Because employees often relax their guard when routines feel familiar, and many assume physical security is someone else’s responsibility. That creates openings for impersonation, tailgating, fake deliveries, and casual access to desks or devices. A red team can demonstrate how trust, convenience, and inconsistent verification combine to make the office easier to penetrate than leaders expect.
Why shared offices make social engineering easier to pull off
Shared workspaces reduce the friction that normally helps employees notice something is off. In a busy office, people see unfamiliar faces, hold doors, accept deliveries, and overhear partial conversations all day. That normalisation of strangers lowers the threshold for impersonation and makes small trust violations feel routine instead of suspicious.
Which office behaviours attackers exploit most
The easiest paths are the ones that look harmless: tailgating behind a badge holder, posing as IT or facilities, leaving a “delivery” at reception, or asking a nearby employee to unlock a workstation. These tactics work because they borrow credibility from the environment itself. The attacker does not need deep technical access if they can get a foothold through courtesy, haste, or confusion.
Shared spaces also blur responsibility. People assume reception, security, or building management will challenge strangers, while those teams may assume employees already know the visitor. That gap creates a verification failure, especially when staff are juggling meetings, hot-desking, phone calls, and hybrid schedules.
For a broader view of how employee trust and recovery paths become attack surfaces, Workforce Identity Security Guide explains how routine access habits can be turned into account compromise. Account Recovery and Help Desk Security Guide shows why casual verification shortcuts often become the weakest point in the chain.
Why return-to-office changes the social engineering risk profile
Return-to-office raises exposure because it reintroduces physical proximity, unscripted interaction, and inconsistent routines. Hybrid environments are especially useful to attackers because employees may not know everyone on-site, may not know who is authorised to request access, and may be less practiced at challenging unusual behaviour in person.
The risk is not just that people are present together again. It is that employees often become less vigilant after a period of remote work, where access cues were mostly digital and more controlled. In the office, verification becomes social, and social verification is easier to manipulate through confidence, urgency, and familiarity.
Identity checks also matter at the office edge. If a request could expose an account, a device, or a reset path, treat it as an access decision rather than a courtesy. Identity Provider and SSO Security Guide is useful when office-based trust is used to reach digital access, and Deepfakes, Social Engineering and AI Impersonation Guide is relevant where voice or video impersonation is used to backstop a physical pretext.
Risk and Threat Considerations
Shared workspaces increase the chance that a small lapse becomes an entry point. Attackers exploit the fact that employees are conditioned to be helpful, and that office routines often reward speed over verification. Once an impostor gets past the first person who fails to challenge them, the rest of the environment often follows the same assumption.
Failure mechanism: The defender’s control assumption is broken when trust is delegated to appearance, context, or someone else’s job function instead of an explicit check. That lets impersonation, tailgating, device access, or delivery-based pretexts reach desks, screens, or credentials.
Impact: The result can be account takeover, device compromise, theft of visible information, or a broader foothold inside the organisation. In practice, the office becomes an access path into both physical and digital systems, not just a place where work happens.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack surface, CIS Controls v8, NIST SP 800-53 Rev 5 and NIST SP 800-63 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-5 — Account Management | Shared-workspace social engineering often targets account access and resets. |
| Recommendation — Tighten account handling and verification around office-based access requests. | ||
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Office pretexts often aim to reach internal user access paths. |
| IA-5 — Authenticator Management | Social engineering frequently targets password resets and credential recovery. | |
| AC-6 — Least Privilege | Limits the damage if an impostor reaches a workstation or support path. | |
| Recommendation — Require strong user authentication before granting access or making changes. Harden authenticator issuance, reset, and recovery procedures. Restrict access so office-side compromise has minimal blast radius. | ||
| NIST SP 800-63 | Digital Identity Guidelines | Phishing-resistant authentication is relevant when office trust leads to account compromise. |
| Recommendation — Use phishing-resistant authenticators and stronger identity proofing for sensitive access. | ||
| MITRE ATT&CK | T1566 — Phishing | The core social engineering mechanics align with pretexting and impersonation. |
| Recommendation — Map office pretexts to phishing-style tactics and hunt for related access attempts. | ||
| ISO/IEC 27001:2022 | A.5.16 — Identity management | Office-based impersonation is fundamentally an identity and verification problem. |
| A.5.17 — Authentication information | Office social engineering often seeks secrets, resets, or recovery paths. | |
| Recommendation — Treat on-site access requests as identity events that require explicit verification. Protect recovery information and reset paths from casual disclosure or misuse. | ||
Practitioner Guidance
What to prioritise: Focus first on the entry points that mix human courtesy with access, especially reception, visitor handling, badge exceptions, and desk-side support. Those are the moments where a friendly request can turn into unauthorised access.
What to verify: Employees should be able to name who is allowed to request access, what proof is required, and when a request must be escalated. If the answer depends on “it looks right” or “someone in the office would know,” the control is too weak.
What good looks like: Staff pause, challenge, and escalate inconsistencies without embarrassment, and building teams back that behaviour instead of treating it as overcautious. The office is safer when verification is normalised as part of professionalism, not framed as mistrust.
Practitioner takeaway: Return-to-office risk rises when convenience is allowed to outrank verification, so the key control is not more suspicion, it is making challenge and confirmation feel routine in shared spaces.
Related resources from NHI Mgmt Group
- Why do shared social media accounts increase takeover risk?
- Why do remote workers and distributed teams increase social engineering risk?
- Why do GenAI-driven social engineering attacks increase account takeover risk?
- Why do long-lived privileges and shared secrets increase risk in modern engineering workflows?