The threat of social engineering is the unexpected chink in your armour for any business. Cyber attackers are counting on you to overlook this.
What actually is social engineering?
Social engineering is the malicious manipulation of a person in order to gain unauthorised access to systems, data or information.
People can be manipulated by attackers to reveal confidential information or to break normal security procedures. While most of us are able to detect and avoid fraud when in a normal state of mind, social engineering hackers are experts at using a fight or flight response to stop us thinking normally. One case of human error could lead to devastating leaks of information or compromise your entire IT system, severely damaging your business and its reputation.
Am I safe if I have a good security system?
An iron clad security system may be jeopardised by unexpected human vulnerabilities when you are underprepared for such types of cyber attack.
Regardless of your antivirus software, firewalls or other threat detection systems, every company carries the risk of compromising their security via social engineering. Human vulnerabilities are the largest areas of risk, especially where you have robust security in place.
Phishing emails:
These emails are seemingly company emails, sent via spoof accounts which appear credible at first glance. Attackers may take care to research the online presence of employees so as to gather information on the company and its staff, sometimes following recent developments (for instance, new projects you publish about on social media). This allows them to feign knowledge, impersonating internal correspondence, allowing someone to be under the impression that this person works within the company/industry. By building this position of trust, hackers make it easier for your staff to then place themselves in a compromised position where they may divulge confidential information or break security procedures. Most cyber attacks start with phishing emails.
The National Cyber Security Centre’s tell tale signs of phishing are set out below.


Three common scenarios illustrating how these attacks are structured:
Credential Harvesting (Urgent IT Account Reset) – This attack targets employees en masse to steal login credentials, often providing initial access into an organisation’s network.These hacking campaigns can target millions of accounts at once, cashing in on one or two unlucky victims.
| Step 1: Domain Spoofing & Setup | The attacker registers a domain that closely resembles the target organisation’s legitimate domain (typosquatting, such as update-company.com instead of company.com) and sets up a fake single login portal. |
| Step 2: The Lure | The attacker sends a broadcast email disguised as an urgent alert from “IT Support,” claiming that mandatory system maintenance requires an immediate password update to avoid account suspension. |
| Step 3: Redirection to Fake Portal | The email includes a button linking to a spoofed SSO login page. To the recipient, the page visually mirrors their company branding to give false assurance. |
| Step 4: Data Capture & Session Hijacking | When the victim enters their username and password, the fake portal captures the credentials. If Multi-Factor Authentication (MFA) is enabled, it may simultaneously prompt and capture the one-time passcode to bypass authentication checks. The portal would redirect to the official page, so while the account has been compromised the recipient is none the wiser. |
Business Email Compromise (Executive Impersonation) – This attack uses authority bias to bypass typical psychological checks to get people to fall victim to things like invoice fraud or gift-card fraud. The use of an ‘authority figure’ makes the victim more conducive to urgent or non-standard work, this is typically effective against companies with hierarchical structures and organisation of work.
| Step 1: Target Mapping & Reconnaissance | The attacker researches the company via public resources like LinkedIn to identify low-to-mid-level employees in the finance or accounts payable departments, alongside the names of top executives or their line manager. |
| Step 2: Account Compromise or Display Name Spoofing | The attacker either gains access to an executive’s real email account via a prior breach, or creates an external email address configured with their display name. |
| Step 3: High-Pressure Direct Request | The attacker emails the targeted finance employee, posing as the CEO or MD during a busy period. The message demands an immediate, confidential BACS for a time-sensitive payment or a surprise gift, instructing not to discuss it via normal channels. |
| Step 4: Exploitation of Trust | Accepting the authority and urgency, the employee processes the transaction directly without following relevant checks or due process. This can be incredibly stressful to the victim, and can cost a business most of its cash if the attacker is successful. |
Supply Chain Invoice Fraud (Malicious Attachment) – This attack leverages existing vendor-client relationships to trick users into executing malicious code or updating payment details.
| Step 1: Supply Chain Identification | The attacker identifies a legitimate vendor used by the target company, often through public partner listings, press releases, or social media posts. |
| Step 2: Delivery of the Spoofed Notice | The attacker sends an email appearing to come from the vendor’s accounts team. The message claims an invoice is overdue or that banking details have changed, attaching a file labeled Past_Due_Invoice.pdf or Invoice_Update.docm. |
| Step 3: Exploiting Operational Routines | Because processing invoices from the supplier is routine, the recipient is primed to open the file to verify the details. |
| Step 4: Payload Execution or Fraudulent Update | Opening the document triggers macro code or embedded scripts that download malware onto the machine, or leads the employee to update supplier account details to an attacker-controlled account. This way an attacker can defraud both parties, or leverage weak security in the supply chain. |
Multilayer Defence:
Suzaku believes in employing defence-in-depth to prevent attacks via social engineering. With a focus on clear, plain-language security policies and security awareness training, we ensure that your staff know when to ‘stop, drop and roll’ instead of falling victim to professional fraudsters who can be very convincing.
This prevents your staff circumventing the technical security systems by inadvertently transferring funds, intellectual property, or customer data to an unauthorised third-party (the hacker).

This means that in the worst case where an attacker is successful in penetrating one layer of defence, they are not able to move deeper to access more systems. Their negative impact can be controlled and limited, allowing for remedial procedures to take place before any major loss for your business.
While defence from attack is prioritised, there must be a strategy in place for recognising when attacks are successful and how to reduce ‘blast-radius’ at pace. Social engineering is about human security, and no matter how robust a security system is there is little point if the proverbial thief can be let in through the front-door by your team.
Joiner/Mover/Leaver Processes:
A foundational aspect of any security policy involves access controls. Setting up accounts, access approval and password changes are small but essential protections for your business.
This is why Suzaku are available every step of the way when employees transition in and out of roles, whether that be internally or externally. All employees will have clearly defined roles and access to only the systems and information necessary for them to carry out their jobs.
This Role-Based Access Control lets standardise and automate the entire JML process. Internal transitions within the company, movers, are the highest carriers of risk as different roles carry different permissions and access.
Such ‘grandfather permissions’ might mean that sensitive information is still accessible by staff who simply should not have that visibility after moving to another role.
Following Cyber Essentials requirements during these transitions eliminates risk and supports you during audit. You will be able to rest assured that your data and systems will be safe.

Conclusions
Social engineering is a major risk to any business, and the more secure your technical systems are the greater vulnerability social engineering poses. For best-practice please see the National Cyber Security Centre’s Guidance for high-risk individuals on protecting your accounts and devices below.

