Skip to content

Operating Context & Threat Exposure

Social engineering tactics are used across every sector, from sole traders and schools to large enterprises, defence contractors, and military organisations. What changes between those environments is the potential consequence of a successful attack, the exposure available to an threat actor, and the way controls need to be applied. The underlying tactics remain broadly consistent, while threat actor motivation and organisational context shape how those tactics are used.

Operating context establishes the conditions in which social engineering risk is assessed and controls are applied. In Pretext8, this includes the workflows and sensitive actions in scope, the roles involved in those workflows, relevant threat actor motivations, the consequence of successful manipulation, exposure to threat actor research and contact, regulatory or contractual requirements, and external dependencies that influence risk.

Assessment should focus on the specific workflow, sensitive action, and roles involved while noting that different teams in the same organisation can face very different exposure and consequence, and their control needs differ accordingly.

The operating context established here informs how Pretext8 control requirements are applied and assessed through the Social Engineering Control Assessment (SECA). See SECA for more information.

Operating context factors

Exposure describes the opportunity a threat actor has to identify targets, gather context, build a credible pretext, and make contact.

Exposure can arise from information that is publicly or indirectly discoverable, including staff directories, organisational charts, procurement notices, job advertisements, social media, conference participation, supplier relationships, and observable site activity. Individually minor details may also become significant when combined, allowing a threat actor to build a more credible picture of people, roles, relationships, and internal processes.

Exposure also depends on the channels through which a target can be contacted. Public phone lines, shared inboxes, service desks, collaboration platforms, SMS, social media, and physical entry points can all create opportunities for social engineering activity.

Exposure is not distributed evenly across an organisation. Roles that handle payments, account recovery, privileged access, recruitment, executive support, reception, or supplier interaction may present greater opportunity because of the information they hold or the actions they can perform.

The consequence of successful manipulation depends on what the targeted workflow, action, or role enables. Outcomes range from financial loss and disclosure of sensitive information to compromise of privileged accounts, unauthorised physical access, regulatory penalty, and harm to customers or downstream organisations.

Consequence should also account for what an action enables next. A request that appears low impact in isolation, such as an information disclosure, password reset, account recovery, or visitor admission, may create the conditions for a more significant compromise later in the attack path.

Reversibility and detection time also matter. A fraudulent payment recalled within the hour has limited impact. Persistent access that goes unnoticed for months does far more damage, even when the interaction that granted it lasted only minutes.

Regulatory and contractual obligations raise consequence where a compromise triggers mandatory notification, breaches a contract clause, or affects accreditation or eligibility to hold sensitive work.

Threat actor motivation and target attractiveness

Section titled “Threat actor motivation and target attractiveness”

Threat actor motivation determines which people, workflows, and relationships are targeted, and how the pretext is built. Financially motivated actors may focus on payment workflows, supplier bank detail changes, account recovery, and other actions that provide direct financial return. Espionage, foreign interference, and access-driven activity often involve longer relationship building, patient information gathering, and repeated contact.

Target attractiveness is the value a threat actor places on what a target can provide: money, sensitive information, privileged systems, physical access, or a route into another organisation. It works alongside exposure. A highly visible role with little to offer may attract little attention, and a low-profile role that approves payments or holds privileged access may be deliberately sought out.

Size is a poor guide to attractiveness. A small organisation that handles high-value transactions, holds sensitive information, or sits inside a larger supply chain can be a deliberate target in its own right.


The following considerations do not sit alongside exposure, consequence, and attacker motivation as core operating context factors, but they can materially shape how those factors apply in practice.

Suppliers, contractors, consultants, and managed service providers often hold trusted access, privileged knowledge, or established relationships with internal staff. Requests arriving through those relationships usually receive less scrutiny than contact from strangers, which makes a third party an efficient indirect route into the organisation.

Third parties can also expose the organisation indirectly. Public references to clients, project announcements, staff profiles, technology, or service arrangements may provide useful context for building a convincing pretext, even where the organisation itself has disclosed very little.

The risk runs downstream as well. Where an organisation provides access, information, or trusted services to others, a successful attack against it can reach those partners.

In defence, national security, critical infrastructure, and other high-assurance environments, consequence extends to operational capability, essential services, public safety, and sovereignty. State-sponsored activity may involve sustained targeting, including attempts to establish access or relationships for later use.

Information aggregation is particularly relevant in these environments, as individually low-sensitivity details about personnel, projects, suppliers, locations, and schedules can become significantly more useful to a threat actor when combined. Contract notices and project announcements can reveal where capability is being developed, while professional profiles that disclose clearance levels or programme involvement may help identify personnel with access to sensitive environments or information.

Cleared personnel and contractors already hold legitimate access and trusted relationships. An external actor may seek to recruit, coerce, or unwittingly use them, which brings insider risk and foreign interference into operating context for these environments. The relationship between social engineering and insider threat is covered in Insider Threat Overlap.