APAC CIOOutlook

Advertise

with us

  • Technologies
      • Artificial Intelligence
      • Big Data
      • Blockchain
      • Cloud
      • Digital Transformation
      • Internet of Things
      • Low Code No Code
      • MarTech
      • Mobile Application
      • Security
      • Software Testing
      • Wireless
  • Industries
      • E-Commerce
      • Education
      • Logistics
      • Retail
      • Supply Chain
      • Travel and Hospitality
  • Platforms
      • Microsoft
      • Salesforce
      • SAP
  • Solutions
      • Business Intelligence
      • Cognitive
      • Contact Center
      • CRM
      • Cyber Security
      • Data Center
      • Gamification
      • Procurement
      • Smart City
      • Workflow
  • Home
  • CXO Insights
  • CIO Views
  • Vendors
  • News
  • Conferences
  • Whitepapers
  • Newsletter
  • Awards
Apac
  • Artificial Intelligence

    Big Data

    Blockchain

    Cloud

    Digital Transformation

    Internet of Things

    Low Code No Code

    MarTech

    Mobile Application

    Security

    Software Testing

    Wireless

  • E-Commerce

    Education

    Logistics

    Retail

    Supply Chain

    Travel and Hospitality

  • Microsoft

    Salesforce

    SAP

  • Business Intelligence

    Cognitive

    Contact Center

    CRM

    Cyber Security

    Data Center

    Gamification

    Procurement

    Smart City

    Workflow

Menu
    • Cyber Security
    • Hotel Management
    • Workflow
    • E-Commerce
    • Business Intelligence
    • MORE
    #

    Apac CIOOutlook Weekly Brief

    ×

    Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from Apac CIOOutlook

    Subscribe

    loading

    THANK YOU FOR SUBSCRIBING

    • Home
    • Cyber Security
    Editor's Pick (1 - 4 of 8)
    left
    IAM May Help Secure Data, But It Needs to be Protected as Well

    Marc Ashworth, Chief Information Security Officer, First Bank

    The Changing Landscape of Cyber Security

    Scott Brandt, CIO & Director of IT, Texas Office of the Secretary of State

    Cyber Security - Integrated enterprise approach required to address the multifaceted challenges

    Sumit Puri, CIO, Max Healthcare

    Leadership Framework for Building Elite Teams

    Douglas Duncan, CIO, Columbia Insurance Group

    Four Cybersecurity Weak Spots You Should Care About When Others Don't

    Marc Probst, CIO & VP, Intermountain Healthcare

    Enterprise Security And The Elusive

    Andre' Allen, CISO, City of Houston

    Secure Text Messaging in an Academic Medical Center - Experience and Lessons

    Kari Cassel, SVP & CIO, UF Health

    It's Time to Turn Security Inside Out

    Gilad Raz, CIO, Varonis

    right

    Cracking The Code - The Psychology Of Social Engineering And The Power Of The Human Firewall

    Joel Earnshaw, Manager Security & Risk, Perenti

    Tweet
    content-image

    Joel Earnshaw, Manager Security & Risk, Perenti

    The idiom that “a chain is no stronger than its weakest link” reportedly was first published in 1786, yet it is known to have Basque origins that pre- date that period. When viewed through a cyber lens, the inference is that even the most stalwart of defences can be circumvented by targeting areas of known weakness. And it’s through this notion that the art of Social Engineering and human manipulation have continued to evolve. Threat actors’ prey on people as the weakest link, exploiting our natural propensity to trust, and tricking unsuspecting victims into divulging sensitive information or taking certain actions. But what’s the psychology behind these tactics, what makes it so successful, and how can we prevent ourselves from becoming unwitting accomplices.

    For centuries, crooks and criminals alike have understood one fundamental truth – that humans are social creatures, wired for trust. This instinctive inclination leaves us susceptible to manipulation and exploitation. And exploit us they do; bypassing even the most robust technical controls to target the human element and achieve their objectives. But what if we could turn weakness, into strength.

    As humans, our brains are wired for efficiency. We rely on mental shortcuts to process the wealth of data inputs we receive daily; and these shortcuts can lead to what’s known as ‘Cognitive Biases’. These biases are caused by the tendency of the human brain to simplify information inputs, and our limited capacity to process information objectively. Instead, we process information through a filter of our own experiences and preferences. Social Engineering exploits these very biases, using elements such as urgency, scarcity, authority, reciprocity, and confirmation bias to amplify the effectiveness of their attack campaigns.

    But Phishing, Smishing, Vishing and Telephone Oriented Attack Delivery (TOAD) techniques are just the tip of the Social Engineering iceberg. Adversarial tactics have evolved, becoming even more sophisticated thanks in part to the propagation and accessibility of Generative AI. Fortunately, though, we're not powerless.

    In many circles, the human element is commonly seen as an organisation’s greatest risk. But risk and opportunity are often two sides of the same coin. And what if we could turn that weakness, into one of our greatest strengths? Herein lies the concept of the Human Firewall.

    People are capable of incredible things, but the pursuit and achievement of the incredible typically requires perseverance, purpose, and preparation. A well-trained mind is a powerful asset. And through regular training we can better educate our people on current and emerging threats, common tactics and techniques, acknowledgement and reduction of cognitive biases, and instil both an individual and collective responsibility for cyber-safe securityaware behaviours. However, this must be paired with the establishment of clear guidelines that reaffirm when and how suspicious activity or communications should be reported. And we should always encourage our people to question their digital reality, no matter how compelling or believable – in today’s hyper-connected always-on digital world, caution and vigilance are key.

    But the most important facet is culture, and culture is king. It’s our responsibility as leaders to promote a cybersafe culture that permeates from the top down. Transparent communication and constructive feedback empower our people to raise potential incidents or issues without fear of reprimand. And by fostering a safe and inclusive team climate, we’re able to cultivate a security-minded culture where everyone understands and acknowledges their shared responsibility for individual and collective security.

    By understanding the psychology behind Social Engineering and promoting a culture of continuous cyber awareness, together we can significantly reduce the risk of falling victim to these universal attack types. And while the human element will forever remain an inherent vulnerability, through purposeful preparation, perseverance, and continuous engagement, it can become our most resolute line of defence.

    Cyber Security Isn't Simply About Firewalls, And Other Protective Technology Controls – At Its Core It's About Empowering People With The Knowledge And The Tools Necessary To Better Protect Themselves, Their Families, And Their Organisations From Those Current And Emerging Threats

    Cyber security isn't simply about firewalls, and other protective technology controls – at its core it's about empowering people with the knowledge and the tools necessary to better protect themselves, their families, and their organisations from those current and emerging threats. People, process, and technology working in harmony, to create a truly resilient cyber immune system. Let's reorient our thinking, and transform ourselves from weakest link, into Human Firewalls – The first and last line of defence, capable of thwarting even the most cunning of cyber criminals.
    tag

    cyber criminals

    Firewall

    AI

    Weekly Brief

    loading
    Top 10 Cyber Security Companies in APAC - 2024
    ON THE DECK

    Cyber Security 2024

    I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

    Read Also

    Digital Hands, Human Focus: Rethinking Productivity with Automation and AI

    Digital Hands, Human Focus: Rethinking Productivity with Automation and AI

    Samuel Budianto, Head Of Information Technology, Time International
    Transforming Cybersecurity Leadership in Critical Industries

    Transforming Cybersecurity Leadership in Critical Industries

    Joel Earnshaw, Senior Manager, Cybersecurity, Perenti
    The Blueprint behind Modernizing Branch Networks

    The Blueprint behind Modernizing Branch Networks

    Ronaldo S. Batisan, Senior Vice President - Branch Channel Management Head Of Union Bank Of The Philippines
    The Blueprint behind Modernizing Branch Networks

    The Blueprint behind Modernizing Branch Networks

    Ronaldo S. Batisan, Senior Vice President - Branch Channel Management Head Of Union Bank Of The Philippines
    Meeting Business Travel Demands with Intelligent Platforms

    Meeting Business Travel Demands with Intelligent Platforms

    Zamil Murji, Chief Technology Officer, Corporate Travel Management – Asia
    From Friction to Function: How Winc Turned Customer Feedback into Business Growth

    From Friction to Function: How Winc Turned Customer Feedback into Business Growth

    Cara Pring, Digital & Cx Director, Winc Australia
    Why Contact Centres are Becoming Strategic Hubs for Social Insight

    Why Contact Centres are Becoming Strategic Hubs for Social Insight

    Cindy Chaimowitz, GM Wholesale & Customer Service and Karen Smith, Head of Customer Service, Foodstuffs North Island
    Why Compliance Needs a Seat at the Strategy Table

    Why Compliance Needs a Seat at the Strategy Table

    David Koh, Head, Legal & Compliance (Singapore) and Operational Risk Management Country Lead, Perpetual Limited
    Loading...
    Copyright © 2025 APAC CIOOutlook. All rights reserved. Registration on or use of this site constitutes acceptance of our Terms of Use and Privacy and Anti Spam Policy 

    Home |  CXO Insights |   Whitepapers |   Subscribe |   Conferences |   Sitemaps |   About us |   Advertise with us |   Editorial Policy |   Feedback Policy |  

    follow on linkedinfollow on twitter follow on rss
    This content is copyright protected

    However, if you would like to share the information in this article, you may use the link below:

    https://cyber-security.apacciooutlook.com/cxoinsights/cracking-the-code-the-psychology-of-social-engineering-and-the-power-of-the-human-firewall-nwid-10099.html