Back to research
Literature ReviewBehavioral ResearchResearch Writing

Understanding Social Engineering

Overview

Some of the most effective security attacks don't begin by breaking into a system. They begin by convincing a person to do something.

A message looks urgent. A caller sounds authoritative. An email appears to come from someone familiar. The technology may be sophisticated, but the attack ultimately succeeds by exploiting human behavior.

This research explored the psychology behind social engineering and why techniques such as phishing, vishing, and impersonation continue to work even as people become more aware of online security risks.

The Question

Why are people vulnerable to social engineering, and what can be done to reduce that vulnerability?

I wanted to look beyond the idea that people simply need to "be more careful" and understand the psychological and situational factors that make manipulation effective.

Research Approach

I reviewed existing research on social engineering, with particular attention to phishing, vishing, impersonation, psychological manipulation, digital literacy, and prevention strategies.

I then synthesized findings across the literature to understand both why these attacks succeed and where existing approaches to prevention fall short.

What I Learned

Social engineering takes advantage of normal human behavior

We trust familiar people. We respond to authority. We react quickly when something feels urgent. We rely on mental shortcuts when we're busy or overwhelmed. Attackers deliberately create situations that take advantage of those tendencies. That makes social engineering more than a technical security problem — it's also a problem of psychology, communication, context, and design.

Awareness doesn't eliminate vulnerability

Security education and warnings are important, but knowing about a threat doesn't guarantee that someone will recognize it at the right moment. People make decisions while distracted, rushed, uncertain, or under pressure. Someone may understand phishing perfectly well in theory and still respond differently when a convincing message appears to come from their bank, employer, or someone they know.

The burden can't fall entirely on the user

Expecting people to correctly identify every sophisticated attempt at manipulation isn't realistic. The research suggests that prevention works better as a layered system, combining human awareness with safeguards that reduce the consequences of inevitable mistakes.

Opportunities for Better Protection

Several approaches emerged from the research:

No single approach solves the problem. Stronger protection comes from combining human understanding with thoughtful technical safeguards.

What I Took Away

The biggest lesson from this research was that blaming users for making mistakes doesn't solve the underlying problem.

People don't interact with technology under perfect conditions. They're busy, distracted, emotional, trusting, or simply trying to get something done.

Designing safer systems means acknowledging those realities and creating safeguards that support human decision-making rather than expecting people to behave perfectly.