Back to Search View Original Cite This Article

Abstract

<title>Abstract</title> <p>Social engineering remains a persistent cybersecurity problem because it targets the cognitive, emotional, and social conditions under which users make security decisions. Although organizations continue to invest in technical controls, recent incident reporting shows that human action, credential misuse, phishing, and deception continue to shape breach pathways. This study develops a human-centered ethical response framework for mitigating social-engineering risk in a higher-education setting. Using an exploratory qualitative case-study design, four focus-group discussions were conducted at William V. S. Tubman University with IT support staff, engineering and technology undergraduates, and foundation programme learners. The discussions examined how participants interpreted phishing, impersonation, urgency cues, trust appeals, workload pressure, and security-awareness interventions. Thematic content analysis identified three dominant clusters: risk and trust perception, recognition and response to deceptive stimuli, and policy/training expectations. Descriptive coding showed that IT support staff produced the highest mean number of risk-and-trust units and the highest training-fatigue scores, engineering undergraduates generated the highest deceptive-response units, and foundation learners required more foundational scaffolding. The article contributes an ISO/IEC 27001-aligned framework that links ethical monitoring, adaptive learning, transparent feedback, and incident escalation. The findings should be interpreted as analytically transferable rather than statistically generalizable. They suggest that social-engineering defence should move beyond one-off awareness campaigns toward role-sensitive, privacy-respecting, continuously improved human-risk governance.</p>

Show More

Keywords

engineering highest social continue incident

Related Articles

PORE

About

Connect