Skip to content
English
  • There are no suggestions because the search field is empty.

Social Engineering: Beyond Phishing

Social engineering is the manipulation of people, not technology — and it doesn't stop at email. Attackers increasingly reach staff by phone, text message, QR code, and even in person. Here is KYND's guide to recognizing and defending against social engineering beyond the inbox.

What is social engineering?
Social engineering is any attack that manipulates a person into granting access, sharing information, or making a payment. Beyond email phishing, common forms include vishing (voice calls), smishing (text messages), quishing (malicious QR codes), pretexting (an invented scenario, such as a fake IT technician), and tailgating (following staff into secure areas).


Why does social engineering succeed?
These attacks exploit human instincts — helpfulness, deference to authority, and urgency — and arrive through channels email filters never see. Staff trained only to spot suspicious emails may not recognize the same scam delivered by phone, and AI-generated voice cloning is making impersonation of known colleagues and officials increasingly convincing.

Why are public entities a target?
Public entities are built to be open and helpful: staff directories, organization charts, meeting minutes, and budgets are public records, handing attackers ready-made material for a convincing pretext. Front-line staff are expected to assist callers and visitors, and that service culture can be turned against them by a confident impersonator.


What if we don't address it?
A single persuasive phone call could yield credentials, a fraudulent payment, or physical access to sensitive areas — and incidents that begin with social engineering can escalate into full network compromise or ransomware. Because no malware is involved at the start, these attacks often leave little technical trace until the damage is done.


Which frameworks should we align to?
NIST Cybersecurity Framework (CSF) 2.0 addresses the human layer through the Protect function, particularly awareness and training outcomes. CIS Controls v8 covers it through Control 14 (Security Awareness and Skills Training), which calls for training on social engineering in all its forms — not just email phishing.


Human and process defenses
Extend awareness training beyond email to cover phone, text, QR code, and in-person scenarios, and establish simple verification procedures: unusual or urgent requests are confirmed through a known channel before anyone acts. Enforce visitor sign-in and badge policies, and foster a no-blame culture so staff report attempts immediately.


Technical controls that limit the damage
MFA (multi-factor authentication) limits what an attacker can do with stolen credentials — prefer phishing-resistant methods, and train staff never to approve login prompts they didn't initiate. Use callback verification and dual approval for payments, and badge-controlled access for sensitive areas.


Checklist
When building or reviewing your defenses against social engineering, consider the following:

  1. Does awareness training cover vishing, smishing, QR-code scams, and in-person pretexting? 
  2. Are staff required to verify unusual or urgent requests through a known, separate channel before acting?
  3. Is MFA enforced broadly, with staff trained to reject login prompts they did not initiate? 
  4. Are payment and banking-detail changes verified by callback and subject to dual approval? 
  5. Are visitor sign-in, escort, and badge policies enforced for sensitive areas? 
  6. Can staff report a suspected social engineering attempt quickly, without fear of blame?