Pretexting. Baiting. Tailgating. Insider threats that were already on the inside. Social engineering attacks need no technical skill — only a plausible story and a willing target. Executives are the highest-value targets because they have the authority to override controls, approve transfers, and grant access. This module teaches you to recognize the human-layer attack before you become the entry point.
Social engineering attacks require no technical skill — only a plausible story and a willing target. Executives are the primary target because they have authority to override controls, approve transfers, and grant access on the spot. Every gatekeeping mechanism your organization built can be bypassed by a single authoritative-sounding phone call.
Pretexting, baiting, and tailgating each exploit a different aspect of human behavior: deference to authority, curiosity, and social compliance. Understanding how each attack chain works is the first step to interrupting it.
Fabricated authority scenarios. The attacker creates a believable identity — a regulator, an IT support technician, external counsel — and uses that persona to extract access or information. Real tactics include impersonating auditors demanding immediate server access, IT support requesting login credentials to "fix a VPN issue," and external counsel requesting document handover for a "time-sensitive legal matter."
Physical and digital lures. The attacker leaves something enticing that the target will interact with, triggering a malware infection or credential capture. Physical: USB drives labeled "Q3 Compensation Review" left in executive parking lots. Digital: fake job posting portals that harvest credentials, malicious invoice PDFs from spoofed vendor addresses that install keyloggers.
Physical access attacks. The attacker follows an authorized person through a secured door, exploiting social compliance — the instinct to hold the door for someone who looks like they belong. Badge-cloning proximity attacks go further: the attacker reads an employee's badge RFID wirelessly and clones it, creating a duplicate access credential.
These incidents illustrate the full spectrum — external social engineers, malicious insiders, compromised credentials. Each one was preventable with the right controls at the right moment.
Insider threats fall into three distinct categories. The appropriate response, monitoring strategy, and escalation path differ significantly depending on which type you're dealing with. Misidentifying the type leads to the wrong response at the wrong time.
Social engineering and insider threats produce observable signals. The problem is that each signal is individually explainable. The pattern is what matters. Train yourself to look for clusters, not individual anomalies.
The protocol for social engineering and insider threat suspicion is identical in structure but differs in execution. Know both paths before you need them.
Social engineering and insider threat governance is a board-level responsibility. The frameworks below define what regulators expect; the questions below are what you should be asking to close the gap between policy and practice.
You have an active audit underway — but no visit was scheduled for today. The man in the lobby has a clipboard, a lanyard, and twenty minutes of patience. Your assistant is waiting for your call. What do you do?
RUN THE SIMULATION ~5 minutes · Decision-tree scenario