Firewalls, antivirus software, encryption, companies invest millions of Kč in technology. Yet every day they are compromised because attackers do not target the hardware but the people. Social engineering: the art of manipulation, bypasses all technological defences by persuading an employee to open the door themselves.
According to the Verizon Data Breach Investigations Report, the human factor is present in more than 74% of all security incidents. An uncompromising figure that clearly states: Investment in employee safety training is not optional. It is essential.
Types of social engineering attacks
Social engineering is not a monolithic technique. Attackers combine various approaches depending on the target, available information and communication channel. Knowing the individual types is the first step towards defence.
Phishing, spear-phishing and whaling
Phishing It is a mass email attack where the attacker sends thousands of messages impersonating a bank, courier or IT department. It relies on statistics, even if only one per cent of recipients respond, it is considered a success.
Spear phishing This is a targeted variant. The attacker researches a specific individual in advance: from LinkedIn, the company website or data breaches, and personalises the message. The email appears to come from a colleague, manager or business partner. The recipient sees their name, a project they are working on is mentioned, and the link looks legitimate. The success rate is dramatically higher.
Whaling It targets top-level management (CEO, CFO). A single CEO fraud: a call for an urgent money transfer, can cost a company millions of Kč. In the Czech Republic, we record dozens of such cases annually.
Vishing and smishing
Vishing Voice phishing is conducted over the phone. The attacker impersonates technical support, a bank advisor, an auditor or a police officer. The voice, urgency and authority are convincing, especially if the attacker knows the target's name, company name or order number.
Smishing uses SMS messages. Typical scenario: "Your package is waiting at customs; confirm payment HERE." The link leads to a fake page capturing login credentials or installing malware on the phone.
Pretexting and baiting
Pretexting It involves creating a convincing fake identity and scenario. The attacker poses as a new IT technician, supplier or auditor and gradually obtains sensitive information from the victim, passwords, access codes, internal documents. A skilled attacker builds trust over several interactions.
Baiting (bait) uses physical media. A USB flash drive labelled "Payroll Q3 2025" found in the car park, who could resist? Once plugged into a company computer, it installs malware. This attack remains surprisingly effective even in 2025.
Psychological principles underpinning social engineering
Social engineering is not just a technical attack. It is psychological manipulation. Attackers know and systematically exploit principles described by scientists such as Robert Cialdini:
- Authority - "I'm calling from the IT department" or "I'm your new manager" immediately lowers critical thinking. People are used to listening to authorities.
- Urgency and fear - "Your account will be blocked within 2 hours" creates pressure that shuts down rational thought. Under pressure, we make mistakes.
- Mutuality - "I've sent you the document; I just need your access code." A small favour creates a sense of obligation.
- Social proof - "All your colleagues have already updated their login credentials." Don't stand out; do what everyone else does.
- Popularity - The attacker builds rapport, being friendly and witty. We tend to trust people we like more.
- Shortage - "This offer is valid only today." Limited opportunities pressure you into hasty decisions.
Key understanding: It is not that the employees are stupid.The point is that people are vulnerable, and psychological manipulation mechanisms work on everyone, without exception. Even on security experts.
Real-life examples from practice
Case study: CEO fraud in a Czech manufacturing company
The finance director received an email apparently from the general manager, who was at a conference abroad. The email was sent from an address that differed from the real one by only one letter. The request: an urgent transfer of 2.3 million Kč to a foreign account due to "an acquisition that must be kept secret from the board." He added a note: "I can't call right now, I'm in a meeting." The money was transferred. It could not be recovered.
Case Study: Vishing on the IT Helpdesk
The attacker called the IT helpdesk of a small financial firm. He knew the name of the IT administrator (LinkedIn), the name of the internal system (company website) and simulated a VPN problem. He requested a password reset and "temporary access" for remote diagnostics. Within 48 hours, the attacker had access to the client database.
Case study: USB baiting at a hospital
Fifteen USB drives labelled "External Audit Results - CONFIDENTIAL" were found in the hospital car park. Four of them were plugged into company computers. Each contained a keylogger that sent keystrokes to a remote server.
How to train employees: A practical approach
A one-off training session is not enough. Social engineering is constantly evolving and employees forget. An effective security literacy programme must be continuous, measurable and tailored to the organisation's reality.
Phishing simulations
The most effective method is controlled phishing campaigns, organised by the company itself (or in cooperation with a specialist company such as SecureOn.cz) sends realistic phishing emails to its own employees and monitors who clicks on them. The key is that after clicking, the employee immediately receives educational feedback: not a reprimand, but an explanation of what gave away the fake email.
Companies that carry out regular phishing simulations reduce the average click-through rate on phishing by 60-70% within one year.
Practical training and tabletop exercises
Theory is not enough. Employees need to practice specific scenarios:
- How to verify the identity of a caller claiming to be from IT support
- What to do if you receive a suspicious email from a "CEO
- How to correctly report a security incident without fear of penalty
- How to respond to an unauthorised person in the office (tailgating)
A blame-free safety culture
The biggest mistake organisations make is punishing employees who report clicking on phishing links or becoming victims of manipulation. The result is that the next incident goes unreported, and the organisation only discovers it months later, when the damage is far greater. A safe culture for reporting incidents is key.
Metrics and regular reassessment
The programme must be measurable. Monitor: click rates on simulated phishing attempts, time to report an incident, post-training test results, and the number of actual incidents caused by human error. Adjust the programme based on data, different teams exhibit different risk behaviours.
Social engineering will always exist because it exploits basic human traits. The goal is not to create paranoid employees, but healthily sceptical people with a clear procedure for what to do when they are unsure. If you wish to set up a security literacy programme for your company, experts from SecureOn.cz will prepare training tailored precisely to your environment and risks.