Ravindra BagaleCourses & study guides

27. Social Engineering Awareness

27.5 Building Awareness and Responding

What to teach (students, staff, family):

  • Never share OTP, password, PIN or card details with anyone, ever.
  • Do not click links in messages to log in; open the official app/site yourself.
  • Verify unusual requests by calling back on an official number you looked up (not the one in the message).
  • Slow down – urgency is the attacker's main weapon.
  • Report suspicious messages; do not be embarrassed to ask.
  • Lock devices, do not plug in unknown USBs, do not let strangers "tailgate" into secure areas.

If you (or someone) clicked or shared something:

  1. Do not panic, act fast. Disconnect the device from the internet if malware may have run.
  2. Change passwords from a different, safe device – the affected account first, then any account sharing that password.
  3. Enable MFA everywhere.
  4. Call the bank to block cards/transactions if financial details were shared.
  5. Report: cybercrime.gov.in and the 1930 helpline (India), and inform your IT/security team.
  6. Learn from it – note what the message looked like so others can be warned.

Why this matters for security

You can spend lakhs on firewalls and still be breached by one convincing phone call. Awareness is the cheapest and most effective control against social engineering, because it fixes the weakest link – the human – across every attack in this book.

Ravindra Bagale's Tip

If you have been cheated, the biggest mistake is staying quiet out of embarrassment. Don't panic and don't be embarrassed – change your password right away, inform your bank, and report it on 1930. The sooner you act, the smaller the loss. Tell your family this clearly.

Practice task

Write a short one-page "safety card" in simple language for your family or students: the top five rules and the exact steps (and the 1930 number) to follow if they get tricked. This is a real, useful thing you can hand out.