TL;DR: Attackers are evolving tactics faster than many traditional defenses can absorb, while social engineering remains a dominant entry method and defender lesson source, according to Abnormal AI’s Innovate 2025 webinar with Sherrod DeGrippo. The practical takeaway is that security programmes must treat human decision paths, not just technical controls, as part of the attack surface.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “Hackers vs. Defenders: The Evolving Threat Landscape and What’s Next in 2025”.
Key questions
Q: How should security teams reduce social engineering risk in identity recovery workflows?
A: They should treat recovery as a privileged control path, not a customer service process.
Q: Why do social engineering attacks still defeat mature IAM programmes?
A: Because many programmes secure the login event but leave recovery, escalation, and exception handling under-governed.
Practitioner guidance
- Harden high-risk human workflows Require step-up verification for password resets, privileged approvals, and account recovery so that a persuasive request cannot bypass identity checks.
- Review delegated decision points Map which teams can approve exceptions, override controls, or validate identity claims, then reduce ambiguity in those escalation paths.
- Rework awareness around attacker tactics Use current social engineering scenarios in simulations and briefings so training reflects how attackers actually change pretexts and delivery methods.
Bottom line: Social engineering remains effective because it targets trust, urgency, and routine decision-making rather than only system weaknesses.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Social engineering is no longer a perimeter problem, it is an identity governance problem. Once attackers can shape human decisions, the effective attack surface includes approval paths, recovery processes, and exception handling. That shifts the control question from simple awareness to governance over who can authorise what, when, and under which verification conditions.
A question worth separating out:
Q: How can organisations verify identity when the request itself may be malicious?
A: Use out-of-band confirmation, stronger authentication for sensitive actions, and tightly scoped approval authority for resets or privilege changes. The goal is to make the request harder to trust than the channel it arrived through.
👉 Read our full editorial: Social engineering outpaces traditional defenses in threat strategy