What Is Social Engineering in Cybersecurity?
Social engineering is the use of psychological manipulation to trick people into revealing information or taking actions that compromise security, rather than exploiting technical vulnerabilities. Phishing is the most common form, alongside vishing, smishing and pretexting.
Quick answer
Social engineering is the use of psychological manipulation to trick people into revealing information or taking actions that compromise security, rather than exploiting technical vulnerabilities. Phishing is the most common form, alongside vishing, smishing and pretexting. The strongest defence is trained staff backed by strict verification and managed cybersecurity that catches what people miss.
Key Points
What you need to know.
The Short Answer
21% of businesses that experienced a breach reported a negative outcome such as loss of money or data.
For UK Businesses
7% of businesses that experienced a breach reported temporary loss of access to files or networks — up from 4% in 2024.
Cost Considerations
The NCSC handled 429 total incidents in 2025, with 204 classified as nationally significant — the highest-ever number.
Next Steps
What you should do with this information.
Quick Comparison
| Feature | Option A | Option B |
|---|
Last updated: June 2026
What does social engineering actually mean?
Social engineering is hacking the human, not the firewall. Instead of breaking encryption or exploiting a software flaw, the attacker manipulates a person into handing over credentials, approving a payment, or opening a malicious file. It works because it targets trust, urgency, authority and the simple desire to be helpful.
This is why it bypasses expensive technical controls. A locked-down network still depends on people who answer emails, take phone calls and process invoices. Get one of them to act, and the attacker walks through the front door with valid credentials. The UK's National Cyber Security Centre treats it as one of the primary routes into an organisation, which is why its phishing guidance for organisations focuses on process and people, not just software.
What are the main types of social engineering attacks?
The main types are phishing (fraudulent emails), vishing (voice calls impersonating IT support or banks), smishing (malicious SMS), pretexting (fabricated scenarios to extract information), baiting (infected USB drives left to be found), and tailgating (physically following authorised staff into secure areas). Email-based attacks dominate by a wide margin.
Phishing is the headline threat: "85% of businesses that experienced a breach identifying phishing as the vector" (DSIT 2025), per the UK government's Cyber Security Breaches Survey 2025. Knowing the variants helps staff recognise an attack when it arrives by a channel they were not expecting.
| Attack type | How it works | Primary defence |
|---|---|---|
| Phishing | Fraudulent email posing as a trusted brand or colleague | Email filtering, phishing protection, staff training |
| Spear phishing | Targeted email using researched personal detail | Verification procedures, phishing simulation training |
| Vishing | Phone call impersonating IT, a supplier or a bank | Call-back on a known number, never trust caller ID |
| Smishing | Malicious link or request sent by SMS | Block external links on mobile, report-and-delete culture |
| Pretexting | Fabricated story to extract information or access | Strict identity checks before releasing data |
| Baiting | Infected USB or "free" download left to tempt a user | Device control policy, disable autorun |
| Tailgating | Following staff through a secure door | Badge discipline, visitor sign-in |
Why is social engineering so effective against businesses?
Social engineering exploits human psychology — trust, urgency, authority and helpfulness — rather than technical weakness. Even well-trained staff can be deceived by a convincing pretext, especially when attackers research their targets first using LinkedIn, company websites and public filings to make the approach feel legitimate.
The financial impact is real: "The average cost of the most disruptive breach is £3,550" (DSIT 2025), and social engineering is the initial access method behind the majority of these incidents. Worse, AI is sharpening the threat — generative tools now produce flawless, personalised emails and clone voices, removing the spelling mistakes and awkward phrasing that used to give attackers away. The old advice to "spot the typo" no longer holds.
How big is the social engineering threat to UK businesses?
It is the dominant cause of UK breaches and the harm is rising. According to the Cyber Security Breaches Survey 2025, "21% of businesses that experienced a breach reported a negative outcome such as loss of money or data," and "7% of businesses that experienced a breach reported temporary loss of access to files or networks — up from 4% in 2024."
The trend at national level matches what businesses see day to day. The NCSC handled 429 total incidents in 2025, with 204 classified as nationally significant — the highest-ever number, a pattern set out in the NCSC threat reporting. Business email compromise is a particular growth area: "overall IC3-reported cybercrime losses attacks increased 33% in 2025" (FBI IC3 Report). For most UK SMEs, the question is not whether social engineering reaches their inbox, but whether a member of staff acts on it.
- Email is the primary channel — start defending there with email security.
- Targeted attacks on named individuals are growing — understand spear phishing and how it differs from mass phishing.
- Finance teams are the highest-value target because they can move money.
How can your business defend against social engineering?
Effective defence combines regular staff awareness training, simulated phishing campaigns, strict verification procedures for financial requests, and technical controls such as email filtering and multi-factor authentication. The aim is a workforce that pauses, questions and reports — backed by technology that blocks what people miss.
No single control is enough. A blameless reporting culture, where staff feel safe flagging a suspicious email or call, is as important as any tool. Organisations with formal verification procedures for payment changes are significantly less likely to fall victim to invoice fraud.
- Train continuously, not annually. Short, frequent sessions and live phishing simulation training beat a once-a-year slide deck.
- Verify out of band. Confirm any payment or bank-detail change by calling a known number — never the contact details in the request.
- Turn on MFA everywhere. Stolen credentials are far less useful behind a second factor; see our MFA setup for Microsoft 365.
- Filter at the gateway. Strong email security and phishing protection remove most malicious messages before staff ever see them.
- Have a plan for when it works. Even good defences fail occasionally — rehearse your incident response so a click does not become a crisis.
At AMVIA we run this for 1,200+ UK businesses on a security-first model: one accountable provider, Microsoft-certified engineers, and Microsoft Defender plus Barracuda doing the technical heavy lifting behind the training. One provider. Security-first. Microsoft-certified.
What should you do if someone falls for a social engineering attack?
Act fast and assume compromise. Reset the affected credentials immediately, revoke active sessions, and check for mailbox rules or forwarders the attacker may have set up. Tell your IT or security team and your bank if money or payment details were involved, and preserve the evidence rather than deleting it.
Speed limits the damage. A reported phishing click contained within minutes is an inconvenience; the same click discovered weeks later via an unexplained invoice is a breach. This is exactly where managed monitoring earns its keep — our incident response and 24/7 SOC work to contain an account takeover before it spreads across the business.
Frequently Asked Questions
The main types are phishing (fraudulent emails), vishing (voice calls impersonating IT support or banks), smishing (malicious SMS), pretexting (fabricated scenarios to extract information), baiting (infected USB drives), and tailgating (following authorised staff into secure areas). Phishing dominates: "85% of businesses that experienced a breach identifying phishing as the vector" (DSIT 2025), making email the most prevalent route.
Combine regular staff awareness training, simulated phishing campaigns, strict verification procedures for financial requests, and technical controls like email filtering and MFA. A blameless reporting culture, where staff flag suspicious contacts without fear, is critical. Organisations with formal out-of-band verification for payment changes are significantly less likely to fall victim to invoice and BEC fraud.
It exploits human psychology — trust, urgency, authority and helpfulness — rather than technical vulnerabilities. Even trained staff can be deceived by a sophisticated pretext, especially when attackers research targets on LinkedIn and company websites first. AI now removes the spelling and grammar errors that once gave attacks away, making convincing fakes faster to produce and harder to spot.
Yes. Phishing is the most common form of social engineering, using fraudulent emails to manipulate people into revealing credentials, approving payments, or opening malicious files. Other forms include vishing (phone), smishing (SMS) and pretexting. In UK breaches, phishing is identified by 85% of affected businesses as the attack vector (DSIT 2025), making it the dominant social engineering technique.
No. Email filtering, MFA and endpoint protection block a large share of attacks, but social engineering targets people, so some attempts always reach a human. The reliable defence is layered: technical controls to reduce volume, ongoing training to build judgement, and verification procedures so a single mistake cannot authorise a payment or expose data on its own.
Phishing is sent in bulk to many recipients using a generic lure. Spear phishing is targeted at a specific person or role, using researched detail — a real supplier name, a colleague's writing style, a live project — to make the approach believable. Spear phishing has a far higher success rate, which is why high-value staff such as finance teams need extra verification.
Related Questions
What Is Phishing?
Phishing is the most common social engineering attack — how it works and how to defend against it.
Email Security and Phishing Protection
Advanced email filtering that blocks social engineering attempts before they reach your staff.
Cybersecurity Guide for UK SMEs
How staff awareness training and technical controls work together to defend against social engineering.
Protect your business → Get Cybersecurity Assessment