Social Engineering Defense

MODULE 03 / INTERMEDIATE10 min / Includes knowledge checks and quiz

Social Engineering Defense

Social engineering targets people, not computers. Learn to recognize manipulation over the phone, by text, and in person, and master the verify-first defense strategy.

A receptionist at a modern office front desk politely asking a visitor to sign in at a badge check-in system

What You Will Learn

Social engineering is the art of manipulating people into breaking security rules. Unlike phishing, which uses email, social engineering can happen over the phone, in person, through text messages, or even through social media. This module teaches you to recognize and resist manipulation.

  • Social engineering basics: why attackers target people, not computers
  • Pretexting: fake scenarios designed to gain your trust
  • Vishing (voice phishing): phone-based attacks
  • Smishing (SMS phishing): text-based attacks
  • Defense strategies: how to verify and respond

Why Attackers Target People

It is easier to trick a person than to hack a system. Attackers know that firewalls, encryption, and antivirus are strong, but people can be manipulated. Social engineering exploits human nature: our desire to be helpful, our respect for authority, and our fear of getting in trouble.

The key defense is simple: verify before you act. No matter how urgent, official, or friendly the request seems, take a moment to confirm through a trusted channel.

Quick Check

Someone calls your office claiming to be from your IT support company. They say they need your password to fix a server issue. What should you do?

A) Give them your password so they can fix the issue quickly
B) Ask them for their name and then give the password
C) Do not share your password. Hang up and call your IT contact directly to verify.
D) Ask them to send an email first, then share the password

Pretexting: The Fake Scenario

Pretexting is when an attacker creates a believable story to get you to lower your guard. They might pretend to be a vendor doing an audit, a new employee who lost their badge, or a delivery person who needs access to a secure area. The story is designed to make you feel like helping is the right thing to do.

Common pretexts include: a software vendor calling about a license renewal, a person claiming to be from the fire department inspecting extinguishers, or someone posing as a board member visiting from out of town.

Vishing: Voice Phishing

Vishing attacks happen over the phone. The caller may sound professional, knowledgeable, and urgent. They may know your name, your role, and details about your organization. They use this information to build trust and pressure you into acting.

Common Vishing Scenarios

  • Tech support scam: Caller claims to be from Microsoft or your IT team and says your computer has a virus. They ask for remote access or your password.
  • Government impersonation: Caller claims to be from the IRS, Medicare, or a state agency and threatens penalties if you do not verify information immediately.
  • Vendor verification: Caller claims to be from a vendor and asks you to confirm account numbers, payment details, or employee information.
  • Executive impersonation: Caller claims to be your CEO or board member and asks for urgent, confidential help with a payment or data request.

Quick Check

You receive a text message saying your package delivery failed and you need to click a link to reschedule. You are not expecting a package. What is this?

A) A legitimate delivery notification
B) A smishing (SMS phishing) attack trying to get you to click a malicious link
C) A wrong number
D) A message from your postal service

Smishing: SMS Phishing

Smishing attacks come through text messages. They are growing rapidly because people tend to trust text messages more than emails and are more likely to click links quickly. Common smishing messages include fake package delivery notices, bank fraud alerts, and prize notifications.

Your Defense Strategy

The Verify-First Rule

  • Slow down. Urgency is the attacker’s weapon. Take a breath and think before you act.
  • Verify through a different channel. If someone calls claiming to be from IT, hang up and call IT directly using the number you have on file.
  • Never share passwords or MFA codes. No legitimate organization will ever ask for these over the phone, by text, or by email.
  • Question authority. Just because someone sounds official does not mean they are. Verify before you comply.
  • Report suspicious contacts. Tell your IT team or STM about any suspicious calls, texts, or visits. Patterns help identify attack campaigns.

How This Looks in Your Industry

Healthcare Practices

Attackers may call claiming to be from Medicare, your EHR vendor, or a hospital partner. They may ask for provider NPI numbers, patient information, or login credentials. HIPAA requires you to verify identity before sharing PHI. When in doubt, do not share.

Legal Firms

Attackers may impersonate clients, opposing counsel, or court personnel. They may request case files, settlement details, or wire transfers. Verify all unusual requests by calling the person at a known number.

Nonprofits

Attackers may impersonate grantors, donors, or board members. They may request financial reports, donor lists, or changes to banking information. Verify any financial or data request through established channels.

Daycares and Schools

Attackers may impersonate parents, state licensing inspectors, or education vendors. They may request student records, parent contact information, or access to the building. Verify identity before sharing any information or granting access.

Key Takeaways

  • Social engineering targets people, not computers. It exploits helpfulness, authority, and urgency.
  • Never share passwords or MFA codes with anyone. No legitimate organization will ever ask for them.
  • Verify through a different channel. If someone calls claiming to be from IT, hang up and call IT directly.
  • Vishing (phone), smishing (text), and pretexting (fake scenarios) are all social engineering tactics.
  • Slow down. Urgency is the attacker’s weapon. Taking a moment to verify is your best defense.

Module Quiz

Complete this quiz to test your understanding of the module. Answers are provided below each question.

1. Someone calls your office claiming to be a fire inspector who needs to check your extinguishers. They ask to be let into your server room. What should you do?

A) Let them in. Fire safety is important.
B) Ask for their ID, verify with your building management, and escort them at all times
C) Let them in but watch them closely
D) Refuse entry and call the fire department

2. You get a text from your bank saying your card has been frozen due to suspicious activity. It provides a link to verify your identity. What should you do?

A) Click the link to unfreeze your card quickly
B) Call your bank using the number on the back of your card, not the number in the text
C) Reply to the text asking for more information
D) Ignore it since it is probably fake

3. An email from your CEO asks you to buy $1,000 in gift cards for a client emergency and send the codes via email. The CEO says they are in a meeting and cannot talk. What is happening?

A) A legitimate business request
B) A BEC / social engineering attack using authority and urgency
C) A test from your IT department
D) A normal way to handle client gifts

4. Why is social engineering effective even when technical security is strong?

A) Because attackers use advanced hacking tools
B) Because it targets human nature: helpfulness, respect for authority, and fear
C) Because firewalls do not work against phone calls
D) Because antivirus cannot detect social engineering

5. Which of these is the best defense against social engineering?

A) Installing better antivirus software
B) Upgrading your firewall
C) The verify-first rule: always verify through a different channel before acting
D) Changing your password every week

Module 03 of 10 – Cybersecurity Essentials Training

Previous ModuleBack to ResourcesNext Module