Phishing attacks, which are a form of social engineering, target
organizations on a daily basis. These types of attacks can cause a
company to lose money and man-hours, not to mention data.
Organizations are beginning to incorporate simulated phishing
campaigns into their ongoing security awareness message. Some
employees may see this as the information security team tricking
employees, which can lower trust. How do you counter these issues?
Do you think the term "social engineering" should be used to
describe these scenarios? How do you prepare employees for
defending against these attacks?