Spies have always relied on technology, disguises, secret communications and clever gadgets, at least if the movies are to be believed.
But some of the most effective tools in the espionage business have always been people. Convince the right person to open a door, reveal a secret or trust someone they should not, and suddenly bypassing the sophisticated security system becomes unnecessary.
I love October for the ability to concentrate our efforts on slowing social engineering, but I also know a lot of people put in charge of doing something for Cybersecurity Awareness Month do not have a lot of experience leveraging it. This is why we put out the KnowBe4 Cybersecurity Awareness Month kit, and this year it is taking on a fun spy theme while providing materials to help.
Week one (the first full week of October) includes the character known as “Ghost,” a Counter-Intelligence Specialist with the theme being Social Engineering. Three other weekly themes follow throughout the month such as AI, credential hygiene and incident reporting and physical security.
Cybercriminals Understand that Attacking Humans Works
Attackers know that they do not necessarily need to defeat firewalls, endpoint protection or other sophisticated security controls if they can convince someone with legitimate access to do the work for them. A phishing email can convince someone to hand over credentials. An attacker impersonating an executive can persuade an employee to transfer money. A fake IT support call can convince someone to approve an MFA request. In other words, sometimes it is easier to fool the person with the key than it is to pick the lock.
The Art of Manipulation
Social engineering has a lot in common with traditional spycraft. Both can involve gathering information about a target, establishing credibility and using psychology to influence someone into taking an action they normally would not.
Attackers frequently rely on emotions such as urgency, fear, curiosity, excitement and even a desire to be helpful. A message from the CEO demanding an immediate wire transfer creates urgency and authority, a warning that an account is about to be locked creates fear, a document labeled confidential may spark curiosity, or a call supposedly from the help desk asking an employee to approve an authentication request can take advantage of our natural tendency to cooperate with people who appear legitimate.
None of these emotions or reactions are inherently bad, and people need to understand that. The problem is that attackers know how to exploit them, and the objective is often simple: get the target to act before they have time to think. That makes one of the most useful countermeasures surprisingly low-tech; slow down, take a deep breath and look at things more closely.
Taking a few extra seconds to examine a message, independently verify a request or question why someone suddenly needs sensitive information or gift cards, can be enough to expose the operation.
Train People Like They Are Part of the Defense
If employees are going to be targeted, and they will be, they need to understand the tactics being used against them. To best help them defend themselves, security awareness training should not simply consist of an annual presentation telling everyone not to click suspicious links. People are much better prepared when they understand why attackers do what they do and have practical experience recognizing those techniques.
We need to remember that employees do not need to become cybersecurity experts, but they do need enough security savvy to recognize when something does not look right and know what to do next. Look at it this way: we would not put someone behind the controls of a forklift without training them first, yet people spend their entire workday using computers, email, collaboration platforms, cloud applications and mobile devices, all of which can expose them to attacks. Teaching them how to use those tools safely should be just as important.
Training should include real-world examples that show people what phishing messages really look like. Explain why attackers manufacture urgency, discuss business email compromise and impersonation attacks, demonstrate how information from social media and other public sources can make a scam much more convincing, and most importantly, teach people how to quickly report something suspicious, and make it easy to do.
Every Employee Can Provide Intelligence
In the spy world, intelligence is valuable because it gives defenders an opportunity to act, and the same applies to cybersecurity. An employee who quickly reports a suspicious email may provide the security team with valuable threat intelligence. If one person reports a phishing message, defenders may be able to identify and remove similar messages before other employees interact with them. Or, if someone reports a suspicious phone call it could allow the organization to warn others that someone is impersonating the help desk. This is why reporting needs to be simple and encouraged.
A report-phishing button, security hotline and/or clearly identified internal contact can save precious time. Employees should not have to investigate an incident themselves or wonder which department to contact, because their job is to raise the alarm, then the security team should take it from there.
Do Not Punish the Person Who Sounds the Alarm
One of the worst things an organization can do is create a culture where employees are afraid to report mistakes. If someone realizes they clicked a suspicious link, entered credentials into a questionable website or opened an attachment they should not have, security teams need to know as quickly as possible. This is how embarrassment and fear can turn a relatively small security incident into a much larger one through delayed reporting or not reporting at all.
Simulated phishing and other attack simulation exercises can help build these reporting habits, but only when they are used to educate rather than embarrass employees. The goal should never be to catch people doing something wrong, having high click rates is not a badge of honor for security people, instead attack simulations should be to give them experience recognizing attacks and build the muscle memory needed to report suspicious activity quickly. Think of it as a training exercise rather than a sting operation and the more realistic practice people receive, the better prepared they can be when the message is no longer a simulation but be reasonable and do not make attack simulations adversarial.
Trust, but Verify
Good spies understand that appearances can be deceiving. In today's world, that lesson is becoming even more important as AI-generated content, voice cloning and deepfakes can make impersonation attacks increasingly convincing. People need to know that a familiar voice, face or writing style should not automatically be considered proof of identity.
Organizations Should Build Verification into High-Risk Processes
If someone suddenly requests a large financial transfer, sensitive information or a change to established procedures, or something out of the norm, require a second form of confirmation using a trusted communication channel. Do not simply reply to the suspicious email or call the telephone number provided in it. If you are going to make an out of the ordinary request of an employee, give them a heads-up first.
Verification is especially important when a request involves money, credentials, sensitive information or unusual changes to normal procedures. The point is not to distrust everyone, but to recognize that identity itself can be spoofed.
Even the Best Agent Needs Backup
Education is extremely important, but employees should never be the organization's only line of defense. Cybersecurity has never been about finding one silver bullet. Effective security requires layers of defenses that complement one another.
Email and communication filtering can reduce the number of malicious messages that ever reach employees, while endpoint protection can help stop malicious software when something gets through. Additionally, monitoring and alerting can identify unusual activity, multi-factor authentication can make stolen passwords more difficult to use, and a well-practiced incident response plan gives organizations a way to react quickly when defenses fail. The key is making those layers work together.
Technology should help protect people, and people should provide another layer when technology misses something. Security awareness training, attack simulations, filtering, endpoint protection, MFA, monitoring, reporting and incident response all have different jobs to do. No single layer should be expected to save the entire organization.
Know the Adversary’s Playbook
Attackers adapt, so our security education needs to adapt as well. Instead of relying solely on the same annual training year after year, especially done just annually, organizations should regularly share examples of current scams, discuss phishing and social engineering during team meetings, review reporting procedures and use short training opportunities to reinforce important lessons. Those attack and phishing simulations can provide practical experience, especially when scenarios reflect attacks employees might realistically encounter.
It is helpful if training also explains the psychology behind those attacks, from a high level of course, so employees understand that when attackers intentionally create urgency, impersonate authority or try to trigger an emotional response they can recognize those techniques regardless of the specific lures being used.
That lesson extends beyond the workplace. The same employees protecting organizational information during the day are dealing with fake delivery notices, account takeover attempts, fraudulent text messages and impersonation scams in their personal lives. Helping people develop stronger cybersecurity habits protects the organization, but it can also protect employees and their families and that makes security education far more meaningful, relatable and palatable for employees than another mandatory training module that seems like all it cares about is saving the organization from trouble.
Your Mission: Stay Skeptical
Cybercriminals may not wear trench coats, carry exploding pens or meet their contacts on park benches, but many of the principles behind their attacks would be very familiar to anyone in the intelligence business. Gather information, establish trust, create a believable story, apply pressure, then convince the target to act.
Our job is not to make employees paranoid about every email, phone call or text message they receive. Our job is to help them develop a healthy sense of skepticism and give them the knowledge and tools to recognize when something does not feel right.
Train them, give them realistic practice, make verification normal, make reporting easy, and back them up with strong technical controls. When someone is trying to manipulate their way into your organization, every employee has the opportunity to become part of the counterintelligence team, and a license to question suspicious requests should probably come standard with the job.
