SaveMyCert
Cloud basics

What is social engineering? Common techniques and defences

Social engineering is the practice of manipulating people into giving up information or access, rather than hacking technology directly. It exploits human traits such as trust, urgency, fear and the wish to be helpful, which is why it works even against well-protected systems. This article explains the common techniques, why people are so often the easiest target, and the defences that reduce the risk.

What social engineering is

Social engineering means attacking the person instead of the system: an attacker persuades someone to hand over a password, open a door, approve a request or install something harmful. No software vulnerability is needed, because the victim supplies the access. It can happen online, by phone or in person.

It is a broad category, and several of the best-known threats are simply social engineering delivered in a particular way.

Common techniques

These are the techniques a beginner should recognise:

  • Phishing — fraudulent messages that impersonate a trusted source. It is the most common form; see our what is phishing explainer.
  • Pretexting — inventing a believable scenario, such as posing as IT support, to extract information.
  • Baiting — leaving something tempting, like an infected USB drive or a free download, for the victim to use.
  • Tailgating — following an authorised person through a secured door without proper credentials.
  • Impersonation — pretending to be a colleague, manager, supplier or official to gain trust and cooperation.

Why people are the easiest target

People are the easiest target because trust and helpfulness are normal, useful behaviours that attackers turn against us. A message that creates urgency or invokes authority — “this is the director, I need it now” — pushes people to act before they think. Technical controls can be tested and hardened, but a convincing story aimed at a busy person is much harder to block.

That does not make people the weak link by nature; it means defence has to be designed around how people actually behave.

How to defend against social engineering

Effective defence combines awareness with procedures that do not depend on anyone’s judgement in the moment. Training helps people recognise manipulation, while clear verification steps — such as confirming an unusual request through a separate channel — mean a convincing story is not enough.

Technical safeguards limit the damage when someone is fooled. Multi-factor authentication means a stolen password alone does not grant access; see our what is multi-factor authentication explainer. Least privilege restricts what any one account can reach, and zero trust, covered in our what is zero trust security article, treats every request as needing verification.

Where to learn more

Social engineering is a core topic in introductory security certifications. ISC2 Certified in Cybersecurity treats it at a foundational level, and the AWS Certified Security – Specialty covers the identity controls that contain its effects. Our /revision library covers that syllabus lesson by lesson.

Ready to start studying — free?

Original practice questions, timed mock exams and revision notes. No card, nothing to pay.

Jump straight into an exam
SCS-C03CC

Questions, answered

Social engineering is manipulating people into revealing information or granting access, instead of attacking technology. It exploits trust, urgency, fear or helpfulness rather than a software flaw.

Sources

Exam details in this post come from the vendor's published exam guide, which is the authority on what is tested and how.

Keep reading

Cloud basics
What is the CIA triad? Confidentiality, integrity and availability
Cloud basics
ALB vs NLB: which AWS load balancer should you use?
Cloud basics
BigQuery vs Snowflake: which cloud data warehouse?
Cloud basics
Databricks vs Snowflake: what’s the actual difference?