The Phone Call That Bypassed a $90M Security Stack
No firewall protects against a well-briefed voice on the other end of the line. An analysis of how social engineering continues to outpace technological controls.
The organisation had invested over ninety million dollars in cybersecurity infrastructure over five years. Endpoint detection and response. Zero-trust architecture. 24/7 security operations. When the breach occurred, none of it mattered. The attacker never touched the network. They called the help desk, impersonated a senior IT contractor, and were given credentials reset within eleven minutes.
This is not an unusual case. It is a representative one. The gap between investment in technical controls and investment in human-layer defences remains, at most large organisations, vast. The calculus of what constitutes a security investment has been shaped almost entirely by technology vendors. As a result, organisations understand their network perimeter in granular detail and have almost no systematic understanding of how their people behave under social pressure.
Social engineering attacks succeed because they exploit cognitive biases that are features of human social functioning, not bugs. The tendency to defer to authority, the discomfort of refusing a request, the pressure of urgency, and the social cost of appearing suspicious are all exploited deliberately. Training programmes that tell employees these biases exist do not neutralise them. Only sustained behavioural conditioning produces measurable resistance.
The sophistication of current social engineering attacks has increased markedly with the availability of large language models and open-source intelligence tools. Attackers can now generate contextually accurate impersonations with minimal effort, drawing on publicly available information about organisational structures, personnel, and current projects. The marginal cost of a highly personalised attack has dropped to near zero.
The organisations that demonstrate consistent resistance to social engineering share a common characteristic: they have built a culture in which verification is normalised rather than treated as an insult. When challenging an unexpected request is institutionally rewarded rather than socially penalised, the attack surface shrinks substantially.
"Every organisation has a penetration test. Very few have tested what happens when someone simply calls reception and asks for help."
Custodia One Advisory Perspective
What Your Organisation Should Do
Commission a social engineering assessment that tests human response rather than technical controls
Redesign your help desk and IT support protocols to include mandatory out-of-band verification for all credential actions
Build verification into your institutional culture: normalise the challenge, remove the social cost of scepticism
Track and analyse social engineering attempts as threat intelligence: patterns across incidents reveal targeted campaigns
Advisory Enquiries
Facing this issue in your organisation?
Custodia One advises on all of the issues covered in our Intelligence Library. Contact us to discuss your specific situation in confidence.
