Social engineering is the manipulation of people rather than technical systems to gain unauthorised access to information or systems. It exploits human psychology — trust, authority, urgency, and fear — rather than software vulnerabilities.
It is often the easiest form of attack: it is much simpler to trick a person into revealing a password than to crack it technically. This is why people are often described as the "weakest link" in cyber security.
Social engineers are skilled at exploiting these cognitive biases:
Mass emails disguised as legitimate sources (banks, PayPal, HMRC) containing malicious links or attachments. Targets large numbers of people — even a 1% success rate yields thousands of victims.
A targeted phishing attack aimed at a specific individual or organisation. Uses personal details (name, job title, colleagues) gathered from LinkedIn or social media to appear convincing. Far more effective than mass phishing.
Phone calls from attackers impersonating banks, IT support, HMRC, or even Microsoft. Common scripts: "Suspicious activity on your account — we need to verify your details" or "Your computer has a virus, give us remote access."
Fake text messages pretending to be from delivery companies, banks, or HMRC with links to fake websites. Example: "Your Royal Mail parcel could not be delivered. Pay £2.99 redelivery fee here: [link]"
Leaving infected USB drives in car parks, offices, or public places, labelled with enticing names ("Payroll 2025", "Confidential"). When a curious person plugs it in, malware installs automatically.
Creating a fabricated scenario to obtain information from a target — for example, an attacker poses as a new IT contractor and asks an employee to reveal their password so they can "fix" their computer. (Also known as pretexting.)
Following an authorised person through a secure door without using their own credentials. Common in offices with key fob access — attacker holds the door saying "I forgot my badge." Also called piggybacking.
Observing someone entering their PIN, password, or sensitive information in a public place — over their shoulder. Common at ATMs, train stations, and open-plan offices.
Regular awareness training — teach employees to recognise phishing emails, vishing calls, and suspicious scenarios. Run simulated phishing exercises. Humans are the threat; make them the defence.
Never act on unexpected requests without independent verification. Call the company back on a number you find independently (not one given in the suspicious message). IT support should never ask for passwords.
Define exactly what employees should and should not do: no sharing passwords, no tailgating, no plugging in unknown USB devices. "Clean desk" policy prevents shoulder surfing. Formal visitor sign-in procedures.
Email spam filters, anti-phishing browser extensions, multi-factor authentication (so stolen passwords alone aren't enough), physical access controls (key fobs, security guards, sign-in procedures).
8 questions · 22 marks
| Term | Definition |
|---|
Timed exam conditions.