The easiest way into a well-defended network is still the same as it's always been: ask someone inside to open the door.
Organisations have spent the last decade getting genuinely better at technical defence, better firewalls, better endpoint tools, better patching discipline. Attackers noticed. Rather than fight through those defences, most have shifted their effort toward the one control that's hardest to patch: human judgement under pressure.
|
62% of breaches involved a human element globally in 2026, up from 60% the year before (Verizon 2026 DBIR) |
60% of incidents reported to the ACSC in FY2024–25 involved phishing (ASD Annual Cyber Threat Report 2024–25) |
+138% jump in total losses large Australian businesses reported from business email compromise (ASD Annual Cyber Threat Report 2024–25) |
What's changed is the method, not the motive. Verizon's 2026 report found that voice calls and text messages are now pulling a 40% higher click rate than email phishing, which tells you attackers are working the phone and SMS just as hard as the inbox. At the same time, unpatched software vulnerabilities have overtaken stolen credentials as the single most common way attackers get in (31% of breaches). Read together, those two data points say the same thing from different angles: the gaps that get exploited are the ones in your everyday processes, not in some hypothetical zero-day.
We've already covered what social engineering actually is and the common types of attacks to watch for. This post is about what to do next. Below are eight controls that make social engineering a lot harder to pull off against your organisation, in roughly the order we'd recommend tackling them.
Make security awareness training something people actually retain
A once-a-year compliance video does not change behaviour. Social engineering works by exploiting instinct, the urge to be helpful, to respond fast, to trust a familiar name, so training has to build habits, not just tick a box.
|
What this looks like: short, frequent modules built around real examples (a spoofed email address, a mismatched hyperlink, a request that skips the usual approval step) rather than a long annual refresher nobody remembers by March. Our security awareness training programs (stickmancyber.com/cybersecurity-awareness) are built around this cadence. |
|
|
|
|
▶ WATCH · STICKMANCYBER 5 Considerations When Creating a Security Awareness Program Our own take on why no amount of anti-virus, firewalls, or endpoint protection stops an employee clicking a phishing link, and what a program needs to actually work. |
|
Run real social engineering simulations, not just training
Training tells people what to look for. Simulation tells you whether it worked. Running phishing (and increasingly, voice and SMS) simulations against your own staff shows you exactly where the gaps are, before an attacker finds them for you.
|
What this looks like: cloud-based simulation campaigns tailored to your organisation, run periodically rather than as a one-off, with results feeding straight back into what your next training module covers. |
Tighten your email gateways
Spam still makes up close to half of all email traffic, and a large share of it is built to compromise systems, steal data, or harvest credentials. A well-configured email gateway is still one of the highest-return controls available, catching the bulk of it before it ever reaches an inbox.
|
What this looks like: layered filtering plus authentication protocols (SPF, DKIM, DMARC) configured correctly, not just switched on and forgotten. |
Put a policy around what gets shared on social media
Spear phishing works because it's personal, and the more an attacker can learn about a target from a public profile, the more convincing the pretext. A basic social media policy, covering what employees post about their role, projects, and organisational structure, closes off a surprising amount of that reconnaissance.
Put process, not judgement, around high-risk transactions
No firewall stops CEO fraud, because CEO fraud doesn't target your network, it targets your finance team's inbox. An attacker impersonating a senior executive asks for an urgent transfer, and if the only safeguard is one person's judgement in the moment, that safeguard will eventually fail.
|
Why this matters right now: business email compromise losses at large Australian businesses jumped 138% in FY2024–25, and BEC with financial loss now accounts for 15% of the cybercrime threats businesses self-report to the ACSC. |
A simple rule, verbal confirmation for any transfer above a set threshold, closes this gap almost entirely, and it costs nothing to implement.
Turn on multi-factor authentication everywhere it counts
Social engineering usually aims at credentials as a stepping stone to something bigger. MFA doesn't stop someone handing over a password, but it stops that password being enough on its own. It's one of the Australian Signals Directorate's Essential Eight mitigation strategies for a reason.
|
What this looks like: MFA on email, VPN, and any system holding sensitive data, paired with access limits so a compromised account can't reach more than it needs to. |
Monitor critical systems around the clock
Some social engineering tactics, Trojanised files disguised as harmless attachments, for example, rely on getting a foothold and staying quiet. Continuous monitoring of the systems holding your sensitive data is what catches that activity before it turns into a breach, and regular vulnerability assessments show you where those systems are exposed in the first place.
Encrypt data in transit
If an attacker does get access to a communication channel, encryption limits what they can actually do with it. A current SSL/TLS certificate on every public-facing site and portal is the baseline, it authenticates your site to visitors and encrypts what passes between them and you.
|
Talk to an expert Social engineering isn't going away, it's getting quieter and moving to new channels. StickmanCyber has helped 200+ organisations build the training, testing, and technical controls to stay ahead of it. Explore our social engineering testing and prevention services, or talk to our team directly. Book a free consultation → stickmancyber.com/contact-us |
None of these eight controls work in isolation, and none of them are a single silver bullet. Training changes what people notice, simulation tells you if it stuck, and policy plus MFA plus monitoring catch what slips through anyway. Together, they're what turns “please click here” from a real threat into a non-event.
Sources
Verizon, 2026 Data Breach Investigations Report
Australian Signals Directorate, Annual Cyber Threat Report 2024–25
