culture into Swiss cheese riddled with loopholes.
• Train people on psychology and influence rather than technical playbooks. Knowing why and how the gift card scam works is far more effective than being taught to look for typos which no longer occur (and before anyone suggests that too-perfect emails are another alarm bell, there are tools which can introduce human- seeming mistakes).
• Technical controls do exist, such as DMARC and phishing-resistant MFA (Multi-Factor Authentication). They aren't perfect, but they raise the bar for attacks and many organisations still haven't implemented these basics
• Help desk controls. The highest-profile recent attacks could have been prevented by simple, procedural controls
which have been well-known since the 70s and 80s. Callbacks to verified numbers, time delays and authorisations on sensitive changes. Given the impact manipulation of a help-desk can have, failure to put these in place can only be described as negligence.
• Leadership. Every time an exception is made because of seniority or authority, every defence is weakened. Every time someone fails to confirm with their CEO for fear of negative consequences, the attackers gain an advantage. If people don't feel safe to question requests, it makes the job of a fraudster that much easier.
The tools change
We spend billions on technical controls while the oldest attacks keep working. Wax seals didn't prevent the Spanish
Prisoner scheme. Clay envelopes didn't stop Ea-Näșir selling poor quality copper.
The oldest recorded use of manufactured trust to neutralise a target is in the Epic of Gilgamesh, around 2100 BC. It may be fictional, but fiction is built on real events. The medium, the tools, have changed beyond any recognition of a Bronze Age merchant, or a Napoleonic private detective (Vidocq), but the methods are still the same.
The good news is that the defences are just as old as the attacks. Verify before acting. Make it safe for people to slow down and question requests. Help people understand the psychological levers being pulled, not just what the latest phishing email looks like.
The tools are going to keep changing, but the methods and the fixes are timeless.
Engineering: & defence strategies
James Bore CSyP Security Institute
www.security-institute.org
© CITY SECURITY MAGAZINE – SUMMER 2026
www.citysecuritymagazine.com
>
10
Page 1 |
Page 2 |
Page 3 |
Page 4 |
Page 5 |
Page 6 |
Page 7 |
Page 8 |
Page 9 |
Page 10 |
Page 11 |
Page 12 |
Page 13 |
Page 14 |
Page 15 |
Page 16 |
Page 17 |
Page 18 |
Page 19 |
Page 20 |
Page 21 |
Page 22 |
Page 23 |
Page 24 |
Page 25 |
Page 26 |
Page 27 |
Page 28 |
Page 29 |
Page 30 |
Page 31 |
Page 32 |
Page 33 |
Page 34 |
Page 35 |
Page 36