Defences: Awareness, Verification and Multi-Factor
Chapter Thirty-Three
Syllabus topic Module 1, "Social Engineering and Human Exploitation Techniques"; Course Outcome 5, "Recommend appropriate mitigation strategies"
Pages 156 to 160 of 578
In one line
Because the target is a person doing their job, the defence cannot be "be more careful". It is a layered arrangement: train people to recognise the levers, build process gates that do not bend, and deploy multi-factor authentication so that a deception that succeeds still does not grant access.
In examination wording: mitigation of social engineering combines awareness training to improve recognition, procedural controls requiring independent verification of sensitive actions, technical controls including multi-factor authentication and least privilege to limit what a successful deception achieves, and detection and response arrangements, notably a blame-free reporting channel, to limit damage when prevention fails.
The principle that orders everything
State it first, because the rest follows from it: a control that depends on every person being alert every time will fail, because the attacker needs one person to be tired once.
So defences are ranked by whether they still work when somebody is deceived:
- Controls that do not involve the person's judgement at all (a process gate, a second factor) work regardless.
- Controls that limit the damage once someone is deceived (least privilege, rapid detection) work often.
- Controls that improve the person's judgement (training) reduce the rate and cannot eliminate it.
All three are needed. The mistake is to invest in the third and call it a programme.
Awareness training: necessary, insufficient, and often done badly
What it should teach. The levers, not a catalogue of current scams. A person who knows that manufactured urgency combined with a reason not to verify is the shape of an attack can recognise a technique they have never seen. A person who has memorised that "phishing emails have spelling mistakes" is worse than untrained, because they have a false test that today's attacks pass.
What it should include, concretely:
- The organisation's own statements of what it will never ask for: no one will ask for your password, no one will ask you to read out a one-time code, IT will never ask you to disable a security control.
- The specific high-risk actions and their rules: payment changes, credential entry, granting access, approving authentication prompts.
- How to report, with a route that takes seconds.
- That reporting a mistake is expected and will not be punished, stated by senior management, not buried in a policy.
Simulated phishing, used well and badly. Used well it measures susceptibility, identifies which departments and which lures need attention, and gives immediate teaching at the moment of the click. Used badly it becomes a trap: punitive consequences, humiliating league tables, or lures that exploit personal anxieties such as fake bonus or redundancy notices. Badly run programmes reduce security, because staff learn that the security team is adversarial and stop reporting real incidents. The metric to watch is not only the click rate but the reporting rate, which should rise; an organisation where clicks fall and reports also fall has taught people to stay quiet.
Defences: Awareness, Verification and Multi-Factor
The honest limit. Training reduces susceptibility measurably and never to zero. Security professionals who research phishing are phished. Any programme whose success depends on a zero click rate is designed to fail.
Process gates: the highest-value control
This is where the real protection is, and it is the answer to almost every case in the previous chapter.
A process gate is a rule that a particular sensitive action requires a specific verification step, regardless of who asks, how senior they are, or how urgent it is. Its power is that it removes the decision from the individual: the clerk does not have to judge whether the message is genuine, because the procedure requires the callback either way.
The actions that need gates:
| Action | The gate |
|---|---|
| Changing a supplier's or employee's bank details | Callback to a number already held on file, never one supplied in the request |
| Payments above a threshold, or to new payees | Second authoriser, independently |
| Password or second-factor reset for another person | Identity verification not based on publicly discoverable facts |
| Granting or elevating access | Request from the manager of record through the ticketing system, not by message |
| Releasing personal or commercially sensitive data | Verified requester and a recorded lawful basis |
| Anything described as too urgent for the normal process | The gate applies especially here |
Three design rules make gates work:
Independent channel. The verifying contact must be obtained independently, from records the organisation already holds. A number in the email signature verifies nothing, because the attacker wrote it.
No exceptions for seniority. A gate that a sufficiently senior person can override is a gate the attacker will impersonate that person to bypass. This must be endorsed publicly by senior management, or staff will not enforce it against them.
Urgency is not a reason to skip; it is a reason to apply. Since manufactured urgency is the attacker's principal tool, a procedure that relaxes under pressure inverts the defence.
Multi-factor authentication: the highest-value technical control
Against credential phishing, this is the single most effective measure available, because it breaks the link between "the attacker learned the password" and "the attacker has access".
The factors, which an examination may ask you to name: something you know (a password), something you have (a phone, a token, a security key), something you are (a fingerprint, a face). Genuine multi-factor authentication uses factors from different categories; a password plus a security question is two things you know, and is not multi-factor.
Defences: Awareness, Verification and Multi-Factor
The methods are not equal, and the ranking matters:
- SMS codes: the weakest. Vulnerable to SIM-swap attacks and to interception, and phishable, but far better than nothing.
- Authenticator application codes: better, since there is no telephone network to attack, but still phishable: an attacker who relays the login in real time can ask the victim for the code and use it within its validity window.
- Push approval: convenient, and vulnerable to fatigue attacks, where an attacker with the password sends repeated prompts until an irritated or confused user approves one. Number matching, which requires the user to type a number shown on the login screen, largely addresses this and should be enabled.
- Phishing-resistant factors (security keys and platform authenticators using the standards behind them): the strongest, because the credential is bound to the legitimate site's identity and simply will not produce a valid response to a look-alike domain. This defeats even a real-time relay, which the other methods do not.
Where it must be applied. Everywhere that matters, and specifically on the paths attackers use: remote access and VPN, email, administrative accounts, cloud consoles and anything holding personal data. An organisation that enables it for staff and exempts executives has protected the wrong people.
The recovery path. The lesson from the previous chapter, repeated because it is the commonest failure: securing the login and leaving a weak reset route relocates the attack. The reset procedure must be at least as strong as the control it restores.
Limiting the damage
Prevention fails, so these determine the loss:
- Least privilege. If the deceived account can reach little, the incident is small. This is the control that turns a compromise into an inconvenience.
- Segmentation, so a foothold does not reach everything.
- Rapid revocation, the ability to disable an account and terminate its sessions in minutes.
- Detection: alerts on impossible travel, new-device sign-ins, second-factor re-enrolment, mailbox forwarding rules created (a classic post-compromise step for payment fraud), and payments to recently changed details.
- A tested incident response plan, so the first hour is executed rather than improvised.
The reporting culture, which underpins all of it
Treat it as a control, because it is one. The damage from a successful attack is largely a function of time: a fraudulent payment recalled within the hour is often recoverable; credentials revoked in minutes limit what is reached.
That time depends entirely on somebody saying "I think I did something". Which means:
- Reporting must take seconds (a button in the mail client, one number to call).
- It must be blameless, stated explicitly and by senior people.
- Reports must be acknowledged, or people stop making them.
- Near misses should be reported too, because they reveal campaigns in progress.
Defences: Awareness, Verification and Multi-Factor
An organisation that disciplines the person who clicked has bought a quieter incident log and a longer average time to detection.
A worked example
A company reviews its social-engineering posture after the supplier-payment case. The recommendations, ranked by effect:
- Process gate: bank-detail changes require a callback to a number already on file; no exceptions for seniority or urgency. Signed off publicly by the finance director.
- Multi-factor authentication on email and remote access, using phishing-resistant keys for finance and administrative staff, with a reset procedure requiring manager verification.
- Detection: alert on payments to details changed within thirty days, and on any mailbox rule that forwards externally.
- Least privilege review of the finance system, so that no single account can both change payee details and release payment.
- Training on the levers, with simulations measured on reporting rate as well as click rate, and explicitly non-punitive.
- Reporting: a one-click report button and a published commitment that no one is penalised for reporting.
Note the ordering. Training is fifth, not because it is unimportant but because items one to four protect the company even when training fails, and item one alone would have prevented the incident that prompted the review.
What beginners get wrong
- Treating training as the programme. It reduces the rate; it cannot be the control where there was nothing to notice.
- Running punitive phishing simulations. They suppress reporting, which lengthens response time and increases loss.
- Measuring only the click rate. The reporting rate matters as much; if both fall, people have learned to stay silent.
- Calling a password plus a security question multi-factor. Both are things you know.
- Assuming all second factors are equivalent. SMS is weakest; application codes are phishable in a real-time relay; push is vulnerable to fatigue without number matching; only site-bound keys resist phishing.
- Securing the login and not the reset. The recovery path must be as strong as the control.
- Allowing seniority to override a gate. The attacker will impersonate exactly that seniority.
Quick revision
- Ordering principle: a control that needs everyone alert every time will fail. Rank by whether the control works when someone is deceived.
- Training teaches the levers, the organisation's "we will never ask" statements, the high-risk actions, and how to report; simulations must be non-punitive and measured on reporting rate as well as clicks. It lowers the rate, never to zero.
- Process gates are the highest-value control: independent-channel verification for bank-detail changes, large or new payments, password and second-factor resets, access grants and data releases; no exception for seniority, and urgency is a reason to apply the gate, not to skip it.
- Multi-factor authentication: factors from different categories (know, have, are). SMS weakest; app codes phishable in real time; push needs number matching; site-bound security keys are phishing-resistant. Apply to email, remote access and administrative accounts, and secure the reset path.
- Damage limitation: least privilege, segmentation, rapid revocation, detection (impossible travel, new devices, re-enrolment, forwarding rules, changed payee details), and a tested response plan.
- A fast, blameless reporting culture is a control, because loss is a function of time.
Defences: Awareness, Verification and Multi-Factor
Test yourself
- Why can awareness training not be the primary defence against social engineering?
Because the attacker needs only one person to be deceived once, because knowing about a bias does not remove it, and because in the most damaging attacks the request looks entirely routine so there is nothing for an alert person to notice. Training lowers the rate, while process gates and multi-factor authentication work regardless of whether anyone was alert.
- What is a process gate, and what three design rules make one effective?
A rule that a sensitive action requires a specific verification step regardless of who asks or how urgent it is. It must use an independently obtained channel such as a number already held on file; it must have no exception for seniority, since the attacker will impersonate exactly that seniority; and urgency must trigger the gate rather than excuse it, because manufactured urgency is the attacker's principal tool.
- Name the three categories of authentication factor and explain why a password plus a security question is not multi-factor.
Something you know, something you have, and something you are. A password and a security question are both things you know, so an attacker who obtains them by the same means, such as a phishing page or research, defeats both; genuine multi-factor authentication requires factors from different categories.
- Rank the common second-factor methods by resistance to phishing and explain the strongest.
SMS is weakest (SIM swap, interception, phishable); authenticator application codes are better but still phishable through a real-time relay; push approval is vulnerable to fatigue attacks unless number matching is enabled; security keys and platform authenticators are phishing-resistant because the credential is cryptographically bound to the legitimate site's identity and will not produce a valid response to a look-alike domain.
- Why is a blameless reporting culture treated as a security control, and what does punishing a click cost an organisation?
Because loss depends largely on elapsed time: a fraudulent payment recalled within the hour is often recoverable and credentials revoked in minutes limit what an attacker reaches, and that speed depends on someone reporting immediately. Punishing clicks makes people conceal mistakes, lengthening detection and response time and increasing loss, while also suppressing the near-miss reports that reveal campaigns in progress.
The rest of this subject
These notes are cut from the University's printed syllabus. Open the syllabus itself for the same subject.