MODULE 9 โ€” Human Factors & Social Engineering

Learning Objectives

Learners will:

  1. Explain psychological principles behind social engineering.
  2. Identify phishing, pretexting, baiting, and impersonation attacks.
  3. Evaluate human vulnerabilities in organisations.
  4. Design awareness and training programs.

Module Overview

Humans remain the most targetedโ€”and often the weakestโ€”element in cybersecurity. This module examines manipulation tactics, behavioural vulnerabilities, and organisational countermeasures.


1. Social Engineering Tactics

1.1 Phishing

  • Email deception
  • Clone phishing
  • Spear phishing

1.2 Pretexting

Crafting believable but false narratives.

1.3 Baiting

Enticements leading to malware installation or data leakage.

1.4 Impersonation

Physical or digital identity fraud.


2. Psychological Drivers

  • Reciprocity
  • Authority bias
  • Scarcity
  • Urgency
  • Trust heuristics

Attackers exploit predictable human behaviours.


3. Organisational Vulnerabilities

  • Poor training
  • Lack of verification procedures
  • Overburdened staff
  • Weak reporting culture

4. Countermeasures

  • Awareness training
  • Simulated phishing campaigns
  • Multi-layer verification
  • Policy enforcement

Summary

Technology cannot fully mitigate human risk; culture and education play essential roles.

Pages: 1 2 3 4 5 6 7 8 9 10