27. Social Engineering Awareness
Chala mitrano, aaj sarvat mahatvacha ani sarvat durlakshit vishay – social engineering. Aataparyant aapan machines hack kelya, pan attacker cha sarvat sopa target machine nahi, manus aahe! Firewall, HTTPS, strong password – he sagle asun suddha ek phone call kiwa ek fake email madhe manus fasto ani sagli suraksha vaya jate. Ha chapter attack karaycha nahi, tar olakhaycha ani thambavaycha aahe – tumhi, tumche students, tumcha kutumb ani business surakshit rahava mhanun. Ha bahutek rojcha, practical dhada aahe. Samjla ka? Chala!
What you will learn in this chapter
- What social engineering is and why it works (the psychology)
- The main types: phishing, vishing, smishing, pretexting, baiting, tailgating
- How to spot a phishing email or message, step by step
- The SET toolkit – named for awareness only, not for attacking anyone
- Building awareness: what to teach students, staff and family
- What to do if you or someone clicked
Awareness only – never target real people
This chapter is about recognising and stopping social engineering. Sending phishing emails, fake calls or fake login pages to real people (even "as a test") without written authorisation is fraud and a crime under the IT Act (sections 66C, 66D). Only authorised, agreed awareness programs run simulated tests.
Concepts in this chapter
- 27.1What Social Engineering Is and Why It Works
- 27.2Types of Social Engineering
- 27.3How to Spot a Phishing Message
- 27.4The SET Toolkit (Awareness Only)
- 27.5Building Awareness and Responding
- 27.6Red vs Blue, Project and Real Incidents
The chapter recap is at the end of the last concept page.