What is social engineering? Common techniques and defences
Social engineering is the practice of manipulating people into giving up information or access, rather than hacking technology directly. It exploits human traits such as trust, urgency, fear and the wish to be helpful, which is why it works even against well-protected systems. This article explains the common techniques, why people are so often the easiest target, and the defences that reduce the risk.
Common techniques
These are the techniques a beginner should recognise:
- Phishing — fraudulent messages that impersonate a trusted source. It is the most common form; see our what is phishing explainer.
- Pretexting — inventing a believable scenario, such as posing as IT support, to extract information.
- Baiting — leaving something tempting, like an infected USB drive or a free download, for the victim to use.
- Tailgating — following an authorised person through a secured door without proper credentials.
- Impersonation — pretending to be a colleague, manager, supplier or official to gain trust and cooperation.
Why people are the easiest target
People are the easiest target because trust and helpfulness are normal, useful behaviours that attackers turn against us. A message that creates urgency or invokes authority — “this is the director, I need it now” — pushes people to act before they think. Technical controls can be tested and hardened, but a convincing story aimed at a busy person is much harder to block.
That does not make people the weak link by nature; it means defence has to be designed around how people actually behave.
Where to learn more
Social engineering is a core topic in introductory security certifications. ISC2 Certified in Cybersecurity treats it at a foundational level, and the AWS Certified Security – Specialty covers the identity controls that contain its effects. Our /revision library covers that syllabus lesson by lesson.
Original practice questions, timed mock exams and revision notes. No card, nothing to pay.
Questions, answered
Sources
Exam details in this post come from the vendor's published exam guide, which is the authority on what is tested and how.
- ISC2 Certified in Cybersecurity exam outline — ISC2
- AWS Certified Security – Specialty (SCS-C03) exam guide — Amazon Web Services