Where attacks actually succeed.
WHAT MOST SUCCESSFUL ATTACKS INVOLVE
A person doing something reasonable-seeming.
Clicking a link, approving a request, providing a code, making a payment.
WHY
It is easier than defeating technical controls.
WHAT THAT MEANS
Technical defences alone do not protect you.
WHAT ATTACKERS EXPLOIT
Trust in authority Urgency Helpfulness Fear of consequences Routine
THE ROUTINE POINT
A request that resembles what normally happens is rarely questioned.
WHAT DEFENDS AGAINST IT
Procedures that do not bend Verification through a separate channel A culture where checking is welcomed
THAT LAST ONE MATTERS MOST
If people fear being thought difficult, they skip verification.
WHAT TO SAY EXPLICITLY
That no request is too urgent to verify, and that nobody will be criticised for checking.
WHAT TO TRAIN
Not how to spot a fake. How to verify.