Social engineering refers to a range of techniques used by cybercriminals to manipulate people into revealing confidential information, granting access to a system or carrying out a specific action.
Unlike some cyberattacks that directly exploit a technical vulnerability, social engineering primarily targets the human factor. The cybercriminal attempts to gain the victim’s trust or create a sense of urgency in order to persuade them to act without taking the time to verify the situation.
For example, an attacker may impersonate a colleague, supplier, company manager or IT support service. They may then ask the victim to provide a password, click on a link, open an attachment, change bank details or make an urgent payment.
Phishing is one of the most common forms of social engineering. However, these techniques can also be used over the phone, by text message, on social media or even during face-to-face interactions.
Cybercriminals often use publicly available information to make their scenarios more convincing. The name of a company director, an employee’s job title or the identity of a supplier can, for example, be used to create a particularly credible fraud attempt.
Strengthen my cybersecurity with MCG
Protection against social engineering does not therefore rely on technology alone. Employee awareness plays an essential role. Learning to recognise unusual requests, verify someone’s identity and follow good security practices can significantly reduce the risk.
In cybersecurity, people can be targeted just as much as computers or servers. Training employees therefore helps turn them into a genuine line of defence against cyberattacks.