Business
How to protect employees from social engineering
Short answer
Three things reduce the risk: a written procedure for confirming payments and access, an employee's right to stop without consequences, and regular short practice on real scenarios. Technical measures are necessary, but they do not remove the human decision — and that is what is being attacked.
Why it matters
In most incidents the employee acted in good faith: they were hurrying to help a manager or a client. Punishing that kind of mistake means the company learns about the next incident late. Awareness is therefore not a lecture but a change in what counts as normal behaviour.
A real scenario
How it looks from the inside
An accountant receives an email from “the director” with new bank details for a regular supplier and a request to speed up the payment. The sender's domain differs by one letter. Checking would take a minute, but the email says the director is in negotiations and unavailable — and that is the attack.
Signs
- A change of bank details arrives by email or messenger.
- A request to bypass approval for the sake of urgency.
- The sender is unavailable for verification “for an objective reason”.
- Confidentiality is requested inside the company.
- Contact comes from a new person referring to management.
What to do
- Introduce a rule: a change of bank details is confirmed by voice on a known number.
- Describe a short procedure for urgent cases — it must be faster than bypassing it.
- Remove punishment for reporting a mistake.
- Run breakdowns of real attempts once a month, fifteen minutes.
- Measure not “completed the course” but the speed and number of reports.
Expert view
When a company comes to us after an incident, we almost always find someone who noticed something odd and said nothing. The issue is not their competence but the fact that reporting felt awkward or frightening. That changes faster than people expect, and costs less than any technical solution.
Frequently asked questions
Do simulated phishing campaigns help?
They help if the results lead to a breakdown rather than punishment. Otherwise people learn to hide mistakes instead of reporting them.
How much time does a programme take?
The basic effect comes from short regular formats: 15–30 minutes a month, working through the company's own cases.
Where do we start with no budget?
With a written payment confirmation procedure and the rule “reporting is a good thing”. That is free and removes a significant share of the risk.