openskills.info
Course Preview

Social Engineering Defense

Social engineering defense protects people and organizations from deceptive requests that try to turn trust, urgency, or routine into unauthorized access, disclosure, or payment. It combines safer work processes, technical controls, practiced verification, reporting, and incident response.

itOffensive security and application security

Social Engineering Defense

Social engineering defense is the coordinated use of people, processes, and technology to prevent deception from producing an unauthorized action. The action might disclose a password, approve an authentication prompt, transfer money, reveal sensitive information, install software, or grant physical access.

The attacker does not need an implausible message. A convincing request can arrive through email, text, voice, video, a social platform, a support channel, or an in-person conversation. It can also come from a real account that has been compromised. Sender appearance therefore provides context, not proof.

A defensible system does not ask one person to identify every lie. It creates several chances to interrupt the attack before harm occurs. The National Cyber Security Centre organizes phishing defense into four layers: reduce delivery, help people identify and report, limit the effect of interaction, and respond quickly. The same structure applies to social engineering beyond email.

The attack path

Most social engineering attacks move through a recognizable path:

  1. Reconnaissance. The attacker learns names, roles, suppliers, routines, current events, and communication patterns.
  2. Pretext. The attacker adopts a believable role and supplies a reason for the request.
  3. Pressure. Urgency, authority, secrecy, fear, helpfulness, or reward narrows the target's attention.
  4. Action. The target is asked to click, reply, disclose, approve, pay, install, connect, or admit.
  5. Exploitation. The attacker uses the action to obtain access, data, money, persistence, or a stronger position for another request.
  6. Continuation. A successful interaction may become account takeover, thread hijacking, business email compromise, or another pretext aimed at a second person.

The defensive objective is to break this path at several points. Less exposed organizational information makes reconnaissance harder. Authenticated communication and filtering reduce delivery. A known verification path defeats the pretext. Approval separation limits the requested action. Phishing-resistant authentication limits credential replay. Reporting and monitoring shorten continuation.

Recognize the decision, not a stereotype

Phishing is electronically delivered social engineering. MITRE ATT&CK distinguishes spearphishing attachments, links, messages through services, and voice. Business email compromise often uses a request that appears to come from a known source, such as a supplier changing payment details or an executive requesting gift cards.

Continue the course

This section is part of the paid course.

See pricing to subscribe, or log in if you already have access.

Where this skill leads

Relevant careers

See how this topic contributes to broader role-level skill maps.

Sources