Authentication and Social Engineering

How authentication factors, access controls, and social-engineering patterns affect identity security and user decision-making.

Authentication verifies an identity; authorization limits that identity’s actions. Multifactor authentication combines independent factor types, such as something known, possessed, or inherent. NIST notes that some MFA methods are more phishing-resistant than others. See NIST MFA guidance.

Pattern Meaning
Phishing Deceptive email or web message seeking credentials, money, or action
Smishing Phishing delivered by text message
Vishing Social engineering by voice call
Impersonation Claiming a trusted identity to obtain access or information
Tailgating Entering a protected physical area by following an authorized person

Treat unexpected requests for credentials, codes, payments, software installation, or urgent access as untrusted until independently verified. Report suspicious activity through the organization’s security process rather than replying through the original message or caller.

Revised on Friday, September 11, 2026