Skip to content

Insider Threat & Social Engineering Tactic Overlap

A trusted, partially trusted, compromised, coerced or former insider can use each social engineering tactic differently from an external actor by combining it with legitimate access, internal knowledge, process familiarity or workplace relationships that an outsider would otherwise need to fabricate. The table below illustrates how those advantages can change the use of each tactic.

SE TacticExample Insider Threat Overlap
SE-T001 ImpersonationAn insider may present as another staff member, manager, executive, support function, vendor or authority figure to influence approvals or bypass controls.
SE-T002 Trust ExploitationAn insider may abuse existing workplace relationships, familiarity, team trust or informal access pathways to obtain something a stranger asking the same way would not.
SE-T003 Authority & Obligation PressureAn insider may pressure colleagues using hierarchy, operational responsibility, role authority or perceived obligation, often without raising the suspicion an external impersonator would trigger.
SE-T004 Urgency, Scarcity & Consequence FramingAn insider may create urgency, consequence or time pressure to bypass verification, review or normal process controls.
SE-T005 Process ManipulationAn insider may exploit workflow gaps, approval ambiguity, exception handling, weak ownership or inconsistent process enforcement they already know about from working inside the process.
SE-T006 Information HarvestingAn insider may collect internal operational, personnel, supplier, facility or system information to support later activity, without needing the reconnaissance an external actor would require.
SE-T007 Credential & Identity AccessAn insider may influence staff to share credentials, approve MFA requests, reset passwords, grant access or weaken identity controls.
SE-T008 Technical DeceptionAn insider may use fake internal notices, portals, files, system messages, links or technical artefacts to create legitimacy.
SE-T009 Legitimacy & Context MirroringAn insider may use organisational knowledge, terminology, timing, relationships and internal context to make requests appear normal or authorised.
SE-T010 Multi-Channel ReinforcementAn insider may combine email, chat, phone calls, collaboration tools, physical interaction or supplier channels to reinforce legitimacy.
SE-T011 Emotional InfluenceAn insider may use personal relationships, guilt, fear, sympathy, loyalty, conflict avoidance or emotional pressure.
SE-T012 Reciprocity, Incentive & BaitingAn insider may offer assistance, convenience, incentives, favours or access to encourage unsafe behaviour, creating an obligation that gets called in later.
SE-T013 Secrecy, Isolation & Commitment EscalationAn insider may encourage secrecy, isolate individuals from oversight or escalate requests gradually over time, with each step small enough on its own to avoid scrutiny.
SE-T014 Physical Access FacilitationAn insider may assist unauthorised physical access, enable tailgating, introduce rogue devices or bypass physical security controls.
SE-T015 Third-Party & Supply Chain ExploitationAn insider may abuse supplier, contractor, vendor, consultant, partner or external relationship trust that an external attacker would otherwise have to fabricate.