1 of 34

Session 2: People Security and Behavioral Threats

Human Factors, Social Engineering, Insider Threats, and Awareness-Based Detection

Justin Pineda CISSP, CISM

Faculty

2 of 34

Learning Objectives

  • Explain how human behavior creates attack surfaces
  • Identify social engineering and insider threat indicators
  • Relate awareness to threat detection activities

3 of 34

Motivation Question

Why do organizations with strong technical controls still get breached?

4 of 34

People as an Attack Surface

  • Humans are part of the system
  • Trust and convenience are exploitable
  • Behavior can bypass controls

5 of 34

6 of 34

Human Factors in Security Failures

  • Cognitive bias
  • Fatigue and stress
  • Security complacency

7 of 34

8 of 34

9 of 34

What Is Social Engineering?

  • Psychological manipulation
  • Targets people, not systems
  • Often first attack stage

10 of 34

11 of 34

12 of 34

Common Social Engineering Techniques

13 of 34

Why Social Engineering Works

  • Exploits trust and fear
  • Mimics business processes
  • Time pressure

14 of 34

Insider Threats Defined

  • Originates from inside
  • May be intentional or accidental
  • Often difficult to detect

15 of 34

16 of 34

Behavioral Indicators of Insider Risk

  • Unusual access times
  • Excessive downloads
  • Privilege misuse

17 of 34

Awareness vs Training

  • Training = knowledge
  • Awareness = behavior
  • Detection relies on behavior

18 of 34

19 of 34

Awareness-Based Threat Detection

  • User reporting
  • Behavior monitoring
  • Signal correlation

20 of 34

People Security in SOC Operations

  • Humans as sensors
  • UEBA integration
  • SOC correlation

21 of 34

Enterprise Scenario Example

22 of 34

The Almost-Legitimate Email

You are an employee in the Finance Department.� At 9:12 AM, you receive the following email:

From: IT Service Desk <servicedesk@company-support.co>� Subject: Action Required: MFA Re-Sync for Finance Users

Hi,

Due to a synchronization issue identified during last night’s system update, several Finance user accounts may experience login issues today.

To avoid payroll delays, please re-sync your MFA token using the link below before 11:00 AM.

👉 Re-sync MFA: https://company-support.co/mfa-sync

If you experience issues, reply to this email.

— IT Service Desk

This activity was approved by Management as part of our system hardening initiative.

23 of 34

The Almost-Legitimate Email

Additional context:

  • The email uses the correct company logo and formatting
  • The sender address looks similar to internal IT emails
  • Payroll processing is scheduled later today
  • You vaguely remember IT announcing “system updates” last week
  • Two teammates already replied in the group chat:
  • “I just did it, worked fine.”

24 of 34

Questions

1. Is the biggest red flag technical, procedural, or psychological? Why?

2. Would verifying the link domain alone be sufficient to decide this is safe or unsafe? Explain your reasoning.

3. How does the mention of “Management approval” change the risk of this email being phishing?

4. What is the safest action you can take that does NOT involve clicking, replying, or deleting the email?

5. Which cognitive bias is most likely being exploited after you read the email but before you click anything?

25 of 34

Key Takeaways

  • People are a primary attack vector
  • Behavior enables detection
  • Awareness supports SOC

26 of 34

Session Summary

  • Human behavior is a major threat vector
  • Social engineering bypasses controls
  • Insider risks require behavioral detection

27 of 34

References

  • NIST SP 800-53
  • NIST SP 800-61
  • ENISA Threat Landscape
  • Verizon DBIR

28 of 34

Knowledge Check 1

  • What best describes social engineering?
  • A. Exploiting software
  • B. Manipulating people
  • C. Network scanning
  • D. Password cracking

29 of 34

Knowledge Check 2

  • Which is NOT an insider threat?
  • A. Malicious insider
  • B. Negligent insider
  • C. Compromised insider
  • D. External attacker

30 of 34

Knowledge Check 3

  • Why do social engineering attacks succeed?
  • A. Weak encryption
  • B. Poor firewalls
  • C. Trust exploitation
  • D. Missing patches

31 of 34

Knowledge Check 4

  • Which is behavioral detection?
  • A. Antivirus install
  • B. IP blocking
  • C. Abnormal login monitoring
  • D. Patch updates

32 of 34

Knowledge Check 5

  • Awareness-based detection relies on:
  • A. Certificates
  • B. User behavior
  • C. Bandwidth
  • D. System uptime

33 of 34

Debrief and Reflection

  • What did you learn today?
  • How does behavior affect detection?
  • What would you improve?

34 of 34

Exercise 2: Ethical Phishing Simulation

  • Create a Proton Mail account (observation-focused)
  • Design a convincing but benign authority-style email
  • Send one controlled email to instructors and groupmates
  • Observe delivery results (Inbox / Spam / Blocked)

📘 Refer to the Lab Instruction Manual for full steps, rules, questions, and submission requirements.