1. How social engineering works
What is social engineering
Social engineering is the art of manipulating people into doing something an attacker wants: handing over a password, transferring money, opening a file, or granting access to a building or system. Phishing, the most common form, does this by email, but the same techniques appear in text messages, phone calls, social media, and even face to face.
The important shift in thinking is this: the attacker is not hacking the computer, they are hacking you. Firewalls, spam filters, and antivirus all help, but a well-crafted message that lands in your inbox has already passed those defences. At that point, the only control left is the person reading it.
Why it works on everyone
There is a persistent myth that only careless or non-technical people fall for phishing. It is not true, and believing it is dangerous, because it makes you drop your guard. IT professionals, finance directors, and security specialists have all been caught. The majority of breaches involve a human element somewhere in the chain, which is exactly why attackers keep investing in these techniques.
Social engineering works because it targets normal, healthy human behaviour: we want to be helpful, we respond to authority, we act quickly when something seems urgent, and we trust messages that look like the hundreds of legitimate ones we handle every week. Attackers do not need you to be foolish. They need you to be busy, distracted, or under pressure, which describes most people on most working days.
What this course will do
This course will not turn you into a security analyst, and it does not need to. The goal is simpler: to help you recognise the moments when you are being manipulated, build a habit of pausing before you act, and know exactly what to do when something looks wrong or when you realise you have already clicked.
One idea underpins everything that follows: legitimate organisations and colleagues will never punish you for taking a moment to verify. Attackers, on the other hand, depend on you not taking that moment.
› Course contents
How social engineering works
Spotting phishing emails
Beyond email
Responding and reporting
Putting it into practice