Social engineering is a type of scam that relies on social, not digital, cues. Scammers use intimate knowledge of your business, your employees, your projects, and more, to convince you to give them a password reset or approve a payment. They’ll often combine this knowledge with urgency, encouraging you to make a quick decision. 

No list of red flags prepares someone for it, because the manipulation isn’t happening via technology. It’s happening in someone’s head as they make a decision.

We’ve already covered what social engineering is at a foundational level: the definitions, the common attack categories, the broad mechanics of manipulation-based attacks versus purely technical ones. Building an effective security awareness program, how to structure training, set cadence, and measure whether any of it is working, is a separate subject we’ve also written about. 

This article sits between the two. Rather than definitions, or program design, it’s about what actually needs to go into your employee training: the psychological mechanics attackers rely on, and what real resistance looks like once someone is standing in the moment rather than reading about it in a slide.

Why social engineering works: six levers, one blind spot

Social engineering doesn’t succeed because employees are careless. It succeeds because it borrows shortcuts the human brain uses every day to move through ordinary decisions quickly, and then aims them at the wrong target. Robert Cialdini’s research on persuasion identified seven of these shortcuts decades ago, and six of them describe almost every social engineering attempt a business will encounter:

  • Reciprocity
  • Scarcity
  • Authority
  • Consistency
  • Social proof
  • Unity

Authority

Scammers rely most often on authority. People comply faster with a request that appears to come from someone senior, an IT administrator, or an external body like a regulator or supplier, often without checking whether that authority is real.

Urgency 

Urgency compounds it: a deadline, a locked account, or a payment that has to go out before the bank closes pushes people toward action and away from verification, because pausing to check feels like it might cause the very problem the attacker is threatening. 

Scarcity

Scarcity works the same way in a different costume: a limited-time offer, a one-time access window, a message implying that hesitation means missing out.

Social proof 

Social proof persuades people that a request is legitimate because others have apparently already gone along with it, “the rest of finance already approved this,” or a thread that looks like a real internal conversation. Liking exploits rapport: an attacker who is friendly, complimentary, or seemingly familiar with office culture lowers a target’s guard simply by being pleasant to deal with. 

Reciprocity

Reciprocity is the quietest of the six: a small favor, a piece of seemingly useful information, or a compliment offered first, which creates a mild, often unconscious sense of obligation to return the gesture.

None of these levers are sophisticated. They’re the same instincts that make ordinary workplace cooperation possible. Any request deploying one or more of these principles looks like a normal, slightly urgent, request; the kind people are trained their entire careers to respond to quickly and helpfully.

The attacks employees actually encounter in a business context

Most organizations focus on anti-phishing measures and we’ve written about defending against phishing attacks. But social engineering training that stops at email misses most of what employees are actually up against, particularly in an office or hybrid workplace where phone calls, visitors, and physical access are still part of daily routine.

Vishing

Voice phishing, or vishing, relies on fake phone calls or voice notes. A caller might pose as IT support asking someone to confirm their password before a system update, as a bank verifying a transaction, or as a courier needing a one-time code to complete a delivery. 

A person’s voice adds urgency and authority that text can’t fake convincingly, which is exactly why it remains effective even against people who consider themselves alert to phishing emails. Increasingly, attackers also use voice-cloning tools to imitate a real colleague or executive’s voice, which the NCSC has flagged as a growing risk(nuova finestra) for both individuals and organizations. We’ve also written about deepfake prevention

Pretexting

Pretexting involves creating a story which an attacker then uses to justify an unusual request. They may pose as a new supplier who needs account details to set up a payment, an auditor requesting access logs, or a job candidate asking an HR contact to confirm personal details for the background check.

The scenario is often built from small pieces of public information, like a job title and a supplier name stitched together to sound plausible.

Baiting

Baiting offers something an employee wants: a free resource, a branded USB drive or hard drive, a document titled Q3 salary review, in exchange for an action that compromises a device or account. It works because it doesn’t ask for trust the way a phishing email does; it relies on curiosity doing the persuading instead.

Tailgating

Tailgating, or piggybacking, is the only attack on this list that has nothing to do with a screen. An attacker follows an employee through a badge-controlled door, often carrying boxes, wearing something that looks like a uniform, or simply timing their approach for a moment when holding the door open is the polite thing to do. It exploits workplace courtesy directly, which is why physical security training tends to get overlooked in programs built entirely around inboxes.

What resistance to social engineering attacks actually looks like

Simply telling employees to “be more suspicious” doesn’t hold up under real pressure.  Suspicion is a feeling and attackers are specifically trying to override it. Training needs to replace that vague instruction with specific, repeatable behaviors that don’t depend on someone noticing they’re being manipulated in the moment.

Always verify

Verification through a separate channel is the single most useful habit a business can install. If a request arrives by email, confirm it by phone or in person, using a number or contact already on file rather than one supplied in the message itself. This one behavior defeats a large share of impersonation attempts regardless of how convincing the initial contact was, because it removes the attacker’s control over the verification step.

Slow down

Urgency has to be treated as a signal to slow down, not a reason to skip a step. Employees should be trained to notice when a request pushes them toward speed over process, because that pressure is rarely accidental. A genuinely urgent legitimate request can survive a two-minute verification call; one that can’t survive that delay should be treated with suspicion, regardless of who it appears to come from.

Get confirmation

Financial and credential requests should require a second person’s confirmation as standard practice, not as an exception reserved for large transactions. This removes the social pressure an attacker relies on when they isolate a single employee and ask them to act alone, and it gives that employee a straightforward, blame-free way to say “let me check with someone” without appearing unhelpful or distrustful.

Report near-misses

Near-miss reporting closes the loop. An employee who complied with part of a request, hesitated but eventually gave in, or later realized something felt wrong should be encouraged to report it even after the fact, and even if nothing appears to have gone wrong. These reports are often the earliest warning a business gets that it’s being targeted, and they only surface in a culture where reporting doesn’t carry embarrassment or blame.

The same instinct applies once money or data has actually moved: Action Fraud(nuova finestra), the UK’s national reporting center for fraud and cyber crime, exists because the earlier an incident is reported, the more useful it is to everyone else being targeted by the same pattern.

Why slides don’t build resistance, and simulation does

Reading about the six persuasion levers is useful for context, but it doesn’t change how someone behaves under real pressure any more than reading about a fire drill prepares someone to find the nearest exit. Resistance to manipulation is a practiced skill, not a fact retained from a slide deck, which is why the strongest social engineering training relies on simulation rather than instruction alone.

Effective simulation puts employees through a realistic version of the pressure they’ll actually face: a simulated vendor call requesting account changes, a fabricated urgent request from someone claiming to be a manager, or a staged visitor asking to be let through a secure door, and then gives immediate, specific feedback rather than a pass/fail score. 

The goal is to let employees experience the moment of pressure somewhere safe, notice which lever was being pulled, and build the instinct to pause and verify before it matters.

Difficulty should increase gradually and scenarios should reflect real roles. Someone in finance faces different pretexts than someone on the front desk, and the exercise should end with a debrief that explains the mechanism used, not just whether the person passed. 

Done well, simulation turns the six psychological levers into understandable and recognizable concepts that employees can recognize, which is the entire point of training designed to to hold up outside a classroom.

Training people, not just policies

Social engineering succeeds by aiming at instincts that make ordinary teamwork possible: trust in authority, responsiveness to urgency, the discomfort of questioning someone who seems senior or friendly. Training that only defines these attacks or lists their categories leaves employees exactly as exposed as before, because recognizing a definition and recognizing a live manipulation attempt are different skills entirely.

A curriculum that names the six psychological levers, walks through how vishing, pretexting, baiting, and tailgating actually show up in a workplace environment, and gives employees concrete, rehearsed behaviors (verify separately, treat urgency as a red flag rather than a deadline, bring in a second person, report even the near-misses) gives people something they can actually use under pressure. 

Reinforced through simulation rather than slides, and backed by unique passwords and MFA that limit what a successful attempt can reach, that combination is what turns awareness into resistance.

None of this replaces the work of building the training program itself: cadence, structure, how often it repeats, how you measure whether it’s landing. That’s the ground our companion guide on building a security awareness program covers. What belongs in here is the layer underneath the program: the psychology employees are actually up against, and the specific, rehearsed habits that hold up once the pressure is real rather than hypothetical.

A team that can name a persuasion tactic while it’s being used on them, and knows exactly which second person to call before acting, is a fundamentally harder target than one that’s simply been told to stay alert. That’s the gap you can close with this kind of training. 

The credential connection: Why containment still matters after a mistake

Training reduces how often social engineering succeeds, but it can’t reduce that number to zero. A program built with that goal will only ever fail. Someone will, at some point, hand over a password over the phone, click through a fabricated login page, or confirm a detail they shouldn’t have. What limits the damage at that point isn’t awareness —It’s whatever access controls were already in place before the call started.

A credential taken through social engineering is far less useful to an attacker if it’s unique to a single service and protected by multi-factor authentication (MFA). Unique passwords prevent one compromised credential from being reused to access other services, while MFA can prevent the stolen password alone from providing access even to the account it belongs to. 

This is the same containment logic covered in our guides to building a strong workplace security culture and creating robust password policies, and it’s worth repeating here because social engineering and password hygiene are usually treated as separate problems when they’re really two stages of the same attack.

A business password manager like Proton Pass for Business makes that containment realistic to maintain at scale, rather than something that depends on individual employees remembering to follow policy. 

When credentials are stored, generated, and securely shared through a managed password vault instead of memory, browsers, or spreadsheets, a single successful social engineering attempt stops being a route into every system an employee touches.

Proton Pass for Business makes credential management easy for every team member, not just your IT team:

Reduce your team’s exposure to social engineering with a secure business password manager.