Back to glossary

Social engineering

2 min read

In offensive operations, social engineering is manipulating people, through phishing, pretexting or vishing, to bypass technical controls. It targets the decision rather than the system, and it works because the decisions it targets are ones the organisation needs people to make quickly and often.

July 24, 2026
Compartir:

How it works

Every operation has the same four parts. Reconnaissance builds a picture of the organisation from public sources, which is OSINT: who reports to whom, which suppliers are used, what software appears in job adverts, who is on holiday. A pretext supplies a reason the request is normal, and the good ones are dull rather than dramatic: a supplier invoice query, a document to review, a mandatory training reminder. A channel delivers it, whether email, telephone, text message, a chat platform, a QR code or a visit. And an action is requested, which is normally to authenticate on a page the attacker controls, which is phishing, or to open a document, or to approve a payment.

The levers are the same ones that make an organisation function: authority, urgency, helpfulness, familiarity and the desire not to obstruct a colleague. That is why the problem is structural rather than a matter of individual carelessness.

What goes wrong

The organisation trains people to detect and does not change the procedures that make the request plausible. Detection advice ages badly: guidance about spelling errors and generic greetings was written for campaigns that no longer look like that, since messages are now personalised at volume and voices can be cloned, which is what makes a deepfake call a procedural problem rather than a novelty.

What holds is process. Verification through a channel the requester did not choose, dual authorisation for payments and privileged changes, a help desk identity procedure that does not rely on facts an attacker can research, and a reporting route that is faster and less unpleasant than complying. The last one is measurable and most programmes ignore it: the useful metric is how quickly the first report arrives, not how many people clicked.

The other structural answer is to make the credential worthless when the person is fooled, which is what phishing-resistant authentication does. People will be deceived; the question is what that deception yields.

Where this shows up in an audit

Exercises run under written agreement with defined scope, named approvers and limits, because these engagements touch employees personally and the ethical boundaries are tighter than in technical testing. Results are reported at the level of the organisation, never as a list of individuals who failed, since naming people destroys the reporting culture that is the actual control. We measure time to first report, proportion reported, whether the session obtained was usable, and what it reached. This is part of how we design and run social engineering exercises.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.