For business management solutions email us or call 020 3004 4600

What is Social Engineering?

Social engineering is the use of psychological manipulation to trick people into breaking normal security procedures, such as revealing passwords, granting access, or making a payment, rather than exploiting a technical vulnerability in a system.

How social engineering works

Social engineering relies on trust, urgency, authority or fear to bypass a person's usual caution, and it takes many forms: phishing emails, phone-based scams known as vishing, pretexting, where an attacker invents a plausible scenario, baiting with infected devices left to be found, and tailgating, following someone through a secure door. Because it targets human behaviour rather than a system's code, technical controls alone cannot fully prevent it, which is why staff awareness training and clear procedures sit alongside tools like Multi-Factor Authentication (MFA) and email security as core defences.

How UK businesses defend against social engineering

  • An attacker phones a company's IT helpdesk pretending to be an employee locked out of their account, attempting to convince staff to reset a password without proper verification.
  • A fraudster leaves a USB drive labelled "salaries 2026" in an office car park, hoping an employee plugs it into a work computer out of curiosity.
  • Someone follows an employee through a secure entrance without swiping their own access card, relying on politeness rather than a technical exploit to gain physical access.
  • A business runs regular staff awareness training covering the different forms social engineering can take, from phishing emails to phone-based scams, so employees recognise the tactics rather than just specific examples.

How Advantage helps SMEs defend against social engineering

Advantage helps SMEs build defences against social engineering that go beyond technology alone, combining staff awareness training with technical controls such as multi-factor authentication and email security to reduce the risk of human manipulation succeeding.

Explore Advantage's cyber security services →

Frequently Asked Questions

Is phishing a type of social engineering?

Yes, phishing is one common channel through which social engineering is carried out, typically using email, alongside other methods such as phone calls, physical impersonation or fake websites.

Can technology alone stop social engineering attacks?

Not entirely, since social engineering targets human behaviour rather than technical vulnerabilities, so staff awareness and clear verification procedures are needed alongside technical controls.

What is pretexting in social engineering?

Pretexting is when an attacker invents a plausible false scenario, or pretext, to convince someone to share information or take an action they otherwise wouldn't, such as posing as IT support or a supplier.