Insider Threat & Social Engineering Tactic Overlap
A trusted, partially trusted, compromised, coerced or former insider can use each social engineering tactic differently from an external actor by combining it with legitimate access, internal knowledge, process familiarity or workplace relationships that an outsider would otherwise need to fabricate. The table below illustrates how those advantages can change the use of each tactic.
| SE Tactic | Example Insider Threat Overlap |
|---|---|
| SE-T001 Impersonation | An insider may present as another staff member, manager, executive, support function, vendor or authority figure to influence approvals or bypass controls. |
| SE-T002 Trust Exploitation | An insider may abuse existing workplace relationships, familiarity, team trust or informal access pathways to obtain something a stranger asking the same way would not. |
| SE-T003 Authority & Obligation Pressure | An insider may pressure colleagues using hierarchy, operational responsibility, role authority or perceived obligation, often without raising the suspicion an external impersonator would trigger. |
| SE-T004 Urgency, Scarcity & Consequence Framing | An insider may create urgency, consequence or time pressure to bypass verification, review or normal process controls. |
| SE-T005 Process Manipulation | An insider may exploit workflow gaps, approval ambiguity, exception handling, weak ownership or inconsistent process enforcement they already know about from working inside the process. |
| SE-T006 Information Harvesting | An insider may collect internal operational, personnel, supplier, facility or system information to support later activity, without needing the reconnaissance an external actor would require. |
| SE-T007 Credential & Identity Access | An insider may influence staff to share credentials, approve MFA requests, reset passwords, grant access or weaken identity controls. |
| SE-T008 Technical Deception | An insider may use fake internal notices, portals, files, system messages, links or technical artefacts to create legitimacy. |
| SE-T009 Legitimacy & Context Mirroring | An insider may use organisational knowledge, terminology, timing, relationships and internal context to make requests appear normal or authorised. |
| SE-T010 Multi-Channel Reinforcement | An insider may combine email, chat, phone calls, collaboration tools, physical interaction or supplier channels to reinforce legitimacy. |
| SE-T011 Emotional Influence | An insider may use personal relationships, guilt, fear, sympathy, loyalty, conflict avoidance or emotional pressure. |
| SE-T012 Reciprocity, Incentive & Baiting | An insider may offer assistance, convenience, incentives, favours or access to encourage unsafe behaviour, creating an obligation that gets called in later. |
| SE-T013 Secrecy, Isolation & Commitment Escalation | An insider may encourage secrecy, isolate individuals from oversight or escalate requests gradually over time, with each step small enough on its own to avoid scrutiny. |
| SE-T014 Physical Access Facilitation | An insider may assist unauthorised physical access, enable tailgating, introduce rogue devices or bypass physical security controls. |
| SE-T015 Third-Party & Supply Chain Exploitation | An insider may abuse supplier, contractor, vendor, consultant, partner or external relationship trust that an external attacker would otherwise have to fabricate. |