TL;DR: Social engineering is increasingly a business event rather than a narrow security incident, with costs spreading into operations, legal exposure, insurance friction, and reputation, according to Trusona. The core lesson is that identity verification and access governance now sit on the same risk path as revenue continuity and board accountability.
NHIMG editorial — based on content published by Trusona: The Business Cost of Social Engineering Goes Far Beyond IT
By the numbers:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities.
Questions worth separating out
Q: How should security teams reduce social engineering risk in identity recovery workflows?
A: They should treat recovery as a privileged control path, not a customer service process.
Q: Why do social engineering incidents create costs beyond the security team?
A: Because they trigger a chain of business effects after the initial access event.
Q: What do organisations get wrong about social engineering defence?
A: They often treat it as an awareness problem instead of a workflow problem.
Practitioner guidance
- Harden identity recovery workflows Require stronger verification for password resets, account recovery, and exception approvals, especially where attackers commonly pressure support teams into bypassing policy.
- Separate urgency from authority Design escalation paths so that a time-sensitive request never overrides dual approval, callback verification, or out-of-band confirmation.
- Review privileged support access Limit which service desk and operations staff can trigger privileged changes, and log every manual override with a reviewable justification.
What's in the full article
Trusona's full blog covers the operational detail this post intentionally leaves for the source:
- How social engineering incidents create response, legal, and communications costs in practice
- Why insurance carriers scrutinise control evidence after manipulated-access incidents
- How board accountability changes when support workflows become part of the attack path
- Why prevention delivers the highest return when identity workflows are the target
👉 Read Trusona's analysis of the business cost of social engineering →
Social engineering risk: what it means for business continuity and identity?
Explore further
Social engineering is an identity governance failure before it is a security incident. The article is right to frame the cost as a business issue, but the deeper point is that the organisation’s identity assumptions were already weak. If a person can be manipulated into overriding verification, the control environment has treated trust as a process shortcut rather than a risk decision. Practitioners should read this as an identity governance problem that spans support, finance, and privileged workflows.
A few things that frame the scale:
- The average organisation believes more than 1 in 5 of their non-human identities are insufficiently secured, according to the 2024 ESG Report: Managing Non-Human Identities.
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to the 2024 ESG Report: Managing Non-Human Identities.
A question worth separating out:
Q: Who is accountable when social engineering defeats identity controls?
A: Accountability sits with the teams that own authentication, support workflows, telecom dependencies, and privileged access, not only with end users. If a reset, SIM swap, or device rebind can grant access without strong verification, the governance gap is structural. Organisations should map those responsibilities before an incident forces the issue.
👉 Read our full editorial: Social engineering costs now extend well beyond IT operations