Your biggest security risk isn't your firewall — it's your people. Social engineering exploits human trust, and annual training won't fix it. Regular simulated phishing, blame-free reporting, and a culture of scepticism will.
The firewall is airtight. The endpoint protection is enterprise-grade. The passwords are long, random, and stored in a vault. And then someone in accounts clicks a link in an email that looks, almost perfectly, like it came from the CEO.
Within minutes, an attacker has a foothold in your network. Within hours, they've mapped your systems. Within days, you're dealing with a breach.
This scenario isn't hypothetical. It plays out in organisations of every size, every sector, every week. The technology held. The people didn't — and that's not a criticism. It's a design flaw in how most organisations approach security.
What Social Engineering Actually Looks Like
Social engineering is the art of manipulating people into doing things that serve an attacker's goals. The term sounds clinical, but in practice it's surprisingly human.
The most common forms:
- Phishing — emails crafted to look legitimate, prompting recipients to click a link, open an attachment, or hand over credentials. Modern phishing emails don't look like the broken-English scam attempts of fifteen years ago. They're personalised, grammatically perfect, and often reference real internal events or colleagues.
- Spear phishing — phishing targeted at a specific individual, using information gathered from LinkedIn, company websites, or prior reconnaissance. A message that addresses you by name, references your role, and appears to come from your CFO asking you to approve an urgent wire transfer is extremely hard to dismiss as spam.
- Vishing — the voice equivalent. Attackers call employees posing as IT support, vendors, or executives and talk them into resetting credentials or granting remote access. The pressure of a real-time conversation, combined with an authoritative tone, bypasses critical thinking in ways that a written email sometimes doesn't.
- Pretexting — constructing a plausible backstory to extract information. An attacker might pose as a new employee needing help with system access, or a supplier following up on an invoice. The goal is to appear legitimate enough that normal scepticism doesn't kick in.
- Physical social engineering — tailgating through secure doors, leaving USB drives in car parks, or posing as a courier. Less common in remote-first organisations, but still devastatingly effective when it happens.
Why Training Usually Fails
Most organisations do run security awareness training. Most of that training doesn't work — or at least, doesn't work well enough.
The typical approach: an annual online module, a series of slides, a quiz at the end that everyone passes by clicking through quickly, and a completion certificate filed away. The box is ticked. The behaviour hasn't changed.
The problem isn't the content. It's the format. Human beings don't learn to recognise threats by reading about them once a year. We learn by encountering them, failing, and being corrected in real time.
This is why simulated phishing campaigns — where your own security team or a third party sends fake phishing emails to employees — are so much more effective than passive training. When someone clicks a simulated phishing link and sees a page that explains what just happened and why, they remember it. When they receive a follow-up explaining what the red flags were, they start looking for those flags.
What Effective Security Culture Actually Requires
Building a workforce that's genuinely resistant to social engineering is less about training and more about culture. That's a bigger undertaking, but it's achievable if you approach it deliberately.
Report, don't hide. Employees who click suspicious links often don't report it because they're embarrassed or afraid of consequences. If your culture punishes mistakes, you won't hear about incidents until they've escalated. Creating a blame-free reporting environment — where the priority is catching things early, not assigning fault — is foundational.
Make scepticism normal. Employees should feel empowered to question unusual requests, even from apparent authority figures. An organisation where a finance team member can comfortably push back on a "CEO" asking for an urgent wire transfer is an organisation that has done this right. That requires explicit permission from leadership — not just a policy document, but demonstrated behaviour from the top.
Simulate regularly. One phishing simulation per year isn't enough. Quarterly campaigns, varied in format and complexity, keep people sharp. Those who click should receive targeted, constructive follow-up. Those who report should be recognised.
Make it relevant. Security training that references abstract threats is easily forgotten. Training that references the actual systems your people use, the actual communication patterns in your organisation, and the actual scenarios relevant to your industry lands differently. A finance team needs to understand invoice fraud. An HR team needs to understand what a fake job application that's actually a document exploit looks like.
Measure the right things. Click rates on simulated phishing campaigns are a useful metric, but they're not the whole picture. Track report rates — the proportion of employees who flag suspicious emails rather than just ignoring or clicking them. That number tells you whether your culture is working.
The Executive Dimension
Senior leaders are disproportionately targeted. They have authority over financial decisions and data access, and they're often less supervised than junior employees. They're also frequently the hardest to train — they're busy, they receive a lot of email, and they can be reluctant to sit through security awareness modules designed for the general workforce.
This is where dedicated executive briefings matter. Not a watered-down version of the standard training, but a focused session on the specific threats targeting people at their level: whaling attacks (highly targeted phishing aimed at executives), business email compromise, credential theft through personal accounts that share passwords with work systems.
The goal isn't to make executives paranoid. It's to make them appropriately sceptical — and to ensure they understand that their cooperation with security processes (not clicking round MFA prompts, not using personal email for work, not approving financial transfers without verbal confirmation) sets the tone for the rest of the organisation.
Where to Start
- If you're not running regular simulated phishing campaigns, start there. It's the single highest-return investment in human-layer security.
- If you are running them but the click rate hasn't meaningfully improved over the past year, the problem is probably in the follow-up — what happens after someone clicks, and whether it's creating genuine learning or just mild embarrassment.
- If your click rate is low but your report rate is also low, employees are recognising phishing but not reporting it. That's a culture problem, and it means real incidents are probably also going unreported.
Security technology has a ceiling. The human layer doesn't — it can always be improved. Organisations that treat security awareness as an ongoing programme rather than an annual compliance exercise are consistently harder to breach.
Calibre Security Group works with organisations to design and deliver security awareness programs that go beyond checkbox compliance — including simulated phishing campaigns, executive briefings, and measurable culture change. Get in touch today to find out where your human layer stands.
