Skip to content

Capability scale

The capability scale describes how organisational resilience changes as social engineering defence becomes more consistent, embedded, integrated, and adaptive. Use the descriptions below as behavioural references and to understand the changes needed to achieve stronger capability where the operating context requires it.

The scale represents increasing capability, but different workflows and operating conditions may align with different points on the scale. A single domain or organisation-wide rating is not required.

Required capability is determined by operating context, threat exposure, consequence, and applicable obligations rather than organisational preference. Where current capability does not meet the required capability, the gap should be addressed or formally managed through the organisation’s risk processes.

Ad hoc

Summary

Legitimacy is largely assumed. Sensitive actions depend heavily on perceived legitimacy, social confidence, and individual judgement. There is no consistent mechanism to verify claims of identity, authority, or intent independently of the request itself.

Observable behaviours

  • Staff avoid challenging people who appear confident, senior, familiar, busy, or helpful
  • High-risk requests move through informal channels including email, SMS, phone, chat, or face-to-face interaction without independent verification
  • Password resets and account recovery rely on weak identity assurance — security questions, caller-supplied details, or informal recognition
  • Unknown visitors, contractors, or couriers are accepted without independent validation of identity or work authorisation
  • Rogue USB drives or removable media are handled casually or ignored
  • Suspicious interactions are discussed locally rather than escalated
  • Tailgating and visitor drift occur without challenge
  • Protective marking, clearance handling, and contractor verification may exist administratively but remain weak operationally
  • Requests that invoke authority, urgency, or distress are acted upon without pause
  • Confirmed manipulation produces improvised response; staff decide during the incident who acts, what is stopped, and whether a payment, access change, or disclosure can still be prevented

Common resilience gaps

  • Authority overrides verification
  • Urgency compresses decision-making
  • Convenience replaces process
  • Familiarity becomes a substitute for identity assurance
  • Staff prioritise helpfulness over challenge
  • Physical legitimacy is assumed through appearance, uniform, or confidence
  • Sensitive access decisions rely on trust rather than evidence
  • Human-layer incidents are treated as user mistakes rather than operational failures
  • No mechanism exists to connect suspicious interactions across channels, functions, or time
  • Recovery depends on individual initiative; whether reliance on a compromised identity, account, supplier, or workflow stops turns on who notices and how confidently they act

Recognition indicators

Evidence of this pattern may include:

  • No retained evidence for sensitive actions — approvals are verbal, informal, or undocumented
  • Identity verification that relies on the requester’s own information — name, role, employee number — rather than an independent source
  • No consistent challenge or escalation expectation — staff resolve unusual requests individually without defined escalation paths
  • Visitor, contractor, and temporary access that is validated informally or not at all
  • Access and approval controls that exist for specific systems but are not joined across workflows
  • Awareness activity that has not changed observable workflow behaviour — staff know what social engineering is but have no procedure to follow when it happens
  • No reconstructable record of how past incidents were interrupted; actions, authority, and restoration decisions cannot be established afterwards

Strengthening toward Developing

The primary shift from Ad hoc toward Developing capability is the establishment of documented procedures for high-risk decision paths. Where Developing capability is required, high-risk decision paths should move from individual judgement toward defined process — not necessarily enforced process, but at least written process that staff can locate and reference. Relevant changes may include:

  • Documented verification procedures for sensitive actions including helpdesk resets, payment changes, and visitor access
  • A basic reporting channel that staff know exists
  • Approval requirements for sensitive actions that are written down, even if not consistently enforced
  • Initial awareness training that describes what social engineering looks like in the organisation’s specific context
  • A basic escalation route for confirmed manipulation that staff can locate, even where subsequent response remains informal
Developing

Summary

Procedures exist, but resilience remains fragile. Verification and escalation degrade under urgency, hierarchy, operational pressure, or convenience. The organisation has moved from no process to documented process, but the gap between written expectation and operational behaviour is significant.

Observable behaviours

  • Verification procedures exist but enforcement is inconsistent across teams and scenarios
  • Staff follow process during normal conditions but bypass controls when facing urgency, authority pressure, or time constraints
  • Finance call-backs or payment approval checks occur inconsistently — some staff follow the procedure, others do not
  • Reporting channels exist but suspicious activity is not consistently escalated — reports are made when staff feel confident the behaviour was genuinely suspicious, not as a default
  • Visitor management exists but enforcement depends on individual reception or facilities staff rather than systemic controls
  • Physical security and cyber security teams operate separately with limited coordination on shared threats
  • Exceptions are handled informally — requests that fall outside normal process are resolved by whoever receives them
  • QR-code deception, removable media abuse, and physical pretexting are rarely exercised or included in awareness scenarios
  • Protective marking and contractor verification are documented but inconsistently applied
  • Confirmed incidents are escalated through informal routes that usually reach relevant personnel, but response quality varies with availability and prior experience

Common resilience gaps

  • Procedures work during normal operations but degrade under pressure — the control only functions when staff feel no urgency to bypass it
  • Authority and urgency override process — senior requests, emergency framing, and distress reliably produce compliance without verification
  • Verification remains socially negotiable — a persuasive or persistent requester can obtain compliance that a less confident one would not
  • Physical and digital identity assurance remain disconnected — a visitor who has signed in at reception is not known to the IT function
  • Supplier and contractor trust is rarely reassessed after initial onboarding — access persists beyond active need
  • Cross-functional coordination is weak — finance, IT, HR, facilities, and legal handle related threats independently
  • Evidence exists in fragments but does not support end-to-end review of what happened across a sensitive transaction
  • Escalation culture varies significantly by team, manager, and business function — inconsistent even within the same organisation
  • Compromised trust is restored under operational pressure; a suspended supplier, account, channel, or workflow returns to use before evidence supports restoration

Recognition indicators

Evidence of this pattern may include:

  • Verification procedures that exist in a policy or playbook but cannot be consistently demonstrated in practice — audits reveal gap between documented expectation and actual behaviour
  • Approval workflows with informal bypass paths — exceptions are approved verbally, via chat, or by the initiator themselves under urgency
  • A reporting mailbox or button that exists but generates few reports relative to the organisation’s size and threat exposure
  • Visitor records that are completed inconsistently — some visits logged, others not — with no review process for anomalies
  • Limited evidence retention across sensitive workflows — actions are taken but the verification step is not recorded
  • Supplier verification that weakens during urgency or exception handling — normal process is suspended when a supplier claims a time-sensitive issue
  • Contractor or access lifecycle controls that operate at onboarding but are not reliably applied to access changes, role changes, or offboarding
  • Incident records capture what was detected but omit containment, suspension, and restoration decisions or reconstruct them from memory

Strengthening toward Established

The primary shift from Developing toward Established capability is enforcement. Where Established capability is required, documented processes should become embedded in operation, with controls applied consistently regardless of urgency, seniority, familiarity, or exception pressure. Relevant changes may include:

  • Verification steps that are built into workflow systems rather than relying on individual compliance
  • Exceptions that require explicit approval with documented rationale rather than informal resolution
  • Escalation paths that staff have practised — not only been told about
  • Supplier, contractor, and access lifecycle controls that are reviewed periodically, not only at onboarding
  • Tabletop exercises that test whether controls hold under realistic adversarial pressure — urgency, authority, distress, and familiarity
  • Evidence that sensitive actions were verified, not only that they were approved
  • Response procedures with named mobilisation and decision authority for material incident classes, practised in exercises rather than only documented
Established

Summary

Verification, escalation, and challenge behaviours are embedded into operational workflows and function consistently under pressure. Human-layer threats are treated as systemic operational risk rather than individual error. Controls hold when urgency, authority, or familiarity is applied.

Observable behaviours

  • High-risk workflows contain enforced verification gates that cannot be bypassed through individual judgement — the process requires completion, not just acknowledgement
  • Staff are explicitly supported when challenging suspicious behaviour, including requests from known, senior, or trusted individuals
  • Escalation pathways are understood, practised, and used — staff can demonstrate where to escalate without management direction
  • Supplier and contractor workflows include identity assurance requirements at onboarding, during engagement, and at offboarding
  • Visitor escorting and physical challenge expectations are operationalised — staff challenge unknown or unbadged individuals without feeling personally responsible for the refusal
  • Exception handling is governed — exceptions are documented, approved by a named authority, time-bounded, and reviewed for patterns
  • Tabletop exercises include behavioural, supplier, and physical scenarios that test whether controls hold under realistic adversarial pressure
  • Multiple business functions coordinate during relevant incidents — finance, IT, HR, facilities, and legal are involved where their domain is affected
  • Protective marking and sensitive workflow handling are operationalised where relevant to the organisation’s context
  • Verification procedures function independently of how the request is presented — urgency, authority, distress, and familiarity do not reliably produce bypass
  • Response procedures with defined mobilisation and decision authority exist for material incident classes, and active manipulation can be interrupted before value moves, access changes, or information is released

Common resilience gaps

  • Controls still vary between business units — embedded in core functions but weaker at operational edges
  • Physical and cyber coordination remains mostly incident-driven rather than proactive
  • Evidence collection is operational but requires manual correlation across systems
  • Complex multi-stage adversarial campaigns are not consistently exercised — single-scenario exercises are the norm
  • Supplier capability remains uneven — strong controls with tier-one suppliers but weaker with smaller or longer-standing relationships
  • Contractor access expiry and revalidation are documented but not consistently tested in practice
  • Strong controls exist in known high-risk workflows but weaken at less-scrutinised decision points
  • Restoration criteria remain generic; trust returns after a fixed pause or management decision rather than against evidence specific to the compromise

Recognition indicators

Evidence of this pattern may include:

  • Approval workflows that evidence both the request and the verification step — not only that an action was taken but that it was checked
  • Helpdesk identity assurance that goes beyond security questions or caller-supplied details — callback to an independently held number, ticket-based verification, or equivalent independent check
  • Out-of-band verification for supplier, payment, access, or account changes — confirmation through a channel the requester did not provide
  • Visitor escort enforcement that is consistent rather than individual — policy is applied by the process, not left to the judgement of individual staff members
  • Removable media handling controls that include a documented procedure and staff awareness — not only a policy that few have read
  • Exception management that produces a reviewable record — who approved, what rationale was given, when it expires
  • Escalation pathways that staff can locate and demonstrate without management direction — tested in exercises rather than only described in policy
  • Identity assurance for privileged, executive, or high-risk access that does not depend on secrets a caller can supply or a one-time code a user can be persuaded to relay
  • Contractor access that is reviewed and expired, with evidence of deprovisioning following engagement end
  • Exercise records showing response procedures practised under realistic pressure, including mobilisation outside normal operating hours

Strengthening toward Integrated

The primary shift from Established toward Integrated capability is integration and visibility. Where Integrated capability is required, embedded controls should be connected across the relevant operational surface — including physical, supplier, digital, and behavioural environments. Relevant changes may include:

  • Mapping social engineering techniques to the organisation’s own control areas and evidence sources — the analysis is the organisation’s to perform and maintain, and it establishes which techniques would exploit which gaps
  • Reviewing physical and cyber indicators together rather than in separate functions
  • Actively reducing OSINT exposure rather than only managing internal controls
  • Conducting multi-channel exercises that simulate realistic adversarial campaigns across more than one environment simultaneously
  • Establishing governance reporting that makes human-layer risk visible at leadership level — not only at operational level
  • Reviewing supplier capability as an ongoing assurance activity, not only at contract initiation
  • Formal trust suspension and evidence-based restoration for affected identities, counterparties, channels, and workflows, with related-target scoping applied during the campaign
Integrated

Summary

Behavioural threats are mapped to workflows, controls, evidence sources, governance, and assurance activities across the organisation. Human-layer risk is visible at leadership level and informs strategic decisions.

Observable behaviours

  • Social engineering tactics and techniques are mapped to specific control areas, ownership points, and evidence sources
  • Behavioural threat patterns are analysed across operational environments — not only after incidents but as a regular assurance activity
  • Human-layer risks appear in formal governance and assurance discussions — risk registers, board reporting, and assurance programs include human-layer threat dimensions
  • Physical and cyber indicators are reviewed together — a tailgating event is connected to network access logs; a phishing report is connected to physical access records
  • Supplier and third-party exposure is regularly assessed — capability expectations are embedded into supplier assurance activity
  • OSINT exposure is actively reduced — job advertisements, public profiles, metadata, and technical exposure are reviewed for reconnaissance value
  • Multi-channel exercises simulate realistic adversarial behaviour across physical, digital, supplier, and communication environments simultaneously
  • Human-layer risk is visible within enterprise risk discussions — not siloed within a security function
  • High-assurance workflows include enhanced verification for sensitive actions where the consequence of compromise warrants it
  • Trust in an affected identity, counterparty, channel, or approval path is formally suspended, communicated to staff who would otherwise rely on it, and held against documented pressure to resume
  • Plausible related targets are identified and protected before the same campaign can produce further compliance

Common resilience gaps

  • Mature environments still depend on manual analysis in areas where automated correlation would improve speed and consistency
  • Correlation between physical, supplier, and digital indicators does not always occur early enough to interrupt a campaign in progress
  • Advanced manipulation scenarios can outpace existing playbooks — exercises are realistic but may not reflect the most current adversarial techniques
  • Supplier capability varies significantly across the ecosystem — strong with primary suppliers, weaker at the edges of the supply chain
  • Governance identifies risk without always accelerating control uplift — risk is visible but remediation timelines can extend
  • Assurance is stronger centrally than at local operational edges — branch offices, remote teams, and embedded staff may operate at a lower effective level
  • Suspension and restoration remain incident-scoped; findings change the affected relationship without consistently changing the wider class of relationships

Recognition indicators

Evidence of this pattern may include:

  • A documented mapping between social engineering techniques and the controls, evidence sources, and ownership points that address them — not only a list of controls but an understanding of what each control defends against
  • OSINT exposure reduction activity that is periodic and evidenced — job advertisement reviews, document metadata hygiene, and public profile guidance are conducted on a defined cycle
  • Integrated assurance reviews where physical security, cyber security, HR, finance, and legal jointly assess human-layer risk rather than conducting independent reviews
  • Multi-channel verification procedures that are in use for sensitive workflows — not only documented but demonstrated in practice
  • Behavioural trend analysis across incidents, exercises, simulations, and suspicious reports — patterns are identified and actioned rather than each event being treated independently
  • Coordinated physical and cyber review — access logs, badge records, and network events are reviewed together following incidents
  • Supplier exposure assessment conducted as a regular assurance activity — not only at onboarding or contract renewal
  • Confidential escalation pathways that are accessible, tested, and used — evidenced by case records, not only by policy documentation
  • Governance-linked control uplift — capability findings and assurance results lead to documented improvement activity with owners and target dates
  • Coordinated insider-risk escalation pathways that involve HR, legal, security, and welfare functions
  • Restoration decisions recorded with the evidence relied upon and approved independently of the function under operational pressure to resume

Strengthening toward Adaptive

The primary shift from Integrated toward Adaptive capability is adaptivity. Where Adaptive capability is required, integrated controls and arrangements should change in response to emerging conditions. Relevant changes may include:

  • Establishing mechanisms that trigger workflow and control reassessment when new adversarial behaviours are identified — not only after a confirmed incident
  • Embedding supplier capability expectations into ongoing assurance rather than periodic assessment
  • Conducting cross-functional exercises that simulate blended, multi-stage campaigns and use the outcomes to directly update playbooks and controls
  • Moving governance reporting from describing risk to driving assurance adaptation — results change the control environment, not only inform it
  • Continuously challenging defensive assumptions rather than periodically reviewing established controls
  • Measuring recovery performance, including classification-to-interruption and suspension-to-restoration intervals, and using the results to improve response and restoration capability
Adaptive

Summary

Human-layer defence operates as a continuously adaptive organisational capability shaped by behavioural intelligence, operational learning, and changing adversarial conditions. The organisation does not wait for incidents to drive improvement — it anticipates change and adjusts proactively.

Observable behaviours

  • New adversarial behaviours — including changes to technique sophistication, targeting patterns, and the reliability of identity indicators — trigger workflow and control reassessment without waiting for a confirmed incident
  • Lessons learned directly and demonstrably influence operational uplift — the path from incident or exercise to control change is short, documented, and evidenced
  • Exercises simulate blended, multi-stage adversarial campaigns that combine digital, physical, supplier, and behavioural vectors simultaneously
  • Human-layer resilience is visible within strategic risk discussions and informs senior leadership decisions about operational change, supplier relationships, and workforce practices
  • Behavioural indicators influence operational decisions in near-real time — patterns are identified and acted on before they escalate to confirmed incidents
  • Supplier capability expectations are embedded into continuous assurance — not only assessed at contract points but monitored as an ongoing operational activity
  • Physical, behavioural, supplier, and digital indicators are treated as part of the same adversarial surface — there is no functional separation between physical security, cyber security, and human-layer risk management
  • Defensive assumptions are continuously challenged and refined — the organisation actively seeks to identify where current controls would fail rather than assuming established controls remain sufficient
  • High-assurance environments can integrate adaptive verification, continuous personnel assurance, or dynamic access controls into broader resilience programs where the operational and risk context warrants it. For entities subject to personnel security mandates such as the PSPF, ongoing assessment of personnel suitability is a baseline obligation; the Adaptive characteristic is the integration of that assurance into adaptive human-layer operations
  • Recovery adapts during an active campaign; scoping, suspension, protective action, and restoration criteria change as observed campaign behaviour changes

Common resilience gaps

Even at Adaptive capability, residual gaps remain. Recognising them is itself a characteristic of adaptive operation:

  • Novel adversarial tradecraft can still create temporary exposure before controls are updated — the gap is shorter and better managed than at earlier points on the scale, but not eliminated
  • Major organisational or supplier change can introduce new trust assumptions that temporarily outpace the assurance program
  • Over-automation of detection and response can weaken human judgement and situational awareness if not carefully governed — technology must support, not replace, human-layer resilience
  • Emerging technologies, platforms, or operational workflows can outpace established controls — new capabilities require new control consideration
  • Local practice can drift from strategic assurance expectations — central arrangements may be Adaptive while some operational edges remain Established
  • Defensive assumptions can become stale if the challenge process itself becomes routine rather than genuinely adversarial
  • Restoration confidence can outpace evidence where a long-standing relationship carries organisational attachment; pressure to resume remains social as well as operational

Recognition indicators

Evidence of this pattern may include:

  • A defined mechanism for triggering control and workflow reassessment in response to new adversarial behaviours — with evidence that it has operated and produced changes, not only that it exists as a policy commitment
  • Integrated behavioural analysis that draws on incidents, exercises, simulations, suspicious reports, OSINT findings, threat intelligence, and supplier assurance data — correlated across sources rather than reviewed in isolation
  • Continuous control uplift evidenced by a documented improvement cycle — controls change regularly in response to operational learning, not only annually in response to scheduled review
  • Advanced supplier assurance that includes behavioural indicators and capability expectations, not only contractual security clauses and periodic assessments
  • Strategic human-layer risk reporting that informs senior leadership decisions — board-level or equivalent visibility that influences organisational strategy, not only security program management
  • Cross-functional resilience exercises that involve senior leadership participation, produce governance-level findings, and directly drive control changes with named owners and defined timeframes
  • Governance-linked assurance adaptation — assurance findings change the control environment within a defined and demonstrably short cycle rather than being queued for annual review
  • Emerging scenario playbook refinement that occurs in response to actual threat intelligence and exercise findings — playbooks are living documents with a tracked update history, not static references
  • Adaptive verification models that respond to changes in threat conditions, the reliability of identity indicators, and operational context — verification requirements increase when conditions change, not only when incidents occur
  • Dynamic access assurance applied in high-risk contexts — access rights reflect current operational need and are actively maintained rather than passively reviewed
  • Measured recovery performance with a tracked history of changes to mobilisation, interruption, suspension, scoping, or restoration criteria

The guide below summarises the primary organisational shifts between adjacent points on the scale. Progression is not linear across capability domains, and organisations are not expected to move every workflow toward Adaptive capability. Where the operating context, threat exposure, consequence, or applicable obligations require stronger capability, the identified gap should be addressed or formally managed. SECA helps organisations identify controls relevant to the conditions limiting that improvement.

ProgressionPrimary shiftPotential enablers
Ad hoc → DevelopingFrom individual judgement to documented processVerification procedures written down; reporting channel established; basic awareness training delivered
Developing → EstablishedFrom documented process to enforced and embedded processWorkflow systems enforce verification steps; exceptions require documented approval; controls tested under pressure in exercises; incident mobilisation and decision authority defined
Established → IntegratedFrom embedded controls to connected and integrated controlsThe organisation maps adversarial techniques to its own controls and evidence sources; physical and cyber coordination; OSINT reduction; governance visibility; multi-channel exercises; trust suspension and evidence-based restoration in use
Integrated → AdaptiveFrom integrated controls to continuously adaptive controlsReassessment triggered by new conditions, not only incidents; supplier capability embedded in ongoing assurance; governance drives adaptation, not only reporting