
Workplace MODULE
Social engineering
The story is the attack. Learn to hear it being told.
How a plausible story gets a careful person to do something they would never otherwise do, the levers underneath every version of it, and the process that holds even when the story is perfect. For everybody in an organisation, whatever their job.
- Name the pressure a request is using, and treat that as information rather than as proof.
- Verify a person through a route you chose, not the one the request offered.
- Refuse a code, a prompt or a remote session without having to prove it was an attack.
Your learning path
01Nobody breaks in. Somebody is persuadedUnderstand why a plausible story outperforms a technical trick.Locked02The levers, and why they work on everyoneName the pressure a request is using, because naming it is what slows it down.Locked03The call that says it is ITHandle an unexpected call, chat or visit offering to fix a problem you never reported.Locked04When they ring your help desk insteadRecognise that you are the identity being impersonated, and see what a verification that works looks like.Locked05It starts in one channel and finishes in anotherFollow an attack as it moves between email, phone, chat and the prompt on your phone.Locked06What they already know, and what to do nextSee your organisation the way somebody researching it does, and act well after an approach.LockedPut your decisions into practice.
Complete each lesson’s scenario, then take eight new questions. A score of at least 80% earns a personal completion record. Retry with feedback; this is a learning exercise, not a timed exam or professional accreditation.
Lessons and scenarios are original Jatzo material informed by published guidance and research:
- NCSC: incidents impacting retailers, recommendations
- NCSC: telling users to avoid clicking bad links still isn't working
- Cyber security breaches survey 2025/2026
- Microsoft Security: threat actors misusing Quick Assist in social engineering attacks
- Phishing in organizations: findings from a large-scale and long-term study
- CISA: implementing number matching in multi-factor authentication applications
- NCSC: report a suspicious email
- Report Fraud: reporting a fraud
- CrowdStrike: 2025 global threat report (voice phishing figures)
- CNN Business: Arup revealed as victim of a 25 million dollar deepfake scam
- Uber: security update on the September 2022 incident
- Influence at Work: Robert Cialdini's principles of persuasion
- Companies House: search the register of companies and directors
- Business and Trade Sub-Committee: oral evidence on UK economic security, 8 July 2025
- Marks and Spencer: half year results for the 26 weeks ended 27 September 2025
