Social engineering exploits predictable patterns in human psychology to manipulate people into compromising security, and it remains one of the most prevalent attack vectors in cybersecurity today. Attacks can be carried out through messaging, voice, in-person interaction, or no-contact physical methods, each with distinct tradeoffs in effort, effectiveness, and scalability.
Social Engineering
A good portion to most of the attacks that happen out there utilize some sort of social engineering.
The way our minds work is amazing, and we still don't have computers that can do the processing power that our brains can do. It is really quite incredible. However, there are some features of our brain, the way we function and the way we work, that really benefit us but also can be our downfall. People can use the way our mind creates things and works and how it processes things — they can use that to their advantage to manipulate us. If we're not knowledgeable and we don't understand how that can happen, we can be susceptible to that.
Social engineering is the attempt to trick someone into saying or doing something that will lead to compromising security. This could be done through messages, through voice, in person, or there are even some no contact methods that we can use to really break into a system through social engineering.
Each one of these methods has their pros and cons.
For instance, if we use messaging — let's say we're doing phishing emails and we're sending them into a company — it's so easy to send out these emails, so it's very easy to carry out. We essentially don't really have to do much at all. We just type in what we want to say and then send it off, and it sends it to the people that we want to send it to. The effectiveness tends to be low, at least when we're hitting all these people. Most of them are not going to click on it; hopefully most people are trained in that way. However, there still is a handful — even in small companies that I worked in, there's been a handful of people that will still click on these links. So overall this can be very effective, even though the effectiveness per person is very low. It is extremely scalable.
Then when we go to something like voice, that's a little more work on our part. If we're attacking a company and trying to use voice to do that, it can be more effective. We can be more persuasive over a voice conversation than we could on some sort of email. They're going to listen to what we have to say a little bit more, and maybe we can get our foothold in there. However, it becomes a little more difficult, because now for every phone call I have to have a person that's actually doing that, that's actually carrying out that type of attack. So it can be scalable, and there are call centers that do this. However, it is not as common as phishing emails.
Then we have in person. This becomes a lot more difficult because I have to actually show up. It's a lot more high risk. But the effectiveness is very high as well. Being in person adds this connection that we wouldn't have otherwise, and I'm able to do a lot more with that. But it's just not scalable.
Then there's no contact. This is also something that can be fairly easy — not as easy as messages, but still fairly easy. I'd have to somehow deliver it physically to them. The effectiveness is fairly low, but once again, if we do enough of this, we'll get somebody tricked into doing it. And I don't know that this one is all that scalable. It's scalable more than some, but less than others.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →