risk
Phishing, spear-phishing and social engineering
Adversary counterfeits trustworthy communications (email, phone, spoofed websites) to trick individuals — including high-value executives — into revealing credentials or sensitive information, or into enabling wire-transfer/BEC fraud.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- cyber_security
- domain
- Awareness & Training
- Access Control & Identity Management
- taxonomy
- nist-800-30-threat-event
- basel-operational-risk
- inherent_rating
- critical
Details
- risk_id
- aware-phishing-social-engineering
- category
- cyber_security
- likelihood
- very_high
- impact
- high
- inherent_rating
- critical
- treatment
- mitigate
- taxonomies
- nist-800-30-threat-event
- basel-operational-risk
Source
No record-specific source URL is provided.
Connections
- UC-TRAIN-01 — Deliver security awareness training to all personnel mitigates Phishing, spear-phishing and social engineering
- strength
- primary
- rationale
- Control explicitly runs phishing simulations and social-engineering awareness, directly lowering susceptibility to deception/credential theft.
- UC-ACCESS-14 — Authorize public content and external information sharing mitigates Phishing, spear-phishing and social engineering
- strength
- related
- rationale
- Pre-publication review preventing exposure of nonpublic information reduces reconnaissance data available for spear-phishing.
- UC-ACCESS-07 — Proof identities before binding credentials mitigates Phishing, spear-phishing and social engineering
- strength
- related
- rationale
- Re-proofing on credential recovery defends against social-engineering of help-desk account-recovery takeover.
- UC-ACCESS-11 — Defend logons against brute-force and anomalous attempts mitigates Phishing, spear-phishing and social engineering
- strength
- related
- rationale
- Adaptive step-up or denial catches use of phished credentials from anomalous location/device contexts.
- UC-ACCESS-09 — Authenticate all users with multi-factor authentication mitigates Phishing, spear-phishing and social engineering
- strength
- primary
- rationale
- MFA blocks account takeover even when a password is phished, the canonical defense against credential-harvesting social engineering.
- UC-TRAIN-03 — Record training completion and measure effectiveness mitigates Phishing, spear-phishing and social engineering
- strength
- related
- rationale
- Collecting phishing-simulation/assessment results and improving content raises anti-phishing effectiveness indirectly.
- UC-TRAIN-02 — Train personnel with specialized security roles and duties mitigates Phishing, spear-phishing and social engineering
- strength
- primary
- rationale
- Role-based training for senior leaders and privileged staff directly defends against executive-targeted spear-phishing/BEC.