A convincing caller claims to be from IT, says a senior director needs urgent access restored, and asks a receptionist to confirm a mobile number.

Nothing technical has happened. No system has been breached. Yet a criminal may already have the information needed to build trust, target the director or gain access through the next call.

Social engineering awareness for staff must prepare people for this moment, not simply teach them to identify suspicious emails and behaviour.

For organisations with public facing sites, busy operations and high-value people or assets, manipulation is a practical security risk.

It can support fraud, theft, unauthorised access, hostile reconnaissance and, in some circumstances, wider terrorism related planning.

The attacker is looking for a weakness (Vulnerability) between written procedure and human behaviour.

Why social engineering succeeds

Social engineering works because it exploits normal working instincts.

Staff want to be helpful, responsive and efficient. They are used to solving problems quickly for customers, colleagues, suppliers and senior leaders.

An attacker does not need everyone to make a mistake.

One person acting on an incomplete story can be enough.

The most effective approaches usually create urgency, authority or familiarity. A caller may pose as a contractor whose delivery is delayed at the gate.

An email may appear to come from a finance colleague chasing an overdue invoice.

Someone in person may wear credible branded clothing, carry a clipboard and move with confidence towards a restricted area.

These methods are not limited to phishing.

They include impersonation by telephone, text messages, false delivery requests, tailgating, QR code scams, deceptive social media contact and attempts to extract operational details through casual conversation.

Staff may be asked about shift patterns, security arrangements, visitor processes, staff names, alarm response or an executive’s travel plans.

Each detail can be low risk in isolation. Combined, it can build a useful picture for an adversary.

Modern threats expose old security thinking.

A policy that says – do not share confidential information – is necessary, but it does not tell a team member what to do when an apparently legitimate person is waiting, impatient and persuasive.

Social engineering awareness for staff is a capability issue

Awareness becomes capability when staff can recognise pressure, pause without embarrassment and use a clear reporting route. This is where many programmes fall short.

They measure whether people completed a module, rather than whether they can make a sound decision in a live operational setting.

Effective learning should be role specific. A front of house team faces different approaches from a payroll administrator, facilities manager, security control room operator or event supervisor. Reception and customer-facing staff may need to verify visitors and callers while maintaining professional service.

Finance teams need strong controls around payment changes and supplier details. Managers need to know how their name, authority and routine can be used to influence others.

The standard should be simple, can the person identify an unusual request, protect the information or access point in question, verify independently, and report the concern promptly?

If they cannot, the organisation has awareness but not readiness.

Teach the behavioural indicators, not just scam examples

Staff should understand that a single indicator does not prove malicious intent.

A rushed caller may genuinely be under pressure. A visitor without the right documentation may have made an honest mistake. The aim is not to make teams distrustful or obstructive.

It is to help them notice when a request does not match normal process.

Useful indicators include urgency that discourages checking, an appeal to senior authority, a request for an exception, reluctance to use normal channels, unnecessary interest in restricted information, or a story that changes when challenged.

When several indicators appear together, the need for verification rises.

Training should also address the psychological tactics behind the approach. People are more likely to comply when they fear delaying an important task, feel flattered by apparent trust, or believe everyone else is already cooperating.

Naming these tactics gives staff permission to slow down and check.

Have you heard of Elicitation? It’s an excellent information gathering techniques used on people, and not one question will be asked, but information will be given away due to built in human responses that are hard wired in out DNA.  The topic is covered in detail within the Mildot Group Brain Game. 

Give people words they can use

Good intentions fail when staff do not know how to challenge professionally. Vague guidance such as – be vigilant – leaves people to improvise, often in front of a customer, contractor or senior colleague.

Provide practical language that protects both the individual and the organisation. A receptionist might say, “I cannot confirm that information, but I can take your details and ask the relevant team to contact you.” A member of staff dealing with a payment request can say, “Our process requires independent verification before we make any changes.” At an access point, the response may be, “Please wait here while I confirm your authorisation.”

These phrases remove the personal confrontation.

The employee is not accusing someone of wrongdoing. They are following an established control.

That distinction matters, particularly in hospitality, retail, events and other environments where courtesy is part of the service standard.

Build verification into normal operations

The strongest defence is not a staff member who remembers every warning sign.

It is an operating model that makes secure behaviour the easy behaviour. Verification should be quick, clear and independent of the person making the request.

If a caller claims to be from an internal department, staff should use a known number from an approved directory, not a number supplied by the caller.

If a contractor requests access, the host, work order and authorisation should be confirmed through the agreed route. If a supplier changes bank details, the confirmation process should be separated from the email or message requesting the change.

This creates some friction.

It may add a few minutes to a legitimate request, and busy teams can see it as inconvenient. That is a real trade off.

But the alternative is allowing confidence and urgency to replace evidence. Leaders should make the expectation explicit, a short delay for verification is acceptable; bypassing a control to be helpful is not.

Procedures also need to work outside normal hours. Many social engineering attempts exploit reduced staffing, handovers, temporary workers or event day pressure.

If a team cannot easily find the right contact or report a concern at 22:00 on a Saturday, the process is not operationally complete.

Make reporting useful, fast and blame free

Staff will not report suspicious contact if they expect criticism for engaging with it.

They may also stay silent because they are unsure whether the incident is significant enough. Both responses give attackers room to repeat and refine their approach.

Set a straightforward threshold, report anything that feels unusual, seeks an exception, requests sensitive information or attempts to bypass a control. Reports should be easy to make, acknowledged quickly and used to improve the wider picture.

A minor telephone enquiry may reveal that several sites have received the same call. A rejected visitor may indicate reconnaissance activity around a venue.

Security and operational leaders should share relevant lessons without naming or shaming individuals. A short briefing on a recent attempt is often more memorable than a generic annual reminder. It also demonstrates that reporting leads to action.

For organisations considering their duties under Martyn’s Law, this discipline supports wider protective security readiness. It helps staff recognise suspicious behaviour, communicate concerns and act within defined procedures.

It should sit alongside, rather than replace, site-specific risk assessment, security planning and counter terrorism training.

Test performance under realistic pressure

A completion certificate cannot show whether staff will challenge a plausible impersonator during a busy shift.

Testing is needed, but it must be proportionate, lawful and designed to improve performance rather than catch people out.

Use realistic scenarios based on the organisation’s threat profile. A corporate office may test a fraudulent request for executive information. A retail estate may assess how teams manage an unplanned contractor visit.

An events operation may examine whether staff challenge an attempt to gain backstage access through a claimed supplier relationship.

The value lies in the debrief. Identify where the process was unclear, where staff lacked authority, where verification details were inaccessible, and where supervisors gave mixed messages.

Then fix the operational weakness. Mildot Group’s approach is built around this principle, turn security theory into action that performs under pressure.

Measurement should go beyond click rates or attendance.

Track the quality and speed of reports, repeat weaknesses by role or location, verification compliance, and the time taken to brief teams after a new threat emerges.

These measures show whether capability is improving.

Leadership sets the security standard

Senior people can unintentionally weaken controls when they ask staff to make exceptions, expect immediate access or treat verification as an inconvenience. Attackers understand this.

They often borrow the language, names and urgency associated with senior leadership because they know staff may hesitate to challenge it.

Leaders should model the behaviour they expect.

They should accept being verified, use approved channels and publicly support staff who pause a request. Where commercial pressure is high, managers must reinforce that secure service is still good service.

The best time to build this confidence is before an incident, during everyday calls, deliveries, visitor arrivals and payment requests.

Give staff clear authority to pause, a reliable route to verify and the confidence to report. When the stress arrives, they will have more than awareness.

They will have a practised security response.

.

Useful Links:

.

Why Mildot Group?

Built on Experience. Focused on Capability.

Mildot Group helps individuals and organisations build practical capability through professional learning, capability evaluations, premium publications and specialist consultancy. Every solution is designed to bridge the gap between theory and practical application, helping people and organisations perform with greater confidence in real-world environments.

Our Mission

Our mission is to help individuals and organisations build practical capability through professional learning, capability evaluations, expert guidance and real-world application. Everything we create is designed to bridge the gap between theory and practice, helping people make better decisions, strengthen resilience and perform with confidence.

Our Philosophy

We believe capability is developed through structured learning, practical application and continuous improvement, not simply by completing a course or meeting a compliance requirement. Every learning programme, capability evaluation, publication and consultancy engagement is designed to help individuals and organisations apply knowledge with confidence in real-world environments.

What Makes Mildot Group Different?

Real Operational Experience
Built on experience gained across military, corporate and international environments.

Practical Learning
Professional learning designed to develop skills that can be applied immediately.

Capability Focused
Building practical capability rather than simply delivering awareness or compliance.

Evidence-Based
Combining operational experience with research, proven frameworks and practical methods.

Individuals & Organisations
Supporting personal development, professional capability and organisational performance.

Continuous Development
A growing platform with new learning programmes, evaluations and professional publications added regularly.

Privacy Preference Center