Social Engineering in OT and IT Security

Protect your organization from social engineering, the source of 70–80% of attacks via IT networks. Watch for urgency, authority, scarcity, trust, and fear tactics in phishing, pretexting, baiting, and tailgating. Defend with MFA, user training and others

Social Engineering in OT and IT Security

What Is Impersonation and Social Engineering

Impersonation is what we call social engineering. It is a cyber attack that uses psychological manipulation to trick people into giving away sensitive information like passwords or OTPs, and into performing actions that end up harming us.

The first defense against it is user awareness, because social engineering does not use any technical trick to break through our security. It works on our mind instead, and once it works, the attacker walks in using our own legitimate credentials. That is why even after we deploy Multi Factor Authentication, the same psychological manipulation can still be used to trick us into sharing our OTP.

Some scammers get really creative, with ideas that come completely out of nowhere, but most of them follow a pattern. The easiest way to remember this pattern is one simple line.

“ Uncles Always Share Tasty Food ”

Urgency      Authority      Scarcity      Trust      Fear

These five triggers show up, in some combination, in almost every social engineering attempt. Once we can spot them, we can spot the scam. The next section walks through each one.


The Five Triggers Behind Every Scam

Every convincing scam is really just a story built around one or more of these five feelings. Let us go through them one by one, with real examples of how they sound.

1. Urgency

Urgency, Creates Panic to Rush Our Actions

Examples

Act now or lose access to your account!” - Forces quick action without thinking.
Your account will be locked in 30 minutes, verify now!Triggers panic.
Last chance! Unpaid invoice will lead to legal action, pay immediately!Pushes a rushed response.

Urgency is a red flag. If something feels unusually urgent, we should pause and verify before we act.


2. Authority

Authority, Pretends to Be a Powerful Figure

Examples:

This is the CEO, send me the employee payroll list now.Impersonates an executive.
I am from IT support, provide your login to fix the issue.Uses IT role to pressure compliance.
This is HR. Send me your ID and contract for an urgent audit.Pretends to be from Human Resources.
I am from the government tax office, share your financial records now.Uses government position.
Police Cyber Unit here. We detected illegal activity. Confirm your credentials to avoid arrest.Uses fear and fake authority together.
I am your manager. Approve this wire transfer immediately.Spoofs a boss for financial action.
As per company policy, IT must install this software update, provide access now.Mimics official policy.

3. Scarcity

Scarcity, Claims Limited Time or Access

Examples:

Only 5 licenses left, claim yours now!Pushes quick action with limited availability.
Offer expires in 10 minutes, download now!Creates time pressure.
Only the first 100 users get access.Triggers fear of missing out.
Exclusive access for today only, act fast!Pretends this is a limited time deal.
Your account storage is almost full, upgrade immediately.” Fakes a limited resource.

4. Trust

Trust, Uses a Familiar Name or Tone to Lower Our Guard

Examples:

Hi, I am from Microsoft support. I am here to help fix your PC.Fakes a trusted brand.
This is your bank. We noticed unusual activity, please verify.Uses a familiar institution.
Hey, it is John from the finance team. Can you help with this payment?Pretends to be a coworker.
I am with the government health department. Fill out this form for benefits.Uses an official sounding role.
We met at last week’s conference. Can you check this file for me?Creates a fake personal connection.

5. Fear

Fear, Threatens Serious Consequences

Examples:

Your account has been hacked, reset your password now!Creates panic.
We found illegal files linked to your national ID. Confirm your ID to avoid arrest.This is the pattern behind the Digital Arrest scam, and it plays entirely on legal fear.
Your bank account will be frozen, verify your info immediately.Pushes fear of losing money.
Security alert, someone tried to access your email. Click here to secure it.Fakes a breach.
You missed a court summons. Pay the fine now to avoid jail.Uses legal fear to force payment.

Common Types of Social Engineering Attacks:

1- Phishing:

Phishing tricks people into giving up credentials through fake emails, texts, or websites. Attackers now use AI writing tools to craft convincing messages with proper grammar, which makes the old advice of "look for bad spelling" much less reliable than it used to be.

How to protect ourselves:

✓ Do not click unknown links or download unexpected attachments.
✓ Check email addresses carefully, for example goog1e.com instead of google.com.
✓ Watch for subtle red flags, even though AI has reduced the obvious grammar errors.
✓ Never share passwords or personal information by email.
✓ Use anti phishing tools and keep systems updated, as CISA recommends.
✓ Enable Multi Factor Authentication wherever it is available.


2 - Vishing and Smishing, Phishing Beyond Email

Phishing no longer travels only by email. Vishing is the same trick over a phone call, and Smishing is the same trick over a text message(SMS). Both work exactly the same way. Someone pretends to be our bank, our courier company, or even a family member in trouble, and asks us to act fast, often quoting the same five triggers we covered earlier.
A call that shows our bank's real caller ID can still be spoofed, so the safest move is to hang up and call the number printed on our card ourselves.

3 - Pretexting and Quid Pro Quo :

Pretexting is when attackers fake a role, such as IT support or the police, to trick us into giving up information. Quid pro quo is when attackers offer help or a reward in exchange for access. Industry data now shows pretexting has become one of the fastest growing tactics, since it does not need any malware at all, just a believable story and a bit of patience.

How to protect ourselves:
✓ Do not share information with unknown callers.
✓ Verify identities before sharing anything.
✓ Run regular training and simulations for our teams.
✓ Use strong passwords together with Multi Factor Authentication.
✓ Monitor accounts for suspicious activity.

4 - Baiting:

Baiting lures us with a fake reward, like a free download or a prize, to get us to share information or install malware.

How to protect ourselves, and it helps to simply remember there is no such thing as a free lunch. If something looks too good to be true, it probably is a scam.

✓ Be skeptical of offers that seem too good to be true.
✓ Verify the source of any download.
✓ Do not enter personal information without verifying trust first.
✓ Keep anti malware tools up to date.
✓ Train staff to recognise bait traps.

5 - Tailgating, the Physical Side of Social Engineering

Tailgating happens when an attacker physically follows someone into a secure area without permission, which is a serious concern in OT environments where physical access can mean control system access.

How to protect ourselves:
✓ Do not let unknown people follow us into restricted zones.
✓ Use access cards, turnstiles, or biometric systems.
✓ Train employees to politely challenge anyone tailgating them.
✓ Monitor access logs and keep security staff and cameras in place.


AI Voice Cloning & Deepfakes

New Threat

Attackers are using AI to clone voices and, increasingly, faces on video calls. We have already seen real cases where a scammer calls an employee using a voice that sounds exactly like their manager or their CEO, asking for an urgent wire transfer some fund. This is Authority and Urgency working together, just powered by AI.

If a voice or video call asks us for money, credentials, or any sensitive action, especially if it feels rushed, we should verify through a second channel. A phone call to a known number, or a face to face confirmation, before we act on it.


Social Engineering in OT and ICS Environments

In OT and ICS environments, social engineering carries extra weight. A tailgating attempt at a substation or a plant is not just about a stolen laptop, it can be a step toward physical access to control systems. A phishing email disguised as a routine vendor update can be the first step toward a ransomware infection on an engineering workstation.

Because OT networks often run older systems that are hard to patch quickly, the human layer becomes an even more important line of defense. Badge discipline, visitor escort procedures, and a habit of verifying any unexpected request, even from someone wearing a contractor badge, all matter here just as much as the firewall does.

The Data Behind the Threat

Numbers help make the point. The Verizon Data Breach Investigations Report looked at breaches from around the world, and the human element, the part social engineering targets directly, was involved in the majority of them.

Image Source: Verizon Data Breach Investigations Report

Vulnerability exploitation and third party compromise matter a great deal too, but neither of them works without a person somewhere along the chain clicking, approving, or trusting something they should not have. That is exactly why awareness training is not a box ticking exercise, it is genuinely one of our strongest controls.

What To Do If We Suspect an Attack?

Even the most careful among us can have a bad day. What matters most is what we do in the next few minutes.

✓ Stay calm, most of the real damage happens in the reaction, not in the click itself.
✓ Disconnect the device from the network if we suspect malware.
✓ Change the affected password from a different, clean device.
✓ Report it to our IT or security team immediately, even if we feel embarrassed about it.
✓ If money was sent, contact our bank right away, some transfers can still be reversed within a short window.
✓ Save the email, message, or call log, it helps our security team trace the attack.


Key Takeaways

Social engineering exploits our psychology through urgency, authority, scarcity, trust, and fear. It targets people, not just systems, which is exactly what makes it harder to catch with technology alone.

Strong Multi Factor Authentication, regular user awareness training, and a Zero Trust mindset are all important, and none of them work well on their own. Prevention starts with awareness, so it is worth running regular training and phishing simulations to keep our teams sharp.

And a couple of habits are worth repeating often.

There is no such thing as a free lunch, if we are not paying for the product, we are the product.

It also pays to take precaution before connecting to a free WiFi network or plugging in a USB drive we found lying around somewhere.


References and About the Author:

This material was developed through an extensive review of root cause analysis reports covering more than 200 attacks, along with technical reports and industry publications. Key reference material includes publications from NIST, CISA, SANS, and the Verizon Data Breach Investigations Report.

This content is intended for educational and awareness purposes. It combines technical sources with the author's own professional experience in industrial cybersecurity and critical infrastructure protection. Some concepts have been simplified for readability, and the examples are meant to help build intuition, real attackers may use other methods as well. Readers should apply their own judgement before making any engineering, operational, or security decisions based on this material.

AI writing tools were used as an editorial assistant, to improve readability, grammar, and clarity. The technical concepts, interpretation, structure, and final technical review were carried out by the author.

This article was written by Abu Saleh Muhammad Zakaria, a security researcher with 300 plus citations, certified by SANS GIAC, Cisco, Fortinet, Google, and twenty others. Certified Expert in I.T. Security, Information Security, O.T. Security and Physical Security. If we found this useful, please share it with others. Questions and thoughts are always welcome.
Email:  sec.asmz@gmail.com
LinkedIn:  https://linkedin.com/in/asmz/