Join our Newsletter — 33% off our NHI Course
Home› FAQ› Authentication, Authorisation & Trust› What should employees do before accepting a connection…
Authentication, Authorisation & Trust

What should employees do before accepting a connection request or replying to a message on social media?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 27, 2026 Domain: Authentication, Authorisation & Trust

Employees should verify the profile carefully, look for inconsistencies, and avoid assuming a familiar name means a trusted identity. They should check mutual connections, job history, and the realism of the request before sharing information or clicking anything. If the message creates urgency, flattery, or pressure, that is a warning sign. A cautious pause can prevent attackers from using social rapport to gain access to information or accounts.

How to sanity-check a social media connection request

A connection request is not trustworthy because it uses a real-looking name, logo, or profile photo. The practical test is whether the account’s history, relationships, and behaviour fit the person it claims to be. In social engineering cases, the attacker’s goal is often to lower your caution just enough to get a reply, a click, or a share.

Look for profile age, incomplete job history, mismatched employment details, unusual network overlap, and recent activity that looks copied or generic. A legitimate contact usually has a coherent digital footprint, while a fake or hijacked account often shows gaps, recycled wording, or a network that does not match the claimed role.

When the request comes through a workplace or customer context, treat the profile check as an authentication question, not a courtesy check. The same discipline that helps with digital identity verification applies here: you are validating whether the apparent identity is credible enough to trust with interaction.

What a risky message is trying to trigger

Social platform messages are often designed to provoke speed instead of judgment. Urgency, flattery, authority, friendliness, or a request to move the conversation elsewhere are classic pressure tactics because they reduce the chance that the target will verify who is behind the account.

That matters because the first successful reply can become the entry point for phishing, credential theft, invoice fraud, account recovery abuse, or requests for internal information. Even if the message does not contain a link, the conversation itself can be the mechanism that builds trust and creates a second-stage opportunity.

Adversaries often rely on believable social context rather than technical exploit chains. That makes this a behaviour and trust problem as much as a content problem, which is why you should pause whenever the message asks for anything that would be sensitive if it came from a stranger, even a familiar-looking one.

The broader pattern is reflected in attack-mapping work such as the MITRE ATT&CK Enterprise Matrix, where credential access, social engineering, and follow-on compromise are treated as linked phases rather than isolated events.

What to do before you reply

Before responding, verify the person through a second channel if the message is unexpected or asks for anything unusual. If the account claims to be a colleague, customer, recruiter, vendor, or executive, compare the profile with other records you already trust and look for something independently verifiable, such as a known email address, internal directory entry, or prior relationship.

  • Check whether mutual connections are real and relevant, not just numerous.
  • Review the timeline of the profile, not only the current name and photo.
  • Read the message for pressure signals, such as urgency, secrecy, or reward.
  • Do not click attachments, links, or embedded previews until the identity is confirmed.
  • If the request is sensitive, move verification to a trusted channel before continuing.

For the underlying security discipline, NIST Cybersecurity Framework 2.0 is useful because it reinforces governance, identification, protection, detection, and response as connected activities, not one-time checks. For practical account-hardening and suspicious-message handling, CISA Known Exploited Vulnerabilities Catalog is a reminder that confirmed exploitation paths should be treated as real until proven otherwise.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-63 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-63Digital Identity GuidelinesIdentity checks depend on verifying whether a claimed social profile is credible.
Recommendation — Apply phishing-resistant verification steps before trusting a new online contact.
MITRE ATT&CKEnterprise MatrixSocial messages can be part of the attacker path to credential access and follow-on compromise.
Recommendation — Map suspicious-contact tactics to attacker techniques and block the follow-on path.
NIST CSF 2.0ID.RA-01 — Asset vulnerabilities are identified and recordedEmployees need a repeatable way to recognize suspicious social-contact risk.
PR.AA-05 — Identities and credentials are managed, protected, and verifiedThe question is fundamentally about verifying the identity behind a request.
DE.AE-01 — A baseline of network operations and expected data flows is established and managedUnexpected message behavior stands out when normal communication patterns are known.
Recommendation — Assess social-message risk signals before allowing interaction or disclosure. Verify the sender’s identity before accepting contact or replying. Compare the request against expected relationship and communication patterns.

Practitioner Guidance

What to prioritise: Prioritise identity validation before conversation quality. If the account cannot be quickly reconciled with a trustworthy source, treat the request as unverified even if it appears polite or familiar.

What to verify: Verify three things before engaging, the profile’s coherence, the message’s behavioural cues, and whether the request makes sense in the context of the relationship. If any one of those is weak, slow down and confirm through another channel.

Common mistake: The most common error is trusting the social surface, such as a familiar name or attractive profile photo, and skipping the cross-check. That shortcut is exactly what social engineering is designed to exploit.

Practitioner takeaway: The safe default is not silence, it is verification. A short pause and a second-channel check usually costs little, but it closes the easiest path attackers use to turn social contact into compromise.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org