This brief is for people who have to make decisions about cyber risk without being cyber specialists. No jargon is assumed and none is used without explanation. It covers what has actually changed in social engineering, what has not, and the small number of things that make a measurable difference.
The headline: this is the attack, not one of them
It is tempting to treat social engineering as one item on a long list of threats. The UK data says otherwise.
Phishing was experienced by 38% of businesses and 25% of charities in the last year, making it by far the most common breach type. Among organisations that were breached, 69% rated phishing as the most disruptive thing that happened to them. And phishing accounts for 93% of all cyber crime experienced by UK businesses.
The more striking figure is how dominant it has become. Among breached organisations, the proportion experiencing phishing and nothing else rose from 45% to 51% for businesses, and from 46% to 57% for charities. For most UK organisations, the cyber threat is not a spectrum. It is people being deceived.
Meanwhile, ransomware was reported by just 1% of businesses, down from 3%. That does not mean ransomware is unimportant, because its impact when it lands is severe and the survey's cost figures understate rare catastrophic events. It does mean that budget and attention allocated in proportion to headlines will be allocated wrongly.
What has genuinely changed
The attack moved to the phone
The most significant shift is that the highest-impact social engineering increasingly does not arrive by email at all. It arrives as a phone call.
The reason is simple. Organisations have spent fifteen years training people to be suspicious of email and deploying technology to filter it. Almost nobody has done the equivalent for voice. A convincing caller reaches a human being with no filter in between.
AI removed the tells people were taught to spot
For two decades, awareness training taught people to look for poor spelling, awkward phrasing and generic greetings. Those signals came from attackers writing in a second language at scale. Generative AI has eliminated them at essentially zero cost.
This is not a minor inconvenience. It invalidates the central lesson of most awareness training ever delivered. Worse, it leaves staff with a false confidence: they believe they can spot a phishing message because they have been taught what one looks like, and what one looks like has changed.
The practical consequence for leadership is that "spot the fake" is no longer a viable defence. The question a member of staff can still reliably answer is not "is this message genuine?" but "have I verified this request through a channel the requester did not choose?"
Voice cloning made authority itself untrustworthy
Cloning a recognisable voice now requires a short sample, and executives who appear on podcasts, webinars, conference panels or company videos have supplied one publicly. Reported attacks follow a consistent shape: a finance team member receives an urgent call from a voice they recognise, authorising a payment or a change of bank details, usually with a plausible reason for the deviation from process.
The defence is uncomfortable for senior people, because it means accepting that your voice is no longer proof of your identity, and that staff should be permitted, indeed required, to refuse an instruction from you until it is verified another way. If your organisation has a culture in which challenging an executive is career-limiting, you have a control gap that no technology will close.
The help desk became a front door
The most instructive UK incidents of recent years were the 2025 attacks on major retailers including Marks & Spencer and the Co-op, which prompted an unusually direct warning from the NCSC.
What made them instructive was where they started. Rather than breaking in, attackers telephoned IT help desks impersonating employees who had lost access, and persuaded support staff to reset credentials and multi-factor authentication. In at least one publicly reported case the entry point was a third-party IT provider's help desk rather than the retailer's own.
Three lessons for a board:
1. Your identity recovery process is a security control, and it is probably owned by whoever runs support rather than whoever runs security.
2. Help desk staff are trained and measured on being helpful, which is precisely the instinct being exploited. This is an incentive problem, not a competence problem.
3. Your suppliers' help desks are part of your attack surface. Yet only 15% of UK businesses review the cyber risks posed by their immediate suppliers and 6% look at the wider supply chain.
Attacks moved inside your trusted tools
Staff have learned that external email is risky. They have not learned that a message in the company chat tool might be. Attackers increasingly operate inside collaboration platforms, where a message appears in a space that feels internal and vetted.
What has not changed
The underlying psychology is identical to what it was twenty years ago. Every social engineering attack manufactures some combination of urgency, authority and isolation: this must happen now, it comes from someone who can direct you, and you should not check with anyone else.
That is genuinely useful news, because it means the defence does not need updating every time the technology does. Any request combining those three pressures deserves verification, whatever the channel and however convincing the delivery.
What actually reduces the risk
Verification processes that cannot be talked around
The shift is from detection to process. Do not ask people to judge authenticity. Give them a mandatory step that removes the need to judge.
For payments and bank detail changes: a call back on a number from your own records, never a number supplied in the request. For identity recovery: proof that does not rely on information an attacker could research or a manager who can be impersonated. For anything urgent and unusual: a named second approver.
The test of these processes is not whether they exist. It is whether a sufficiently senior, sufficiently impatient caller can get them waived. If they can, they are guidance rather than controls.
Permission to say no, granted visibly and from the top
This costs nothing and is the control most often missing. Staff need to know, from the chief executive rather than from a policy document, that verifying a request from a senior person is expected behaviour and that no one will be penalised for the delay.
Make reporting the trained behaviour
The most useful evidence on this comes from a fifteen-month study at ETH Zurich covering around 14,000 employees, which found that embedded training delivered after someone clicked a simulated phish did not improve resilience and in some conditions appeared to make people more susceptible, partly through a false sense of security.
What did work was giving people a simple way to report suspicious messages. Reports were accurate around 68% of the time for phishing, the most active reporters exceeded 80%, and the researchers found no evidence of reporting fatigue. Crowd-sourced reporting let the organisation detect real campaigns quickly.
The implication is that the metric worth improving is not the click rate but the report rate and the time to first report. One person reporting a novel campaign within minutes protects everyone else.
Exercise the decision, not the inbox
Only 22% of UK businesses test staff with mock phishing exercises, and only 19% run any staff training or awareness activity at all. Even among those that do, the testing is almost entirely email-based, while the highest-impact attacks now arrive by phone and target help desks and finance teams.
The gap worth closing is the one between "our staff receive simulated phishing emails" and "our finance team has practised refusing a convincing urgent call from someone who sounds exactly like the chief executive".
Five questions for your next board meeting
1. If someone calls our help desk claiming to be a locked-out executive, what exactly must they provide, and can a sufficiently forceful caller get that waived?
2. Can a member of our finance team change a supplier's bank details without an out-of-band call back to a number from our own records?
3. Would a junior member of staff feel able to refuse an urgent instruction from me until they had verified it, and how do I know?
4. What is our report rate and our time to first report, and is anyone accountable for improving them?
5. Which of our suppliers can reset our staff's credentials, and when did we last check how they verify identity?
If those five questions produce hesitation, that hesitation is the brief.