Did you know that over 80 percent of cyberattacks are due to human error?
4IR Simplified
John Tseriwa
Contrary to the popular belief that highly sophisticated expert hackers carry out cyberattacks, the truth is that most cybersecurity attacks are due to human error.
Although sophisticated hackers often dominate the headlines, human error remains the most significant threat.
Just as leaving your car keys in the ignition can attract even an amateur thief, neglecting small security measures online can make you vulnerable to cyberattacks.
Cybersecurity professionals often point out that people can be the weakest link in the chain of defence against cyberattacks.
This is because human beings are susceptible to making errors, falling prey to well-crafted scams, or even cybercriminals acting with malicious intent.
Educating and training individuals on proper cybersecurity practices is essential, but it is also crucial to implement technical controls to protect against these vulnerabilities.
By combining education and technical solutions, organisations and individuals can strengthen their cybersecurity and better defend against potential threats.
These errors can range from simple mistakes like using weak passwords, falling for phishing scams, misconfigured systems or improperly configured firewalls.
Let us talk about a term that can be quite ambiguous — social engineering.
Someone would be tempted to think this is a well-meaning profession.
However, social engineering refers to the practice of manipulating or deceiving individuals or groups to achieve a particular outcome.
Why is it called social engineering?
The reason is it relies on human nature rather than technical hacking skills to manipulate people into compromising personal or organisational security.
Social engineering is also called “human hacking” because it exploits human weaknesses rather than technical vulnerabilities.
The term “social engineering” was popularised by the infamous hacker Kevin Mitnick in the ’90s.
Mitnick was convicted and sentenced, but he “repented”. His books are now bestsellers and well-known in the cybersecurity world.
Social engineering attacks can take many forms, including phishing emails, phone scams and in-person interactions.
In addition to cybercriminals, individuals who impersonate government officials and gather information from households under pretence are also skilled social engineers.
Remember, before the Zimbabwe 2022 census, these criminals would often visit households disguised as census workers, gathering information about the targeted family and using it for nefarious ends.
Social engineering is meant to exploit certain universal human qualities like greed, curiosity and impatience for financial gain.
Examples of social engineering include phishing attacks, smishing, baiting, scareware, et cetera.
Phishing is the most common type of social engineering attack.
It involves sending a fake email or message that appears to be coming from a legitimate source such as a bank or a social media platform.
The email usually contains a link that, when clicked, takes the user to a fake website where they are asked to enter their login credentials.
Baiting is another form of a social engineering attack, where the victim is lured to download malicious code by tempting them with a valuable offer.
Pretexting involves creating a false scenario to obtain information.
For example, an attacker may pose as a bank employee and calls a victim to ask for their account information.
How to spot a social engineering attack?
When something seems too good to be true, there is likelihood that it is not genuine.
An infamous example of this principle is the classic email scam where an individual claiming to be the daughter of a wealthy Saudi Arabian prince contacts unsuspecting victims via email, offering them financial gain in exchange for assistance with getting access to their inheritance through marriage.
As much as we may laugh at this, many of us still fall for such scams and tricks.
Scammers often use tactics like sending fraudulent emails claiming you have won a phone or a lottery you never entered, but in reality, life is far more complex than these deceptive tactics.
Social engineering attacks typically follow a predictable pattern that can be broken down into several stages, including investigation, hook, play and exit.
By understanding the stages of a social engineering attack, individuals can take steps to protect themselves against these types of threats.
The best way to prevent social engineering is through cybersecurity awareness training.
Apart from training, individuals need to stay calm and cautious, mainly when they receive new information.
This applies especially when dealing with unusual links or strange emails/texts.
Never open emails or file attachments from unknown sources to avoid being hacked.
If you do not recognise the email address, delete the email outright and don’t click on any links or download any attachments.
Always remember that you never share personal information online.
Protect your personal information by never giving out passwords or financial details online.
Social engineering attacks are not limited to cyber criminals, as individuals who impersonate government officials and gather information from households under pretence are also skilled social engineers.
Therefore, educating and training individuals on proper cybersecurity practices and implementing technical controls to protect against these vulnerabilities are essential.
John Tseriwa is a tech entrepreneur and a digital transformation advocate focusing on delivering business solutions powered by 4IR technologies. He can be contacted at: [email protected] or +263773289802.



