CEO says they are in a meeting and cannot talk. What is happening?
4. Why is social engineering effective even when technical security is strong?
5. Which of these is the best defense against social engineering?
Module 03 of 10 – Cybersecurity Essentials Training
