AEO Answer

What Is Social Engineering in Cybersecurity?

Social engineering is the use of psychological manipulation to trick people into revealing information or taking actions that compromise security, rather than exploiting technical vulnerabilities. Phishing is the most common form, alongside vishing, smishing and pretexting.

Quick answer

Social engineering is the use of psychological manipulation to trick people into revealing information or taking actions that compromise security, rather than exploiting technical vulnerabilities. Phishing is the most common form, alongside vishing, smishing and pretexting. The strongest defence is trained staff backed by strict verification and managed cybersecurity that catches what people miss.

Key Points

What you need to know.

The Short Answer

21% of businesses that experienced a breach reported a negative outcome such as loss of money or data.

For UK Businesses

7% of businesses that experienced a breach reported temporary loss of access to files or networks — up from 4% in 2024.

Cost Considerations

The NCSC handled 429 total incidents in 2025, with 204 classified as nationally significant — the highest-ever number.

Next Steps

What you should do with this information.

Quick Comparison

Feature
Option A
Option B

Last updated: June 2026

What does social engineering actually mean?

Social engineering is hacking the human, not the firewall. Instead of breaking encryption or exploiting a software flaw, the attacker manipulates a person into handing over credentials, approving a payment, or opening a malicious file. It works because it targets trust, urgency, authority and the simple desire to be helpful.

This is why it bypasses expensive technical controls. A locked-down network still depends on people who answer emails, take phone calls and process invoices. Get one of them to act, and the attacker walks through the front door with valid credentials. The UK's National Cyber Security Centre treats it as one of the primary routes into an organisation, which is why its phishing guidance for organisations focuses on process and people, not just software.

What are the main types of social engineering attacks?

The main types are phishing (fraudulent emails), vishing (voice calls impersonating IT support or banks), smishing (malicious SMS), pretexting (fabricated scenarios to extract information), baiting (infected USB drives left to be found), and tailgating (physically following authorised staff into secure areas). Email-based attacks dominate by a wide margin.

Phishing is the headline threat: "85% of businesses that experienced a breach identifying phishing as the vector" (DSIT 2025), per the UK government's Cyber Security Breaches Survey 2025. Knowing the variants helps staff recognise an attack when it arrives by a channel they were not expecting.

Attack typeHow it worksPrimary defence
PhishingFraudulent email posing as a trusted brand or colleagueEmail filtering, phishing protection, staff training
Spear phishingTargeted email using researched personal detailVerification procedures, phishing simulation training
VishingPhone call impersonating IT, a supplier or a bankCall-back on a known number, never trust caller ID
SmishingMalicious link or request sent by SMSBlock external links on mobile, report-and-delete culture
PretextingFabricated story to extract information or accessStrict identity checks before releasing data
BaitingInfected USB or "free" download left to tempt a userDevice control policy, disable autorun
TailgatingFollowing staff through a secure doorBadge discipline, visitor sign-in

Why is social engineering so effective against businesses?

Social engineering exploits human psychology — trust, urgency, authority and helpfulness — rather than technical weakness. Even well-trained staff can be deceived by a convincing pretext, especially when attackers research their targets first using LinkedIn, company websites and public filings to make the approach feel legitimate.

The financial impact is real: "The average cost of the most disruptive breach is £3,550" (DSIT 2025), and social engineering is the initial access method behind the majority of these incidents. Worse, AI is sharpening the threat — generative tools now produce flawless, personalised emails and clone voices, removing the spelling mistakes and awkward phrasing that used to give attackers away. The old advice to "spot the typo" no longer holds.

How big is the social engineering threat to UK businesses?

It is the dominant cause of UK breaches and the harm is rising. According to the Cyber Security Breaches Survey 2025, "21% of businesses that experienced a breach reported a negative outcome such as loss of money or data," and "7% of businesses that experienced a breach reported temporary loss of access to files or networks — up from 4% in 2024."

The trend at national level matches what businesses see day to day. The NCSC handled 429 total incidents in 2025, with 204 classified as nationally significant — the highest-ever number, a pattern set out in the NCSC threat reporting. Business email compromise is a particular growth area: "overall IC3-reported cybercrime losses attacks increased 33% in 2025" (FBI IC3 Report). For most UK SMEs, the question is not whether social engineering reaches their inbox, but whether a member of staff acts on it.

  • Email is the primary channel — start defending there with email security.
  • Targeted attacks on named individuals are growing — understand spear phishing and how it differs from mass phishing.
  • Finance teams are the highest-value target because they can move money.

How can your business defend against social engineering?

Effective defence combines regular staff awareness training, simulated phishing campaigns, strict verification procedures for financial requests, and technical controls such as email filtering and multi-factor authentication. The aim is a workforce that pauses, questions and reports — backed by technology that blocks what people miss.

No single control is enough. A blameless reporting culture, where staff feel safe flagging a suspicious email or call, is as important as any tool. Organisations with formal verification procedures for payment changes are significantly less likely to fall victim to invoice fraud.

  • Train continuously, not annually. Short, frequent sessions and live phishing simulation training beat a once-a-year slide deck.
  • Verify out of band. Confirm any payment or bank-detail change by calling a known number — never the contact details in the request.
  • Turn on MFA everywhere. Stolen credentials are far less useful behind a second factor; see our MFA setup for Microsoft 365.
  • Filter at the gateway. Strong email security and phishing protection remove most malicious messages before staff ever see them.
  • Have a plan for when it works. Even good defences fail occasionally — rehearse your incident response so a click does not become a crisis.

At AMVIA we run this for 1,200+ UK businesses on a security-first model: one accountable provider, Microsoft-certified engineers, and Microsoft Defender plus Barracuda doing the technical heavy lifting behind the training. One provider. Security-first. Microsoft-certified.

What should you do if someone falls for a social engineering attack?

Act fast and assume compromise. Reset the affected credentials immediately, revoke active sessions, and check for mailbox rules or forwarders the attacker may have set up. Tell your IT or security team and your bank if money or payment details were involved, and preserve the evidence rather than deleting it.

Speed limits the damage. A reported phishing click contained within minutes is an inconvenience; the same click discovered weeks later via an unexplained invoice is a breach. This is exactly where managed monitoring earns its keep — our incident response and 24/7 SOC work to contain an account takeover before it spreads across the business.

Frequently Asked Questions

Need More Detail?

Speak to an AMVIA expert for advice tailored to your business.