Organisations should treat social engineering as a people, process, and verification problem, not only a technology problem. Train staff to slow down unusual requests, verify identity through a second channel, and recognise urgency, secrecy, and authority cues. Pair awareness training with clear reporting paths and phishing-resistant authentication so employees can verify sensitive actions before they expose access or data.
Why This Matters for Security Teams
social engineering succeeds because attackers do not need to defeat every control, only the human decision that opens the door. Training matters most where urgency, authority, and secrecy collide: a rushed payment, a password reset, a vendor callback, or a “quick” data share. Good awareness programmes teach employees to pause and verify, while bad ones stop at annual phishing slides. Current guidance suggests pairing behaviour training with phishing-resistant authentication and formal verification steps from NIST SP 800-63 Digital Identity Guidelines and lessons from Storm-2949 Azure Breach.
Teams often overestimate how many staff will “spot the phish” on first contact, then underestimate how effective impersonation is when the message arrives through SMS, phone, collaboration tools, or a compromised supplier account. The practical risk is not only credential theft. It is also invoice fraud, session hijack, malware delivery, and authorised data disclosure after a convincing pretext. In practice, many security teams encounter the damage only after a trusted employee has already responded to the impersonation, rather than through intentional resistance testing.
How It Works in Practice
Effective training should build a repeatable decision habit: stop, verify, report. Employees need scenario-based practice that reflects how attackers actually work, including pretexts that exploit roles, calendar pressure, and business context. A strong programme teaches staff to question any request that changes payment details, resets access, shares secrets, or asks for a bypass of normal process. That is especially important because impersonation now spans email, voice, messaging apps, and AI-generated content, as reflected in CISA cyber threat advisories and Co-op Group DragonForce Breach — Scattered Spider.
Training should move beyond “spot the typo” and cover verification mechanics:
- Use a second channel for high-risk requests, such as calling a known number rather than replying to the message.
- Never trust urgency alone; freeze the action until the requester is verified.
- Escalate any request involving payment, payroll, access changes, or shared secrets.
- Report suspected impersonation quickly so defenders can contain follow-on attempts.
- Reinforce phishing-resistant MFA and approval workflows so employees have a safe way to say no.
Where possible, use short live simulations and role-specific drills for finance, HR, IT, and executives, because attackers tailor their stories to the function they target. Security teams should also align this training with identity controls and monitoring, using principles from NIST SP 800-53 Rev 5 Security and Privacy Controls and incident patterns documented in the 52 NHI Breaches Analysis. These controls tend to break down when employees are pressured to act quickly in chat-based workflows because the attacker can impersonate a trusted colleague before formal verification happens.
Common Variations and Edge Cases
Tighter verification often increases friction, requiring organisations to balance security against speed, customer service, and internal trust. That tradeoff is real, especially for teams that handle emergencies, executive requests, or revenue-sensitive transactions. Best practice is evolving here, but the direction is clear: high-risk actions should have stronger challenge steps, while routine work should stay efficient.
Some scenarios need tailored guidance. Executives and assistants are frequent targets because attackers lean on status and urgency. Remote teams are more exposed to voice and chat impersonation. Multi-party approvals help for payments, but they can fail if all approvers are pulled into the same fake narrative. Organisations should also recognise that social engineering often pairs with credential theft and session abuse, a pattern discussed in Ultimate Guide to NHIs — Key Challenges and Risks and the Anthropic report on AI-orchestrated cyber espionage. There is no universal standard for employee spotting accuracy yet, so measurement should focus on reporting rate, verification compliance, and time-to-escalate rather than shame-based quiz scores.
The strongest programmes make resistance easy: clear scripts, known callback numbers, visible reporting buttons, and managers who reward caution instead of punishing delay. That is the behaviour attackers struggle to bypass.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 | Social engineering often targets secret handling and identity misuse. |
| OWASP Agentic AI Top 10 | LLM-04 | AI-generated impersonation raises the credibility of social engineering. |
| CSA MAESTRO | MA-02 | Operational controls should reduce human error in agent-access workflows. |
| NIST AI RMF | GOVERN-2 | Training is part of governing human oversight and accountability for risky AI use. |
| NIST CSF 2.0 | PR.AT-1 | Awareness and training directly support user preparedness against impersonation. |
Train staff to verify before sharing secrets and route all high-risk requests through approved checks.
Related resources from NHI Mgmt Group
- Why do social engineering attacks still succeed in well-defended organisations?
- What breaks when organisations rely mainly on detection instead of prevention for social engineering and impersonation attacks?
- What breaks when organisations rely only on endpoint controls to stop browser-based social engineering attacks?
- How should organisations assess social media platform risk before using them for election-related communications?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org