Skip to content

Framework Adoption

Pretext8 explains how social engineering attacks work by examining attacker behaviour, techniques, and the human factors that make them effective. It then turns that understanding into practical controls organisations can implement, assess, evidence, and improve.

Pretext8 uses four components to describe attacker behaviour, the methods used, and the human mechanisms that make those methods effective. The components are related but serve different purposes. They are described below.

ComponentDescription
TacticsThe approach used by the threat actor, such as impersonation, authority pressure, process manipulation, or another tactic.
TypesHow the activity is commonly named or recognised in practice, such as phishing, vishing, pretexting, business email compromise, or physical intrusion.
Technique CatalogueHow the tactic is carried out through a specific and observable method.
Manipulation LeversWhy the request influenced a target, including factors such as authority, urgency, trust, familiarity, or obligation.

Pretext8 is applied as a continuous review and improvement cycle. The framework moves from understanding organisational context and threat exposure, through capability review, into control assessment and strengthening through SECA, followed by reassessment.

Pretext8 framework adoption cycle

1. Establish operating context and threat exposure

The organisation identifies material workflows, sensitive actions, relevant threat exposure, regulatory or contractual requirements, and the consequences of successful manipulation.

Operating Context informs the capability required and how control requirements are prioritised and applied. The decision is led by three considerations:

Exposure considers the opportunity an attacker has to identify targets, gather context, build a convincing approach, and reach the organisation through relevant channels.

Consequence considers the impact of successful manipulation in the workflows a control domain protects.

Attacker motivation considers what the attacker is seeking to achieve and how that objective influences target selection and the pretext used.

Pretext8 acknowledges that consequence and exposure vary between organisations. However, the underlying attack patterns and framework principles remain consistent.

2. Review current and required capability

The Capability Review establishes current and required capability to understand how effectively the organisation resists, responds to, and recovers from social engineering in practice.

Relevant Capability Domains are reviewed against observed behaviour and available evidence, particularly under operational pressure, during exceptions, and at points of weakness.

The Capability Scale provides behavioural reference points from Ad hoc through Adaptive.

The outcome is an evidence-based view of current capability, required capability, and any material gaps that require improvement, further investigation, or risk management.

Different workflows and operating conditions may align with different points on the capability scale. Capability results are not averaged, as strength in one area does not offset a material weakness in another.

3. Assess and strengthen controls through SECA

The Social Engineering Control Assessment (SECA) is used to determine which controls apply, assess how those controls are implemented and evidenced, identify control gaps or weaknesses, and determine the changes required to address the identified capability gaps. See Control Assessment.

Capability Review findings provide context for SECA by identifying the workflows, operating conditions, and weaknesses that require stronger control. The same capability gap may require different controls depending on its cause.

Where improvement is required, the organisation implements or strengthens the relevant controls, assigns ownership, and defines the evidence needed to demonstrate that the intended outcome has been achieved.

The SECA is intended to be applied across the parts of an organisation that own or support workflows exposed to social engineering risk. Depending on the organisation, this may involve teams such as Finance, IT, service desk, Facilities, Reception, Procurement, Human Resources, Legal, Operations, or other business units with relevant responsibilities.

Control ownership is assigned per control rather than per domain, allowing controls within the same domain to sit across different operational functions.

4. Reassess

Control effectiveness and organisational capability are reassessed on a defined cadence and after material change.

Reassessment determines whether the controls operate effectively and whether the required capability is demonstrated in practice. Implementing a control does not by itself demonstrate improved capability.

Reassessment should consider changes to operating context, threat exposure, sensitive workflows, supplier relationships, technology, workforce conditions, and significant incidents or near misses.

As part of this process, the organisation reviews whether the original context, scope, assumptions, and required capability remain current.