Social engineering training for employees, starting with the phone call.
Not every attack has a link. Social engineering is a person talking their way past your team, by phone or in person, posing as IT, a vendor, or a new hire and asking for a reset, a code, or a little access.
What social engineering is and why it works
Social engineering is the use of persuasion, pretending, and pressure to get people to give up information or access. Attackers pose as help desk staff, vendors, coworkers, or officials, and build a believable story, called a pretext, to make an unusual request feel routine.
It works because most people want to be helpful and because the attacker controls the conversation. A confident voice, a few real details, and a sense of urgency can make a risky request feel reasonable. There is no malware involved, so the defense is a habit: verify through a channel you trust.
Warning signs of a social engineering attempt
Real callers and visitors sometimes do a few of these things too. The point is to notice the pattern and verify.
- A caller who creates urgencyThere is a problem that must be fixed right now, and you are the only one who can help.
- A request for codes, passwords, or remote accessA legitimate help desk should not need your password or a one-time code.
- Borrowed authority or familiar detailsThe caller names a manager, a system, or a recent event to sound credible. Real details do not prove real identity.
- Reluctance to let you verifyThe caller discourages you from hanging up, calling back, or checking with a colleague.
- A request to bypass the normal processSkipping a ticket, an approval, or an identity check just this once is a classic move.
What to do when a call or visit feels off
You can be polite and still say no. A real caller will accept a call back.
- Slow the conversation downYou can say you will call back. A real caller will accept that.
- Do not share codes or passwordsNot with a caller, a chat message, or a visitor, whatever reason they give.
- Hang up and call back on a known numberUse a number from your directory or the company website, not one the caller gave you.
- Check with a colleague or managerA second opinion costs a minute and can prevent a serious loss.
- Report itTell your IT or security contact what was asked and how the call went, even if you did not comply.
Social engineering training for employees that sticks
These AwarenessCORE modules are self-paced and each ends with a graded assessment.
A dedicated module on this topic is coming soon. See the Coming soon card.
Questions about social engineering training for employees
What is social engineering?
Social engineering is the manipulation of people, rather than systems, to obtain information or access. It uses trust, urgency, and believable stories, and it can happen by phone, email, text, chat, or in person.
What is vishing?
Vishing is voice phishing: a phone call in which an attacker pretends to be someone trusted, such as IT support or a bank, to get you to share information or take an action.
What is pretexting?
Pretexting is inventing a believable scenario to gain trust and extract information. Examples include a caller posing as IT to run an update, or a visitor claiming to be a contractor.
Why do attackers ask for one-time codes?
A one-time code can complete a login or a password reset. If an attacker already has a password, the code is the last step, so they try to talk the account holder into reading it out.
How can a team prepare for social engineering?
Training helps people recognize the tactics and gives them a simple response: slow down, verify through a trusted channel, and report. Clear policies, such as never sharing codes, make that response easier to follow.
Know the signs beyond social engineering
A quick reference: the first warning sign from each of the ten threat pages. Each chip opens the full list and what to do.
Teach your team to hang up and verify
Tell us your team size and we will suggest which modules fit. A real person replies, usually within one business day.
- A real person, not a bot, within one business day
- Straight answer on cost and what fits your team size
- No pressure to buy
Got it. We will be in touch.
Someone from AwarenessCORE will reach out within one business day.
What every module includes
- A graded knowledge check with a pass mark
- A completion certificate when you pass
- Access that does not expire
- One payment per module, no subscription
Built by TheBRHub, an IT and email security company in Carlsbad, California.