The Human Factor: Your Role in Security

About this module

This social engineering awareness module puts you inside a real-world scenario.

Meet Sarah: eight years at the company, careful with sensitive data, zero incidents, until one Tuesday morning email that looked exactly right. You'll watch how urgency, authority, and familiarity short-circuited her judgment, how one click exposed 40,000 customer records, and why 88% of employees click phishing links in simulations. It's not a failure of intelligence. It's a success of social engineering.

By the end you'll have the three-step habit that breaks the attack chain: pause when rushed, verify independently, and report even the false alarms.

Key takeaways

  • 88% of employees click phishing links in security simulations
  • Urgency, authority, and familiarity short-circuit critical thinking
  • Verify requests independently: never through the suspicious message itself
  • Reporting false alarms still protects colleagues facing the same attack

Full Transcript

Meet Sarah. She's a capable, experienced employee who takes her job seriously. She's not careless.

She's not negligent. She's just... human.

It's Tuesday morning. Sarah has been with the company eight years, handles sensitive financial data daily, and has never had a security incident. Until today.

At nine forty-seven an email lands from what looks like the payments team. Subject: 'Urgent — Invoice approval needed.' It asks her to log in to a vendor portal to release a payment.

Put yourself in Sarah's position. Busy morning. The email looks legitimate.

The sender name matches a colleague. The logo looks right. The request is within her normal responsibilities.

Sarah clicked, and handed over her credentials. The domain was a lookalike. The site was fake.

In sixty seconds, her login was in the hands of an attacker.

Eighty-eight percent of employees click on phishing links in security simulations. That's not a failure of intelligence. It's a success of social engineering.

In forty-eight hours the attacker moved through the network. Forty thousand customer records were exfiltrated. Sarah didn't know until the I.T. team called her on Wednesday afternoon.

People who say 'I'd never click that' are often the most vulnerable. Attackers study human psychology. They know that urgency, authority, and familiarity short-circuit our critical thinking.

First: pause. Urgency is the attacker's greatest tool. When an email or message tries to rush you: slow down.

That friction you're feeling? That's your instinct working.

Second: verify. Don't use the phone number in the suspicious message. Look up the sender's contact independently: call the colleague, check the internal directory.

Third: report. Forward suspicious emails to I.T. security. Even a false alarm is useful.

It builds pattern data and protects your colleagues who might receive the same attack.

Technology catches the vast majority of threats. But the attacks that get through are specifically designed to fool technology, and they rely on one thing: a human who doesn't pause.

The strength of a security chain is its weakest link. Your job isn't just doing your work. It's making sure the chain stays strong.

In Module Four you'll put these habits into practice with safe browsing: knowing which sites are safe, how to spot a fake, and what to do when something looks off.