Social Engineering Awareness for Staff
Security & antivirus
social engineering
awareness
security training
vishing
By Kerry · Updated 03/05/26 07:41 AM
Social engineering attacks manipulate people rather than technology. Attackers impersonate authority figures, create urgency, or exploit helpfulness to trick staff into divulging information or taking harmful actions. Technical controls alone cannot stop social engineering — training is the defense.
Common attack types: Phishing (email), Vishing (phone calls — 'Hi, I'm from IT support, I need your password to fix your account' — IT will NEVER ask for your password), Smishing (SMS texts), Pretexting (impersonating someone with a plausible story), and Baiting (leaving USB drives in parking lots).
Training points: always verify the identity of anyone requesting sensitive information or unusual actions, especially if they create urgency ('This needs to happen NOW or accounts will be suspended'). Call back on a known number — not one the caller provides. Be skeptical of unsolicited contact even from familiar-seeming names. Report suspicious contacts to IT immediately. Run periodic simulated phishing tests (KnowBe4, Proofpoint Security Awareness) to measure and improve staff resilience.