SAINTCON 26 · Session

What Social Engineers Know About You That Your Security Team Doesn't

Speakers
  • Lee Anderson · Cybersecurity professional focused on human-centered defense, social engineering, and security education

The social engineer studied your users more carefully than your security team did — and most awareness training is designed to prove that point. Security training uses urgency, authority, and fear to compel behavior change; malicious social engineering uses the same three mechanisms for the exact opposite purpose, because they were engineered to bypass skepticism, not activate it. After 16 years on the attacker's side — red team work, phishing simulations, social engineering assessments — I've found that the most important thing that experience revealed isn't how to attack people, it's how not to train them. This briefing covers the psychological mechanics social engineers depend on: why urgency bypasses skepticism, how authority disarms critical thinking, why helpfulness is exploitable, and what actually interrupts these patterns — making the case that curiosity, not compliance, is the behavior worth training.

← Full schedule

Security Briefing

Join the mission log

Occasional emails with training announcements, CFP windows, and what's launching at SAINTCON. No spam, no selling your address. Ever.

By subscribing you agree to the Privacy Policy.