The Woman Your Access Control Cannot Stop: “People Hacker” by Jenny Radcliffe

Book of the Month, Due Diligence, Employee Fraud, Employee Training, External Threats, Financial Investigations, Global Business, Hacking, Industrial Espionage, Intelligence, International Trade, People, Phishing, Risk Management, Security

December 1, 2023

Your building has card readers, cameras, a visitor log and a security desk. Jenny Radcliffe will be inside it by lunchtime, and nobody will have done anything wrong.

She is a social engineer — hired by organisations to breach their own premises so that the gaps are found by someone friendly. She calls herself a burglar for hire. What she actually does is demonstrate, repeatedly and expensively, that the most sophisticated physical security in the world is administered by people who would rather be helpful than difficult.

People Hacker is her account of thirty years of doing this. For anyone responsible for a site, a building or a workforce, it is uncomfortable in exactly the right way.

What the book actually covers

Radcliffe's method is almost entirely non-technical. She does not defeat the lock; she persuades someone to hold the door. She has talked her way into banks, data centres, corporate headquarters and, on one occasion, the Tower of London — using pretext, confidence, appropriate clothing and an unshakeable air of belonging.

The mechanics she describes are the ones that matter operationally. Reconnaissance first: what an organisation publishes about itself, who its suppliers are, what its lanyards look like, when its shifts change. Then the pretext — a role plausible enough that challenging it feels rude. Then the exploitation of the two most reliable human tendencies in any workplace: the reluctance to challenge someone who appears senior, and the instinct to help a person who seems to be struggling.

Her most useful observation is that forced entry is the amateur's route. Talking your way in is safer, quieter, leaves less evidence and works more often. That reframing should worry anyone whose security posture is built around barriers rather than behaviour.

She is candid about the near-misses, and about the toll of a working life spent deceiving decent people for their own good. The book is funny, which makes the underlying finding land harder.

People Hacker book cover

Why it matters for your risk posture

Read it because the human layer is the one almost nobody tests. Organisations commission penetration tests of their networks as a matter of routine and almost never commission the physical and social equivalent. Radcliffe's career exists because that gap is universal.

Read it for the reconnaissance material. Most of her work is done before she arrives, using information the target published voluntarily — organisational charts, supplier relationships, photographs with lanyards visible, social media posts revealing schedules. That is precisely the exposure a proper open-source assessment identifies, and this book demonstrates what an adversary does with it.

And read it for the training implication. Radcliffe is emphatic that awareness training fails when it tells staff to be suspicious, because being suspicious conflicts with being good at a customer-facing job. What works is giving people a specific, socially acceptable script for verification — a way to check that does not require them to be rude. That distinction is the difference between a policy that is followed and one that is quietly ignored.

Key takeaways

  • The barrier is not the control; the person operating it is. Access systems are administered by staff whose instinct is to be helpful, and that instinct is the actual attack surface.
  • Reconnaissance is done from your own published material. Org charts, supplier names, visible lanyards and posted schedules are the raw material of a successful pretext.
  • Talking in beats breaking in. It is safer, quieter and more reliable — which is why the sophisticated adversary never touches the lock.
  • Train the script, not the suspicion. Staff need a polite, specific way to verify. Telling them to be wary conflicts with their job and loses.

About the author

Jenny Radcliffe is a social engineer and founder of Human Factor Security, working in physical infiltration and the psychology of scams, cons and fraud. She is hired by organisations to test their premises and their people, and to build the awareness programmes that follow.

She was inducted into Infosecurity Europe's Hall of Fame in 2022 in recognition of her work on the human-centred side of information security, has been named among the leading women in the field by several industry bodies, and is a multiple TEDx contributor.

People Hacker: Confessions of a Burglar for Hire was published by Simon & Schuster in 2023.

Beyond the Book

Jenny Radcliffe — social engineer; founder, Human Factor Security

  • Listen, weekly and free: she hosts The Human Factor, an award-winning podcast on the human side of security, interviewing practitioners across the field. It is the ongoing version of the book and the best free resource on this subject anywhere.
  • She speaks, and constantly: a sought-after keynote at security conferences and corporate events internationally, with talks aimed specifically at waking up a workforce to social-engineering risk.
  • She can be hired to do this to you. Human Factor Security conducts physical infiltration assessments and awareness programmes. For an organisation that has never tested its human layer, that is the actionable step this book points to.
  • Read alongside: The Official CIA Manual of Trickery and Deception for the attention-management mechanics underneath her method, and The Gift of Fear by Gavin de Becker for the signals that indicate manipulation in progress.

Get your copy

Get your copy

Order People Hacker on Amazon: find it here.

Discover more Insights from Falcone International

In “On Intelligence,” John Hughes-Wilson offers an insightful journey through the clandestine world of intelligence and espionage. Covering historical events to modern dilemmas, the book illuminates the inner workings of intelligence agencies and their impact on world history. This exploration encourages critical thinking about the role of intelligence in society and the ethical issues it presents.

This weekend read delves into the various risks businesses face during economic downturns, with a particular focus on the rise of fraud and malfeasance. It outlines several strategies to recession-proof a business, including fostering a culture of integrity, investing in human capital, leveraging technology, creating a robust crisis management plan, and implementing strong internal controls. By taking proactive measures, businesses can effectively manage risks, enhance resilience, and weather the economic storm.

In “Glass Houses,” author Joel Brenner dissects the paradox of privacy, secrecy, and cyber insecurity within our increasingly transparent digital age. Brenner presents a thorough exploration of the delicate balance between the need for secrecy and the demand for transparency in modern societies. Through his detailed examination of current cybersecurity issues, Brenner provides valuable insights into navigating the complex dynamics of privacy in a world where every action can be monitored and tracked.

In the world’s complex network of business transactions, counterparty risk stands out as an invisible game-changer. Frequently under-appreciated and easily overlooked, this element can silently sway a company’s fortune. This comprehensive guide seeks to demystify counterparty risk, illuminate its significance, and offer an efficient path toward its management.

Discover how we use our integrated capabilities for our clients

Case Studies and Client Stories