Social Engineering, The Art of Deception for Attacks
Social engineering is not a new concept, nor is it a concept specific to technology. However, the emergence of technology, along with the digital transformation process and organizations not wanting to see their systems attacked, has given the subject a particular importance.

"Hope this email finds you well. We are implementing some improvements to our systems' security and we need your collaboration to ensure a smooth transition. As part of this process, we are updating our login protocols to ensure that your personal information and company data are sufficiently protected. Please follow the link below to update your login credentials."
The paragraph above could be the beginning of a phishing email; readers have seen hundreds, even thousands of similar messages targeting employees to steal their information or gain access to their credentials.
Phishing is not the only type of social engineering, nor is it limited to the digital world; an example would be someone impersonating an employee or contractor to gain access to restricted buildings or areas.
The Evolution of Social Engineering Attacks
Attackers need a gateway to launch an attack against an organization, and sometimes the easiest way is not to discover a zero-day security vulnerability; it's to attack the person between the keyboard and the chair.
Ricardo Silva, a Cybersecurity Business Developer at Claranet Portugal, reminds us that social engineering is "one of the most used tactics by cybercriminals to 'obtain sensitive information by exploiting human trust and behavior'". In the digital age, this tactic "continues to evolve as malicious actors adapt to technological changes and security and cybersecurity practices adopted by organizations."
At the same time, Ricardo Silva adds that these attacks "use more complex methods and different communication channels," with "targeted phishing, spear-phishing, and even deep fakes emerging."
Olga Carvalho, a Cybersecurity Engineer at Noesis, reminds us that social engineering is an "old technique that exploits human psychology and manipulates it," recalling the "Trojan Horse," perhaps "the oldest and most popular social engineering attack in history." Although the method and purpose have remained the same - to deceive - social engineering attacks "have evolved significantly in terms of techniques, complexity, and access."
For example, Artificial Intelligence (AI) "has increased the capacity of tools such as mimicking the voice of people the victim knows; the content; and the techniques used by cybercriminals for these attacks."
According to Bruno Castro, founder and CEO of VisionWare, these attacks are "increasingly sophisticated, personalized, and targeted." Cybercriminals are using "more detailed techniques by impersonating the image and voice of CEOs, colleagues, and customers through mainly productive artificial intelligence."
At the same time, Bruno Castro says that phishing and targeted phishing campaigns have also "evolved, becoming increasingly difficult to distinguish, containing more personalized and less visual detection methods." In addition to "advanced technologies and psychological manipulation," criminals have "more tools at their disposal to gain unauthorized access to sensitive information."
Challenges in Dealing with Attacks
Olga Carvalho reminds us that social engineering is a "major challenge for companies" because "these types of attacks target human and non-technical security vulnerabilities, which are much more difficult to detect." Therefore, "a strong employee education component within a good cybersecurity culture is the first line of defense against these attacks."
At the same time, the Noesis representative adds that another important challenge is "the exposure of companies to digital information that allows attackers to obtain valuable information about the organizational hierarchy." With this information, "it is possible to direct the attack towards the most sensitive and privileged members of internal information or systems," and "companies must regularly review and evaluate their publicly available information to reduce the risks of social engineering attacks."
Similarly, Bruno Castro says that the human factor is "still" the main challenge for organizations. "There's an increasing difficulty in identifying and distinguishing complex attacks from legitimate interactions, and additionally, there is a growing need to protect an ever-expanding range of devices and communication channels."
Ricardo Silva explains that many employees are still unaware of the risks of social engineering and how to detect attack attempts, which makes them easier targets. The increase in remote work also "requires companies to adapt their technology, policies, and security training to protect remote workers," because attackers are using "various channels such as emails, social networks, and phone calls that make it harder to prevent and detect attacks." In my opinion, some organizations are lacking effective policies and practices to prevent and respond to these attacks.
Test and Create (and Repeat as Necessary)
Bruno Castro says that some of the applications that organizations can implement with their employees are organizing training or courses and awareness training such as phishing simulations. At the same time, "providing additional training for those who fail assessments is essential." The founder and CEO of VisionWare also says that other applications should "encourage the adoption of security measures such as verifying the source of communication before clicking on links or sharing confidential information; basically, promoting a culture of security and digital hygiene that must pass through all employees, from the lowest to the highest levels."
Ricardo Silva also argues that "testing and training employees on the risks of social engineering is necessary for organizations to protect themselves." To reach a "high level of maturity," regular training and courses, practical drills or attack simulations, and internal and continuous communication on the subject are necessary. However, this issue cannot be limited to employees: "the leadership of the organization must show commitment to cybersecurity and encourage a culture that values the protection of data and information," and this culture "should encourage all employees' collaboration and shared responsibility in maintaining a secure environment."
Olga Carvalho summarizes that "trained employees who can recognize social engineering attacks are the first line of defense for any company." Therefore, "a complete cybersecurity awareness strategy must include various applications that make employees aware of various social engineering methods and how they can be identified."
Create a Security Culture
As threats increase, it's important for employees to understand not only their own risks but also the risks the company faces. The answer is creating a security culture where employees are aware of the risks.
According to Ricardo Silva, a "strong and effective" cybersecurity culture, supported by leadership, requires regular employee training, clear policy implementation, and inter-departmental collaboration. "Organizations become more prepared to address and reduce risks associated with social engineering and other cybersecurity threats by investing in advanced technological solutions and encouraging open communication and shared responsibility environments."
Olga Carvalho shares that a zero-tolerance approach to cyber hygiene is necessary, "promoting a healthy and safe culture for both systems and people." At the same time, "companies should implement policies that strengthen clear guidelines to empower employees in detecting and preventing social engineering attacks."
Bruno Castro argues that along with continuous education, "encouraging open communication about potential threats and promoting alertness for any behavior that deviates from the organization's or employee's behavioral baseline is equally important." At the same time, security controls should be considered by applying least privilege principles, "defining that employees have only the minimum levels of access or permissions needed to perform their professional duties and not anything else."
Technological Support
It's true that employees should be the first line of defense for any organization, but when this first line fails, you need technology. Therefore, as Olga Carvalho pointed out, the first line of defense is sensitive employees; the second is technology.
The Noesis representative says that in terms of the environment, "email security solutions are determining in detecting and countering social engineering attacks, account theft, and information leakage." At the same time, it is necessary to have solutions that provide "multi-factor authentication, document classification, and measures to prevent contact with social platforms where employees are most vulnerable."
Finally, solutions supported by artificial intelligence or machine learning also allow for "not only identifying abnormal behavior but also automatically responding to phishing attacks." Therefore, "the synergy between humans and technology offers companies the best chance to deal with these types of attacks."

Social engineering is "one of the most used tactics by cybercriminals to 'obtain sensitive information by exploiting human trust and behavior'"
- Ricardo Silva, Cybersecurity Business Developer at Claranet Portugal *
According to Bruno Castro, organizations "should have advanced security solutions that allow them to identify and respond to malicious actions based on social engineering," that is, using AI technology to analyze, detect, and respond to advanced forms of these attacks. For example, "SOCs can be very helpful in this regard as they will integrate the necessary technologies for threat monitoring, protection, and reduction with an intelligence component based on big data correlations at a behavioral level."
The Claranet Portugal representative argues that organizations should "adopt multiple technological solutions and services such as anti-spam solutions" to reduce the risks of social engineering cyber attacks. "Implementing effective firewalls to protect against malicious traffic and unauthorized access attempts is also very important. Keeping antivirus programs up to date can help protect devices from malware that could be distributed through social engineering attacks," he adds.
Warning Signs
Bruno Castro argues that warning signs include "any direct communication with employees to access personal or corporate information using the human factor" or "requests for confidential information or personal data via email or phone for financial transactions." At the same time, "urgency feelings and suspicious URLs and attachments are also explanatory indicators for alarm. Grammatical errors and text with a robotic communication feel are also urgent warning signs."
Ricardo Silva notes that "unwanted emails, short messages, or phone calls could be indicators of a social engineering initiative that encourages the disclosure of confidential information or requires immediate action." Therefore, companies "should carefully check the sender's email address or the URL of the mentioned website and be cautious of emails and messages containing unexpected attachments or links. By identifying and considering these warning signs, organizations can better protect their assets and valuable information from social engineering attacks."
Olga Carvalho states that "detecting social engineering attacks requires significant effort since cybercriminals use various methods to communicate with victims." Therefore, "it is up to organizations to be attentive and investigate potential signs indicating that a social engineering campaign is ongoing."
Source: Social Engineering: The Art of Deception to Attack (itsecurity.pt)