MODULE 9 โ Human Factors & Social Engineering
Learning Objectives
Learners will:
- Explain psychological principles behind social engineering.
- Identify phishing, pretexting, baiting, and impersonation attacks.
- Evaluate human vulnerabilities in organisations.
- Design awareness and training programs.
Module Overview
Humans remain the most targetedโand often the weakestโelement in cybersecurity. This module examines manipulation tactics, behavioural vulnerabilities, and organisational countermeasures.
1. Social Engineering Tactics
1.1 Phishing
- Email deception
- Clone phishing
- Spear phishing
1.2 Pretexting
Crafting believable but false narratives.
1.3 Baiting
Enticements leading to malware installation or data leakage.
1.4 Impersonation
Physical or digital identity fraud.
2. Psychological Drivers
- Reciprocity
- Authority bias
- Scarcity
- Urgency
- Trust heuristics
Attackers exploit predictable human behaviours.
3. Organisational Vulnerabilities
- Poor training
- Lack of verification procedures
- Overburdened staff
- Weak reporting culture
4. Countermeasures
- Awareness training
- Simulated phishing campaigns
- Multi-layer verification
- Policy enforcement
Summary
Technology cannot fully mitigate human risk; culture and education play essential roles.
