Security teams should assume that fast-moving public events will create attention spikes, uncertainty, and behavior changes that attackers can exploit. The right response is to tighten user awareness, verify urgent requests through trusted channels, and increase monitoring of messages that reference policy changes, benefits, remote work, or health updates. Rapidly changing themes often outperform generic lures because they feel timely and legitimate.
Why major public events change the social engineering landscape
Public events create a predictable shift in attacker tradecraft: people are overloaded, timelines compress, and legitimate policy changes are happening fast enough that unusual requests can feel normal. That makes the environment ideal for impersonation, urgency cues, and “exception handling” requests that bypass careful verification. Security teams should treat the event itself as part of the threat surface, not just the background.
During a pandemic or similar disruption, the strongest lures usually borrow real operational themes, such as health notices, travel restrictions, benefits, policy changes, remote access, or payroll issues. Those themes work because they reduce suspicion and encourage immediate action. A useful control strategy is to make trusted communication patterns more explicit before the crisis peaks, so people know where legitimate updates will come from and how they will be announced.
social engineering also becomes more effective when internal processes are changing at the same time as external messaging. When teams are adjusting work arrangements, approvals, or support workflows, attackers can exploit confusion around “who can approve what” and “which channel is authoritative.” That is why awareness, process clarity, and verification discipline need to move together rather than being treated as separate tasks.
What the safest response looks like in practice
The best response is to harden the human decision path, not just the technical one. Teams should pre-brief staff on likely lure themes, require independent confirmation for high-impact requests, and make it easy to verify urgent messages through known internal channels. For sensitive workflows, the goal is to slow down the attacker’s favorite shortcut: urgency without confirmation.
That means reinforcing callback verification, using known directory or portal contact points instead of replying to an inbound message, and tightening approvals around payment, access, policy exceptions, and account recovery. When the business is under time pressure, those controls should be simpler to follow, not more complex. If a control is hard to use during a crisis, people will route around it.
Monitoring should also be adjusted to the event context. Security teams should look for spikes in messages that imitate official guidance, request credential resets, ask for fast exceptions, or redirect users to external forms and documents. A targeted alerting strategy is more useful than generic phishing noise because it focuses review on the stories attackers are most likely to tell during the event.
What tends to fail when the event is moving too fast
Most failures come from overtrust in urgency, fragmented communication, and exception creep. When leadership, HR, operations, and IT each send separate updates, attackers gain room to impersonate one of them convincingly. The more a situation feels fluid, the more valuable it is to preserve a single source of truth and a narrow set of approved channels.
Another common failure is relying on awareness training alone. Training helps, but during a major event the attacker is counting on fatigue, anxiety, and distraction. Controls that depend entirely on the user spotting a fake are weaker than controls that also verify sender identity, require step-up checks, or remove easy paths for password reset and account recovery abuse.
Security teams should also watch for secondary effects, such as staff forwarding suspicious notices to peers, sharing screenshots, or trying to help each other through unofficial workarounds. Those behaviors are understandable, but they can spread malicious links and confuse incident triage. Clear reporting instructions and quick internal validation matter as much as the original warning.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8, NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-14 — Security Awareness and Skills Training | Event-themed social engineering relies on human error and urgency. |
| Recommendation — Tailor awareness training to the event lures staff are likely to see. | ||
| NIST SP 800-53 Rev 5 | AT-2 — Awareness Training | The question centers on reducing susceptibility to social engineering. |
| IA-5 — Authenticator Management | Urgent scams often target password resets, account recovery, and credential abuse. | |
| Recommendation — Update awareness content with current event-based phishing and impersonation themes. Strengthen reset and recovery handling to resist social engineering abuse. | ||
| NIST CSF 2.0 | PR.AT-01 — Awareness and Training | The answer depends on user readiness to recognize and report event-driven lures. |
| Recommendation — Refresh training on the specific urgency and impersonation patterns tied to the event. | ||
| ISO/IEC 27001:2022 | A.6.3 — Information security awareness, education and training | Reducing social engineering risk depends on timely staff awareness and behavior guidance. |
| Recommendation — Deliver targeted awareness on event-specific scams and response steps. | ||
Practitioner Guidance
What to prioritise: Focus first on the requests that can create immediate business or identity impact, such as password resets, payment changes, remote access exceptions, and policy-related approvals. Those are the routes attackers most often exploit when urgency is high.
What to verify: Confirm that every “urgent” communication has a known origin path, an approved channel, and a second-factor verification step for high-risk actions. If any one of those is missing, treat the request as untrusted until it is independently checked.
Common mistake: Sending a one-time awareness reminder and assuming the problem is solved. During a crisis, the control that matters is repeatable verification under pressure, not generic caution.
What good looks like: Staff know where legitimate updates will appear, supervisors know which requests require callback confirmation, and monitoring can distinguish ordinary messaging volume from a surge in event-themed lures.
Practitioner takeaway: The event is not just the subject of the scam, it is the condition that makes the scam believable, so the most effective defense is to narrow trusted paths, make verification routine, and remove ambiguity before attackers benefit from it.
Related resources from NHI Mgmt Group
- How should security teams reduce the risk of GenAI amplifying misinformation during major public events?
- How should security teams reduce the risk of vaccine-themed phishing and BEC campaigns during fast-moving public events?
- How should security teams reduce social engineering risk in identity recovery workflows?
- How should security teams reduce Microsoft Teams social engineering risk?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org