Social Engineering Control Assessment
Control Assessment last updated: September 2026
The Social Engineering Control Assessment (SECA) groups social engineering controls into domains for implementation, assessment, and assurance. Ownership is assigned at the individual control level, recognising that responsibility may sit across finance, HR, legal, security, and other business functions.
SECA can be used after a capability review or directly alongside an organisation’s existing risk and assurance methods. Before assessing controls, define or reference the workflows, sensitive actions, organisational boundaries, threat exposure, consequences, and applicable obligations in scope. Use this context to determine which controls apply.
Note: Capability review findings can help focus SECA. SECA findings can also provide evidence for later capability reviews. Implementing a control does not by itself demonstrate improved capability. See Capability Review
Control domains
Section titled “Control domains”| Prefix | Control domain | Controls | Scope |
|---|---|---|---|
| GOV | Governance, Assurance & Documentation | 8 | Establishes and governs organisational requirements for social engineering defence, including control ownership and resourcing, control deviations, lessons learned, authorised testing and simulation, risk integration, threat and exposure assessment, and the identification of high-consequence decision paths. |
| IDA | Identity & Access Assurance | 13 | Protects identity-dependent actions and access through identity verification, helpdesk and account recovery controls, multi-factor authentication, push-based MFA safeguards and phishing-resistant authentication, credential handling, identity indicator reliability and adaptive verification, trusted identity records, authenticator lifecycle controls, protection of privileged and high-impact identities, application consent governance, and authorised identity provisioning. |
| FST | Finance, Supplier & Third-Party Controls | 11 | Protects financial, procurement and third-party processes through approval and segregation controls, procurement workflow and payment-obligation integrity, supplier and customer record integrity, third-party access and contractor verification, non-standard value-transfer safeguards, software and update source verification, payee and payment-destination verification, external support and remote-session assurance, payroll change verification, and third-party legitimacy checks. |
| AVE | Authority, Verification & Escalation | 15 | Protects consequential requests and decisions through controlled approval workflows, authority verification, out-of-band and layered or step-up verification, off-channel safeguards, governed exceptions, out-of-hours escalation, crisis and emergency verification, legal and regulatory request handling, stakeholder request verification, reporting and escalation, approval record integrity, safe holds, delegated and representative authority, and degraded-mode controls. |
| MPE | Messaging, Platform & Endpoint Safety | 6 | Applies technical safeguards to social engineering delivery surfaces, including email and domain security, malicious links and attachments, collaboration platforms, browsers and endpoints, removable media, and permissions that could allow protective security controls to be disabled or overridden. |
| DTM | Detection & Monitoring | 3 | Ensures relevant systems and workflows provide the telemetry needed to support social engineering detection and investigation, that this event data remains available when required, and that monitoring arrangements provide appropriate administrative, physical and technical coverage. |
| IRR | Incident Response, Containment & Trust Recovery | 5 | Integrates social engineering into incident response arrangements and supports rapid interruption of active interactions, containment of affected identities and trust relationships, controlled restoration of trust, post-recovery monitoring, and protection of related targets during broader campaigns. |
| PHY | Physical, Site & Asset Protection | 10 | Protects physical trust boundaries through access control, visitor management, reception escalation, asset release and logistics safeguards, temporary and off-site environment controls and situational security briefings, secure workspaces, physical reconnaissance reduction, network connection-point protection, and physical credential lifecycle management. |
| IEX | Information Exposure & Disclosure Control | 3 | Reduces information that can enable social engineering through secure information disposal and sanitisation, management of public information exposure and reconnaissance value, and safeguards against inappropriate verbal or conversational disclosure. |
| PHM | Personnel & Human Risk Management | 9 | Builds personnel resilience through social engineering awareness and reporting, personal-channel targeting resilience, coercion and duress reporting, targeted role-based training, personnel trust reassessment and withdrawal, protection for good-faith challenge, organisational communication conventions, and awareness of suspicious devices and removable media. |