New Blog
The Rise in Social Engineering: Why ISO 27001 matters more than ever
Social engineering is on the rise, with attackers increasingly targeting employees through phishing, impersonation, fake payment requests and AI-powered scams.
This resource on the importance of social engineering pen testing explains why people are now a key cyber security frontline and how ISO 27001 helps organisations reduce risk through security awareness, access controls, supplier management, clear policies and incident response.


The New Frontline: Your Employees
We picture a cyber-attack as something technical. A shadowy figure tapping away on a keyboard exploiting weaknesses in businesses' systems. The reality is a little closer to home. Instead of trying to break in through the virtual front door, threat actors are targeting the business’ actual front door.
This attack angle is called Social Engineering and it can be very effective. The art of manipulating people to gain access to information, data, money, credentials, etc.
Common methods used by threat actors include:
· Phishing emails that look like legitimate requests
· Fake invoices or payment requests (Business Email Compromise)
· Impersonation of senior executives or suppliers
· Phone-based scams and even AI-generated voice cloning
These attacks are effective because they exploit human behaviour, trust, urgency and authority.
And It's working!
Studies show that 36% of incidents started with social engineering tactics.
Why is Social Engineering on the Rise?
There are several reasons why these attacks are becoming more frequent and more successful:
Remote and Hybrid Working: Employees are no longer protected by a traditional office perimeter. Communication is more digital and easier to fake.
Public Information: Attackers can gather employee details from LinkedIn, company websites, and data breaches to craft highly convincing, targeted attacks.
AI-Powered Attacks: Threat actors are now using AI to generate realistic emails, messages, and even voices, making attacks harder to detect.
Why Traditional Security Isn't Enough
Businesses already invest in technical controls like:
· Email filtering
· Endpoint protection
· Vulnerability scanning and Penetration testing
However, these solutions can’t stop an employee from:
· Clicking a convincing phishing link
· Approving a fraudulent payment
· Sharing credentials with someone they believe is legitimate.
This is where all the money spent on security falls short and where your employees are potentially opening the door to a threat actor.
Where ISO 27001 Makes The Difference
ISO 27001 is not just a Technology Certification. It goes beyond that. It helps organisations build a culture of security, where employees understand their role in protecting information and know how to respond when something feels wrong. In the context of social engineering, this is critical because the strongest firewall in the world cannot protect a business if people are not prepared to recognise and challenge suspicious requests.
How ISO 27001 Helps Protect Against Social Engineering
ISO 27001 addresses the human factor in 5 key areas within the standard.
Security Awareness
· Regular training helps employees recognise phishing emails, fake requests, impersonation attempts, and other common social engineering tactics.
· Awareness campaigns reinforce the need to pause, question urgency, and verify unusual requests before taking action.
Access Control
· Strong access controls ensure employees only have access to the information and systems they genuinely need.
· Multi-factor authentication adds an extra layer of protection if credentials are stolen through phishing or impersonation.
· Regular access reviews help remove unnecessary permissions and reduce the damage caused by compromised accounts.
Supplier and Third Party
· Supplier security checks help ensure third parties follow appropriate information security practices.
· Clear contractual requirements can define how suppliers handle sensitive information and report security incidents.
Incident Management
· Defined reporting routes make it easier for employees to raise concerns quickly when something feels suspicious.
· Incident response procedures help organisations contain and investigate social engineering attempts before they escalate.
Information Security Policy
· A clear information security policy sets expectations for how employees should handle information securely.
· Policies provide guidance on acceptable use, password management, and reporting suspicious activity.
Final Thoughts
Social engineering represents a fundamental shift in cyber security, one where people are both the target and the solution.
By implementing ISO 27001, organisations can move beyond purely technical defences and adopt a comprehensive, people-focused approach to security.
In today’s threat landscape, that’s not just best practice; it’s essential.
Worried your team could be the next target?
Social engineering attacks are becoming harder to spot, but the right security framework can help.
Find out how it can strengthen your processes, protect your people and reduce the risk of human error. Get ISO 27001 ready today with a free consultation at WorkNest.
Share your challenge with us and we’ll help you find the right level of support for your business.














