Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Protect your organization by requiring independent verification before anyone acts on a consequential request. A familiar name, convincing voice, or professional invitation is not proof of identity: confirm the requester through a known contact method or approved workflow, and use strong account protections and clear reporting procedures to limit damage.

How expert impersonation works

Social engineering exploits trust and context to persuade someone to take an unsafe action. An attacker may pose as an executive, colleague, vendor, outside specialist, or known professional contact. The request can arrive by email, text, phone call, or video and may ask an employee to disclose credentials, open a login page, change payment details, share sensitive files, or grant access.

CISA describes phishing as social engineering that impersonates a trustworthy entity. Related forms include spearphishing aimed at particular people, whaling directed at senior targets, vishing by voice, and smishing by text. See CISA’s Phishing: General Security Postcard.

A well-targeted message can draw on plausible professional context rather than obvious errors. A 2024 CISA and FBI fact sheet describes a particular account-targeting campaign that used fake login pages and lures such as interview or speaking invitations. Those observations concern that activity; they are not a measure of how common such attacks are. Read How to Protect against Iranian Targeting of Accounts.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Voice and video do not remove the need to verify. Synthetic audio or video may make an impersonation more convincing, but the request still needs to be authenticated separately from the channel or media in which it arrived. A September 2023 CISA announcement describes an NSA, FBI, and CISA information sheet on synthetic-media threats and organizational preparation, identification, defense, and response; the announcement is archived, so it should not be treated as confirmation of the latest agency policy. See CISA’s deepfake media announcement.

Verify consequential requests before acting

Write a procedure for requests that could move money, change payroll or bank details, expose credentials, grant access, disclose sensitive information, or bypass normal controls. The procedure should make verification routine rather than a judgment call under pressure.

Rank #2
J. J. Keller 2024 OSHA Safety Training Handbook, Softbound, English
  • Updated Compliance: While the new rule takes effect on 7/19/2024, training and compliance dates don’t start until 1/19/2026, giving your team ample time to prepare with this thorough guide to OSHA regulations (29 CFR 1910.1200(j)).
  • Comprehensive Safety Training Handbook: Prepares your employees for 25 of OSHA’s hottest safety topics, from Confined Space Entry to Workplace Violence, ensuring they are equipped with vital safety knowledge for a safer work environment.
  • In-Depth, Easy-to-Understand Content: Each chapter tackles key workplace hazards like Electrical Safety, Lockout/Tagout, Respiratory Protection, and more, helping to prevent injuries and illnesses while promoting safe practices.
  • Interactive Learning with Quizzes: Engaging chapter review quizzes reinforce safety concepts, making it easier for employees to retain and apply the knowledge, with downloadable answer keys for easy tracking.
  • Specifications: English, Softbound, full-color pages (272 pages) offer clear, visually appealing safety information for a diverse workforce, with home safety details included throughout.
  1. Pause the request. Treat urgency, secrecy, authority, or a sudden switch to a new channel as reasons to slow down—not as reasons to skip controls.
  2. Use an independent route. Contact the person through a number or address already on file, a trusted internal directory, or an approved workflow. Do not use contact details or links supplied in the suspicious message to verify that same message.
  3. Confirm the exact action. Verify the amount, destination account, requested access, data to be shared, or other material details—not merely that the person contacted you.
  4. Apply required approvals. Keep normal approval and separation-of-duties steps in place, including for requests that appear to come from senior staff or recognized experts.
  5. Record and escalate anomalies. If verification fails or the request does not match normal procedures, do not proceed; use the organization’s reporting channel.

This process applies to calls and video meetings as well as email and text. A caller ID, familiar voice, or apparent face should not be the sole authorization for a high-impact action.

Train staff to recognize and report attempts

Teach employees to inspect sender addresses, links, attachments, unexpected requests, and abrupt changes in how a contact communicates. Do not limit examples to spelling mistakes: a convincing lure may be polished and tailored to a real role or relationship.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Make the reporting path explicit for suspicious email, text, phone, and video requests. Employees should know whom to contact and what to do if they clicked a link, entered a password, shared information, or approved an action. A 2025 CISA guide for state, local, tribal, and territorial governments recommends threat-literacy training, simulations that reflect real threats, and policies explaining reporting and official communication channels. These are practical principles for other organizations too; the guide’s intended audience is SLTT governments. See Four Cybersecurity Essentials for SLTTs.

Use realistic exercises to find gaps in procedures and improve readiness, not to declare employees or the organization immune. CISA’s phishing guidance also points to protective measures such as securing high-value accounts with strong passwords and MFA, protecting email systems, separating email from critical assets, and assessing susceptibility through phishing campaigns.

Protect accounts with stronger authentication

Require multifactor authentication (MFA) for email, file storage, remote access, and privileged or administrative accounts. Prioritize accounts belonging to people who can access sensitive data or approve high-impact actions. MFA can reduce the risk that a stolen password alone is enough to take over an account, but methods differ in how well they withstand phishing.

CISA recommends aiming for phishing-resistant MFA and identifies FIDO as an option that can block a sign-in attempt to a fake website. A compatible FIDO security key is one physical way to use this approach. Before choosing a key, check that it works with the organization’s identity provider, device fleet, enrollment process, and account-recovery policy. CISA’s guidance is available at Require Multifactor Authentication and More than a Password.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For the specific Iranian targeting activity described in its 2024 fact sheet, CISA and FBI say SMS- or email-based authenticators are not sufficient against those tactics. That threat-specific warning should not be read as meaning that every non-FIDO MFA method offers no protection in every situation.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Layer controls because each covers a different risk

No single measure addresses every part of an impersonation attempt. Compare controls by the channel they cover, where they act in the attack, how much they depend on employee judgment, and their deployment and recovery requirements.

Control What it helps address Important limitation
Independent verification procedure Requests made through email, text, voice, or video, including attempts to induce payment, access changes, or disclosure. It depends on employees following the process and on the organization maintaining reliable contact and approval workflows.
Phishing-resistant MFA Sign-ins to supported accounts; FIDO can block a user’s attempted login to a fake website. It does not verify a payment or business instruction by itself. Compatibility, enrollment, and account recovery must be planned.
Training and realistic exercises Recognition, reporting, and readiness for threats that resemble the organization’s work. Training is not a guarantee that a person will identify every attempt or that an unsafe action cannot occur.
Email protections and segmentation Reduce exposure to some email lures and limit connections between email and critical assets. They do not cover every text, phone, or video impersonation scenario.

What to do if someone may have acted on an impersonation

  1. Stop the pending action. Pause a payment, account change, data transfer, or access grant if it is still possible to do so safely.
  2. Report it through the internal incident process. Include the channel used, the request, what action was taken, and any account or information involved.
  3. Contact the real person independently. Use a known number, address, or directory entry—not the contact details in the suspicious message—to confirm whether they made the request.
  4. Preserve relevant evidence. Keep the message, caller information, links, and other details needed by the organization’s responders.
  5. Follow incident instructions promptly. If credentials were entered or shared, report that immediately so the organization can take the appropriate account-protection steps.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.