• Products
  • Services
  • Compliance
  • Resources
  • Partners
  • Book a Return Call
  • English
    • العربية
    • Türkçe
    • Español
    • Português
    • Tiếng việt
  • All Products
    DLP
    SearchInform Risk Monitor
    SearchInform ProfileCenter
    SearchInform FileAuditor
    SearchInform SIEM
    TimeInformer
    Cloud solutions
    Third-party integration
    All Services
    SearchInform MSS
    SearchInform for MSSP
    SearchInform solution in the cloud
    All Resources
    White Papers
    Research
    How to
    Practices and use cases
    Videos
    All Challenges
    Abnormal event detection
    Data loss prevention
    Employee with problems
    Data visibility
    Behavioral risk management
    Measuring employee morale
    Compliance
    Time tracking & employee monitoring software
    Corporate fraud
    Ransomware protection
    Data at rest discovery
    Real time monitoring
    Data encryption
    Investigation
    Employee Profiling
    Personal data protection
    All Roles
    C-level executive
    Compliance manager
    Risk manager
    Information security analyst
    Internal audit officer
    Chief Human Resources Officer
    All Industries
    Business Services
    Technology
    Education
    Healthcare
    Financial Services
    Retail
    Government
    Energy
    Insurance
    Hospitality
    Manufacturing
    Construction
    Compliance with SearchInform
    SAMA Cybersecurity Framework
    GDPR
    Personal data protection bill
    Compliance with Data Cybersecurity Controls
    Compliance with Kingdom of Saudi Arabia Personal Data Protection Law
    SearchInform Partners
    Become a Partner
    Partner login
    Events
    News
    About our company
    Blog
    Contact us
    Language:
    • English
    • العربية
    • Türkçe
    • Español
    • Português
    Follow us:
    Book a Return Call
Home — Blog — Social engineering prevention
Back
BACK TO BLOG LIST

Social engineering prevention

20.05.2020

Focus on the Real Issue

No matter how many thousands of dollars companies spend on firewalls to ensure that their systems cannot be penetrated from the outside, many businesses fail to sufficiently address the most critical issue of all. When cyber criminals target organizations, their target normally is people themselves, because they can be manipulated. 70 to 90 percent of data breaches occur as a result of social engineering. Social engineering is the practice of impersonation by cyber criminals to get employees, users, or customers to do things that they wouldn’t otherwise do and is not in their best interest. If a social engineering attempt is successful, all the money a company spends on firewalls could be in vain. 

Is Phishing a Social Engineering Attack?

Social engineering phishing is an attempt to defraud employees or users when the criminal poses as a person above him in the company or a well respected organization enjoying a high level authority and requests him to enter his login credentials or provide secret information about the company. Phishing e-mails are not the only thing to look out for. Individuals who are 35 years of age and up tend to prefer e-mail for their communication, but those who are below that age tend to prefer using their smartphones more. Scammers have adapted to this and now phishing scams come to people’s smartphones as well. Employees may be duped by a text message or e-mail claiming that they’ve won a gift card from iTunes or an impersonation of Microsoft billing staff claiming that they will experience a service interruption if they don’t send a payment for Microsoft office for the next year. 

Other Social Engineering Scams

Another step up from ordinary phishing is spear phishing. Is spear phishing a social engineering attack? You guessed it. This type of attack targets a particular individual. In this case, the attacker knows who the person is and pretends to be a particular person that person knows. He may commonly ask for his bank information or his username and password. This is how a number of celebrities have had their personal photos stolen, such as Jennifer Lawrence. Similar scams include pretexting social engineering, in which the attacker provides a clever, well thought out scenario in order to steal a person’s information. They may also pretend to be FAFSA writing to a student in order to confirm documents relative to his financial aid application process. Another one is tailgating social engineering. In the event of tailgating a person may follow an employee onto a company’s premises, posing for instance as a delivery man and asking for the employee to hold the door of a room that is authorized only for high up personnel. If he succeeds in getting into the sensitive area, he may download sensitive information onto a flash drive.

How to Prevent Phishing and Social Engineering

Just like other risks that companies have to face, one of the first decisions a company should consider is purchasing cyber insurance social engineering coverage. Because these scams are done with the employees’ consent, companies need to specifically buy an endorsement to their fidelity policy that covers these specifically, which may be subject to a sublimit. The best way to ensure employees spot a phishing e-mail is to train them not to click on malicious links, especially which do not lead to the specific domain of the company.

Many spam filters prevent these from actually reaching the inbox. The more a company stays up to date on the latest scam trends, the easier phishing detection will be.

BACK TO BLOG LIST
Letter Subscribe to get helpful articles and white papers. We discuss industry trends and give advice on how to deal with data leaks and cyber incidents.
Email
By submitting this form, you agree to our Terms of Use and acknowledge our Privacy Statement.
FileAuditor
DLP
Risk Monitor
ProfileCenter
SIEM
MSS
MSSP
Cloud Deployment
Contact
About Our Company
Our Clients
Press About Us
Press Kit
White Papers
Third-party integration
Research
Practices and use cases
Videos
Company News
Product News
Events
Blog
Compliance
Data Loss Prevention
Investigation
Data at Rest Discovery
Data Encryption
Data Visibility
Data Classification and Protection
Time Tracking and Employee
Monitoring
Corporate Fraud Mitigation
C-level executive
Risk manager
Internal audit officer
Compliance manager
Information security analyst
Chief Human Resources Officer
Business Services
Education
Financial Services
Government
Insurance
Manufacturing
Healthcare
Retail
Energy
Hospitality
Construction
SearchInform partners
Become a partner
Partner login
SearchInform products are recognized by
Gartner The Radicati Group
Follow us:
© 2026 SearchInform LTD All rights reserved.
Terms of Use
Licence
Privacy&Cookies
Cookie settings
We use cookies to analyze our website usage, make our service more effective, and improve user experience. By continuing to use our website, you are agreeing to our policy.
Ok
Settings
Cookie Policy
✖

SearchInform uses four types of cookies as described below. You can decide which categories of cookies you wish to accept to improve your experience on our website. To learn more about the cookies we use on our site, please read our Cookie Policy.

CATEGORY
DESCRIPTION
STATUS

Necessary Cookies

Always active. These cookies are essential to our website working effectively.
Cookies does not collect personal information. You can disable the cookie files record on the Internet Settings tab in your browser.

Functional Cookies

These cookies allow SearchInform to provide enhanced functionality and personalization, such as remembering the language you choose to interact with the website.

Performance Cookies

These cookies enable SearchInform to understand what information is the most valuable to you, so we can improve our services and website.

Third-party Cookies

These cookies are created by other resources to allow our website to embed content from other websites, for example, images, ads, and text.

Save Settings
✖

Please enable Functional Cookies

You have disabled the Functional Cookies.
To complete the form and get in touch with us, you need to enable Functional Cookies.
Otherwise the form cannot be sent to us.

Cookie settings
Subscribe to our newsletter and receive a bright and useful tutorial Explaining Information Security in 4 steps!

Subscribe to our newsletter and receive a bright and useful tutorial Explaining Information Security in 4 steps!

By submitting this form, you agree to our Terms of Use and acknowledge our Privacy Statement. You can unsubscribe at any time.
Subscribe to our newsletter and receive case studies in comics!

Subscribe to our newsletter and receive case studies in comics!

By submitting this form, you agree to our Terms of Use and acknowledge our Privacy Statement. You can unsubscribe at any time.