Check out all of our upcoming events


Latest cybersecurity news, insights and commentary by Telesoft engineers and specialists

Social Engineering explained...What is it and how can you protect yourself from an attack

Written by Robert Fitzsimons on Thursday, 30 January 2020. Posted in Cyber


Social engineering is one of the most widely utilised techniques by malicious actors within the cybersecurity industry today, with the recent annual Human Factor report by Proofpoint stating that social engineering is utilised in up to 99% of all cyber-attacks.

Social engineering is often a key element to the first stage of ethical hacking, or penetration testing, known as reconnaissance or information gathering.  However, whilst it is a widely utilised and readily available technique, it is also generally easy to overlook for the unsuspecting victim who falls foul to such methods.

But to be able to identify or prevent social engineering attempts, first we need to understand what social engineering is.

So what is Social Engineering?

Social engineering is a term used to describe the manipulation of human psychology, a weakness that has the potential to be found and influenced in every individual within every organisation, from the contractors and service workers through to the front of house staff and directors. Third parties and contractors are just as likely to be exploited as someone who works directly for the company.

Successful social engineering attempts can result in the breaking of security procedures and best practices whilst enabling the extraction of valuable information from individuals, which can, in turn, be utilised to gain access to areas that would not be otherwise available.

Social engineering involves many different methods of gaining information from individuals.

What are the most common social engineering attacks?

Baiting / Drop attack 

This is generally carried out by leaving a USB/CD or some other form of storage device where someone will likely find it, for example on a seat in a train or in a lobby of an organisation. This will only ever be as effective if the person is not very cyber aware and actually inserts the device into their computer system, either at home or work. The device will then automatically install malware and reach back to the malicious actor for further exploitation.

Spear/ Phishing 

Generally in the form of emails, text messages or phone calls, phishing is a fraudulent communication with a victim that intends to elicit a response of some kind, likely by clicking on a link provided in the message or giving up some personal details. Whilst phishing is fairly generic, spear phishing is much more targeted, focussing on specific individuals with a much more bespoke cover story, making it appear more realistic.

Image 1   A phishing attempt through text message with a malicious email made to appear legitimate.

Social Engineering Image 1                                                                                                                                   

 Image 2  Link has been copied and pasted into showing the real link.

Social Engineering image 2


The victim is generally compelled to provide information or access to sensitive data by the malicious actor pretending to be someone and explaining a reasonable need for the data. For example, the attacker could claim to be new to an organisations’ IT department and request passwords and usernames to allow remote updates by the team. 


Utilised to gain access into ‘secure’ areas, or areas in which security cards of some description are required. The attacker will follow an unsuspecting victim into an area directly behind them before the door can shut. Alternatively, they may be as transparent as asking a victim to open the door for them, claiming they ‘left their card at home.’ This can be very successful as people do not like to say no or challenge an individual due to the possibility of confrontation.

Shoulder Surfing

This is as simple as looking over someone’s shoulder when they are typing in a password on their laptop, a number sequence on a secure door keypad or even their pin number when they are using a cash machine.

With a wealth of techniques in the social engineers’ arsenal, it is no wonder as to why they are used so commonly.

Utilising the techniques

One of the most enticing elements of social engineering is its versatility; it can be used during the reconnaissance stage and potentially throughout almost any attack to ensure that your attacks are achieving the desired outcome.

The specific technique can be altered depending on the scenario, organisation and the individual or even the information the malicious attack is inevitably looking to achieve. For example, tailgating will be utilised where physical access is required, whereas baiting is more likely looking to achieve remote access. Additionally, these techniques can be used alone or in conjunction with one another, being tailored on the fly to suit a specific scenario.

How can we protect ourselves?

Social engineering is a technique that relies on the victim being unaware that they are being targeted. However, there are several factors that individuals can practice in order to make themselves less susceptible to social engineering, such as:

  1. Increased cyber awareness
  2. Identifying fake emails
  3. Avoiding clicking links or opening attachments
  4. Utilise up to date cybersecurity tools

Increased Cyber Awareness

This can be gained through individual interaction or ideally through the introduction of company training during employee induction and routinely throughout their employment. Training should discuss the different elements of social engineering and highlight the risk posed by introducing USBs into local networks, for example.

Identifying Fake Emails

It is always important to check where an email is coming from. The sender can often be the first indication that an email is malicious as it would likely be from a strange email address, or a slightly edited one. An example would be, where the letter ‘o’ is replaced with the number ’0.’ Whilst a small change, users will often not notice this and continue to open the email.

Avoiding Clicking Links or Opening Attachments

This is commonly exploited within phishing attempts as the link often redirects the user to a malicious page that will download malware, or could even prompt the user to enter their username and password, which will be recorded and provided the attackers with the user’s details. Additionally, if a link is opened within an organisations’ network, it could allow the attacker to gain access to many sensitive files.

Utilise Up-to-Date Cyber Security Tools

Many cybersecurity suites today will identify and prevent malicious attempts before they reach the end-users, reducing the overall risk. These tools should be maintained and kept up to date however, as vulnerabilities could be exploited in out of date software.


It is important to approach social engineering holistically and try to increase overall awareness for everyone, as personal computers are just as vulnerable as company infrastructure.

Whilst it is almost impossible to prevent these types of attacks from happening in the future, having a basic understanding of how they work and what to look out for will allow individuals to potentially mitigate attacks or even prevent them completely.

The next time someone you don’t recognise tries to follow you into a secure area, don’t be afraid to challenge them for their ID/ security pass and encourage them to visit the relevant desk if they have ‘forgotten’ it. Or maybe don’t pick up the shiny 64Gb USB stick from the floor and take it home for formatting because you need one. It is always better to be safe than sorry.



About the Author

Robert Fitzsimons

Robert Fitzsimons

Rob is a Field Applications Engineer with a background in Military Intelligence who recently completed his BSc (Hons) Intelligence and Cyber Security degree.

Leave a comment

You are commenting as guest.

Information cookies

Cookies are short reports that are sent and stored on the hard drive of the user's computer through your browser when it connects to a web. Cookies can be used to collect and store user data while connected to provide you the requested services and sometimes tend not to keep. Cookies can be themselves or others.

There are several types of cookies:

  • Technical cookies that facilitate user navigation and use of the various options or services offered by the web as identify the session, allow access to certain areas, facilitate orders, purchases, filling out forms, registration, security, facilitating functionalities (videos, social networks, etc..).
  • Customization cookies that allow users to access services according to their preferences (language, browser, configuration, etc..).
  • Analytical cookies which allow anonymous analysis of the behavior of web users and allow to measure user activity and develop navigation profiles in order to improve the websites.

So when you access our website, in compliance with Article 22 of Law 34/2002 of the Information Society Services, in the analytical cookies treatment, we have requested your consent to their use. All of this is to improve our services. We use Google Analytics to collect anonymous statistical information such as the number of visitors to our site. Cookies added by Google Analytics are governed by the privacy policies of Google Analytics. If you want you can disable cookies from Google Analytics.

However, please note that you can enable or disable cookies by following the instructions of your browser.