northdan.
Vezi pagina în română

IT Glossary

What is social engineering?

Hacking people rather than machines: the psychological manipulation through which attackers obtain access and money without breaking into a single system.

In the majority of successful company frauds, no security control failed. The firewall held, the passwords were never cracked, the antivirus reported nothing — because a person was persuaded to open the door and did so willingly. Social engineering is that craft: the deliberate exploitation of authority, urgency, helpfulness and fear to make a legitimate user act against their own organisation. It arrives as an email from the chief executive who needs a transfer handled quietly before a flight, as a supplier politely notifying a change of bank details, as an IT technician who needs a code read out to fix an urgent problem, as a candidate's CV that must be opened today, as a visitor in high-visibility clothing carrying a ladder. The techniques are old; what modern tools changed is the polish, since flawless business language in any language now costs nothing. This is why awareness alone is insufficient and procedure is not. The controls that actually hold are structural: payment changes verified on a previously known number, dual authorisation above a threshold, and an explicit organisational permission to slow down and check.

Let’s talk about your project

Message us on WhatsApp or send an email — you talk directly to a developer.

office@northdan.com · +40 752 070 247

Why it matters for your business

Transfer fraud blocked by procedure

Verification of bank detail changes on a stored number defeats the single most expensive attack pattern regardless of how convincing it was.

Trained people, not merely warned ones

Staff who have practised against realistic simulations recognise the pressure pattern, which is the element every variant shares.

A verification culture without stigma

When checking is expected rather than insulting, the attacker's strongest lever — reluctance to question a superior — stops working.

Frequently asked questions

Which social engineering schemes hit European companies most often?

Four dominate. Invoice redirection, where a supplier appears to notify new bank details. Chief executive fraud, an urgent confidential transfer requested from the top. Fake IT support asking for a one-time code during a manufactured emergency. And recruitment or delivery lures that get an attachment opened. All four target finance, HR and reception, which is where training budget belongs.

How do I verify a suspicious request without offending a genuine partner or manager?

Make the check a rule rather than a judgement about the person. Publish a policy stating that all payment detail changes and all out-of-process transfer requests are confirmed by callback to a number already on file, without exception and regardless of who asks. Genuine partners recognise professionalism; the only party ever offended by a documented control is the one who was hoping to bypass it.

How much does training actually help, given that people forget?

Substantially, but only when it is continuous. Single annual sessions decay within weeks. Programmes combining short quarterly refreshers with realistic simulated attacks reduce click rates several-fold and, more importantly, raise reporting rates — which is the metric that matters, because an attack reported in ten minutes is an incident while the same attack reported in ten days is a loss.