Leadership · 3 September 2026
The human factor and social engineering
Most successful intrusions do not start at a firewall. They start in a conversation, an email or a hurry.
By Rafael Núñez Aponte. Published on 3 September 2026. Updated on 4 September 2026.
Original text in Spanish. Read the original Spanish version

I keep seeing incidents that do not start in a software vulnerability. They start in a message that looks urgent, in a boss who “cannot talk now” and in an employee who does not want to look bad. Social engineering is not magic. It is the design of haste.
Why notices are not enough
A “do not click” poster does not compete with a payroll that is paid today or with a supplier that threatens to cut the service. Human defence is a verification procedure, not a campaign. If verifying a superior is frowned upon, the attacker already has internal policy in their favour.
Hacker culture, read seriously, teaches exactly that: the adversary does not attack the system you imagine; it attacks the habit you do not question. A tone of authority, an informal channel and a “just this once” exception are enough to open a door the perimeter believed closed.
How haste operates
- Urgency is manufactured: a transfer, an access, a silence that “cannot wait”.
- Authority is manufactured: the name of a director, a lawyer, a critical supplier.
- An exception to the procedure is requested, not a technical assault.
- The fear of looking bad is exploited more than the fear of the incident.
Three habits of an organisation that is hard to deceive
- Confirmation channels for money, access and account changes. Always. No exceptions for “this time”.
- Cultural permission to doubt. The person who asks is not exposed to ridicule.
- Drills that teach, not that hunt. The aim is to reduce verification time, not to publish a ranking of fools.
Board questions
- Which payments, accesses or supplier changes can be made without a second confirmation channel?
- Is an employee who doubts an order from the chair protected or exposed?
- When was the last social-engineering drill that ended in learning and not in humiliation?
- Does senior leadership submit to the same procedure as everyone else, or is it the permanent exception?
References
- NIST SP 800-50: Building an Information Technology Security Awareness and Training Program. NIST. Accessed: 2026-09-04. El énfasis en simulacros, confirmación por un segundo canal y el mismo procedimiento para la alta dirección se plantea como cultura de concienciación, no como un incidente real.