Protecting your business from social engineering attacks: The importance of employee training and technical controls

February 23, 2023

Phishing and pretexting work because they target people rather than systems, and because the people they target most successfully are helpful, busy, and authorized. No security budget closes a gap that opens when someone reasonable is asked a plausible question by someone who appears to have a right to ask it. This piece covers the main forms these attacks take, what they cost, and which defenses hold up.

Types of Social Engineering Attacks

Phishing and pretexting are two of the most common social engineering attacks. Phishing attacks typically involve sending an email that appears to be from a legitimate source, such as a bank or an email provider, and asking the recipient to provide sensitive information, such as their username and password. Pretexting, on the other hand, involves creating a false scenario to gain the victim’s trust, such as pretending to be an IT helpdesk technician who needs access to the victim’s computer.

Another type of social engineering attack is baiting, which involves leaving a physical device, such as a USB drive or a CD, in a public place in the hope that an employee will pick it up and plug it into their computer. Once the device is plugged in, it can install malware or steal sensitive data from the computer.

Spear phishing is a more targeted type of phishing attack that involves sending an email that appears to be from a known individual, such as a colleague or a friend, and asking for sensitive information or requesting that the recipient clicks on a link that installs malware.

Finally, the insider threat involves an employee or contractor with authorized access to an organization’s systems and data intentionally or unintentionally causing harm. This can include stealing confidential information or compromising systems or data security.

Impact of Social Engineering Attacks

Social engineering attacks can have a significant impact on organizations. The cost of a successful attack can range from lost productivity to financial loss, reputational damage, and even legal action. According to the 2021 Verizon Data Breach Investigations Report, phishing attacks accounted for 36% of all data breaches, making them the most common type.

In addition to financial costs, social engineering attacks can damage an organization’s reputation. If sensitive information is stolen, it can erode trust with customers and partners, leading to a loss of business. A successful attack can also result in regulatory fines and legal action.

 

Protecting Against Social Engineering Attacks

Defending against this needs both halves: training, so people recognize the approach, and technical controls, so that recognizing it late is not fatal.

Employee Trainingsocial engineering

Employee training is a critical component of protecting against social engineering attacks. Employees must be trained to recognize and prevent social engineering attacks, including phishing and pretexting. This training should be provided on an ongoing basis to ensure that employees are updated on the latest threats and best practices for protecting against them.

One effective way to increase employee awareness of social engineering attacks is through simulated phishing tests. These tests send fake phishing emails to employees and track how many fall for the scam, providing valuable data for further training and education.

Another critical training component is teaching employees best practices for protecting passwords and other sensitive information. This includes using strong, unique passwords, avoiding sharing passwords, and enabling multi-factor authentication wherever possible.

Technical Controls

In addition to employee training, organizations must implement technical controls to reduce the risk of successful social engineering attacks. This includes implementing multi-factor authentication, using spam filters to block suspicious emails, and restricting access to sensitive information based on job roles and responsibilities.

Multi-factor authentication (MFA) is an effective way to prevent unauthorized access to systems and data. MFA requires users to provide two or more forms of authentication before granting access to sensitive information, such as a password and a fingerprint or a smart card.

This added layer of security can help prevent unauthorized access even if a password is compromised. Spam filters can also help prevent phishing emails from reaching employees’ inboxes. Restricting access to sensitive information based on job roles and responsibilities can limit the potential damage of an insider threat.

Regular vulnerability assessments and penetration testing can also help identify weaknesses in an organization’s security posture and provide valuable insights into areas that require improvement. It is essential for organizations to regularly review and update their security policies and procedures to ensure that they remain effective in the face of evolving threats.

Simulated phishing tests, multi-factor authentication, spam filtering and least-privilege access all measurably reduce successful attacks, and none of them depends on people being careful. Review them when your tooling or your team changes. One thing worth stating explicitly: run the simulated tests to find weak points in the process, not to identify individuals. The moment staff believe a test is a trap, they stop reporting the real ones — and self-reporting is the control that actually catches these attacks.


Falcone International

Bring us a question like this one

We handle corporate investigations, due diligence, financial investigations and duty of care — usually for people who need something established quietly, and established properly, before it turns into a problem.

Talk to usSee what we do

Discover more Insights from Falcone International

“Never Split the Difference” offers an inside look into the world of high-stakes hostage negotiations, translated into tactics for personal and business use. Chris Voss, a former FBI negotiator, shares strategies that center around empathy, active listening, and tactical mirroring to sway outcomes. This book is an essential guide for anyone aiming to improve their negotiation skills and interpersonal effectiveness.

In “On Intelligence,” John Hughes-Wilson offers an insightful journey through the clandestine world of intelligence and espionage. Covering historical events to modern dilemmas, the book illuminates the inner workings of intelligence agencies and their impact on world history. This exploration encourages critical thinking about the role of intelligence in society and the ethical issues it presents.

Fraud rises when budgets tighten. Pressure goes up, headcount comes down, and controls that quietly depended on someone having spare time stop working. This weekend read sets out where exposure concentrates during a downturn and which defenses actually hold: strong internal controls, systems that flag the patterns people miss, a crisis plan written before it is needed, and a culture in which raising an anomaly is not a career risk.

Joel Brenner sets the demand for transparency against the need for secrecy and finds that most institutions have no coherent answer to the collision. “Glass Houses” is less a privacy book than an account of what secrecy now costs, who can still maintain it, and how little of it survives in a world where nearly every action leaves a record somewhere.

Discover how we use our integrated capabilities for our clients

Case Studies and Client Stories