How authentication factors, access controls, and social-engineering patterns affect identity security and user decision-making.
Authentication verifies an identity; authorization limits that identity’s actions. Multifactor authentication combines independent factor types, such as something known, possessed, or inherent. NIST notes that some MFA methods are more phishing-resistant than others. See NIST MFA guidance.
| Pattern | Meaning |
|---|---|
| Phishing | Deceptive email or web message seeking credentials, money, or action |
| Smishing | Phishing delivered by text message |
| Vishing | Social engineering by voice call |
| Impersonation | Claiming a trusted identity to obtain access or information |
| Tailgating | Entering a protected physical area by following an authorized person |
Treat unexpected requests for credentials, codes, payments, software installation, or urgent access as untrusted until independently verified. Report suspicious activity through the organization’s security process rather than replying through the original message or caller.