In spring 2025, several major UK retailers experienced highly disruptive cyber incidents.

For many businesses watching the headlines, the immediate reaction may have been: “That’s a major retailer. Surely this isn’t relevant to us.”

It is.

One of the most important lessons from the attacks was that cybersecurity is not only about preventing malicious software or blocking suspicious network traffic.

Sometimes, the attack begins with a conversation.

A convincing phone call. A request to reset an account. Someone claiming to be a colleague who has been locked out. A support employee trying to be helpful.

This is social engineering, and it can turn a perfectly legitimate business process into an entry point for an attacker.

The human side of the attack

Social engineering works by manipulating people rather than exploiting technology directly.

An attacker may research an organisation and identify employees, suppliers, systems or processes that could help them gain access.

They then create a believable situation designed to make someone act.

For example, an attacker might contact an IT support function claiming to be an employee who cannot access their account and needs their password or MFA reset.

The request may sound completely reasonable.

The person making the request may know enough about the organisation to appear credible.

And the employee receiving the call may simply be trying to solve a problem quickly.

That is what makes social engineering so effective.

The weakness is not necessarily a lack of technical security.

It is trust being placed in the wrong person.

Why this matters to smaller businesses

It is easy to assume that attackers only target household-name organisations.

Smaller businesses should not take comfort from that.

In fact, smaller organisations can sometimes have fewer layers of verification between a request and an action.

An internal IT employee, outsourced support provider or office manager may be responsible for handling account access, password resets or MFA changes.

That makes these processes important security controls, regardless of the size of the organisation.

There is another issue too.

Your business does not operate in isolation.

Suppliers, contractors and technology partners may have access to your systems or data. Their security processes can therefore become part of your own risk.

Five practical ways to reduce the risk

1. Don’t rely on trust alone

Build verification into sensitive processes.

Password resets, MFA changes and access requests should follow a defined procedure rather than depending on whether the person making the request sounds convincing.

Use information that an attacker is unlikely to know and, where possible, verify through a separate trusted channel.

2. Make it acceptable to slow down

Social engineering often creates urgency.

Employees may feel pressured to solve a problem immediately, particularly when the person on the other end of the phone sounds frustrated or senior.

Make it clear that staff are allowed to pause, ask questions or escalate a request.

Taking five minutes to verify is better than spending five weeks recovering from a compromised account.

3. Treat access management as a security function

Anyone with the ability to reset credentials or MFA effectively has significant access to the organisation.

That applies whether the role sits inside the business or with an external IT provider.

Make sure these people receive appropriate security training and that sensitive actions are logged and reviewed.

4. Test the process

A policy document cannot tell you how your team will respond under pressure.

A controlled social-engineering exercise can.

Test scenarios such as:

“I’m locked out of my account and need my MFA reset urgently.”

What happens next?

Who verifies the request?

What information is checked?

Who can approve it?

And how quickly can the request be stopped if something does not look right?

The answers will tell you far more about your resilience than a policy sitting in a shared folder.

5. Look beyond your own organisation

Ask suppliers and technology partners how they handle sensitive requests.

If an external provider can reset your employees’ credentials, manage your systems or access sensitive information, their processes form part of your security boundary.

Ask the questions before there is an incident.

The uncomfortable lesson

The biggest lesson from these attacks is not that technology has failed.

It is that technology cannot compensate for a process that can be manipulated by a convincing person.

Firewalls, MFA, endpoint protection and monitoring remain essential.

But if someone can talk their way around your identity and access controls, the technology protecting the account may never get the chance to do its job.

That is why social engineering deserves the same attention as technical vulnerabilities.

For businesses across the Thames Valley, this does not necessarily mean buying another security product.

It may simply mean looking at the processes already in place and asking:

Could someone talk their way through them?

If the answer is unclear, that is a good place to start.

Because sometimes the strongest security control is not another piece of technology.

It is a person who knows when to stop, verify and ask questions.