What happened: You walked to reception. The individual was well-dressed, calm, and immediately professional when he saw you arrive. He introduced himself by name, made strong eye contact, and referenced your CEO by first name — he had clearly done his research. He mentioned a specific audit finding: "the DR configuration issue in rack B." It sounded plausible — there had been a DR discussion in last month's audit meeting, though you couldn't recall the specific rack reference.
Under direct social pressure — he was standing in front of you, relaxed and authoritative — you authorized a 30-minute escorted visit. Afterwards, you called your Grant & Associates liaison. No one from their firm had been at Meridian Capital that day. The individual had researched your organization well enough to name real infrastructure details, reference your CEO correctly, and construct a scenario that felt genuine under social pressure.
// WHAT WENT WRONG
• Direct in-person social pressure is more effective than phone or email pressure — proximity activates compliance instinct
• The attacker had done reconnaissance: CEO's name, audit context, plausible infrastructure detail ("rack B DR issue")
• Plausible detail ("sounds like something we'd discuss") is not verification — it's confirmation bias
• The protocol (call Grant & Associates from your records) was bypassed by going down yourself
• In-person assessments are manipulable; independent verification via your records is not
In-person social pressure is social engineering. The protocol must be followed even face-to-face. The correct response was to have your assistant request ID, then call Grant & Associates from your records — regardless of whether you chose to go down to reception. Going down did not change what verification was required; it just added the pressure of being face-to-face.