BLOG

Resources for Educators
& Professionals

 

The User is the New Perimeter

by  Dr. Gene Lloyd     Aug 13, 2026
user-cyber

When I first started learning about hacking, defending against hackers, and the various components that make up a good cybersecurity plan, the topic that was most intriguing was that of social engineering. People were naïve to security in the early days of computing and generally allowed physical or digital access to anyone who presented themselves as an authorized user. Social engineering was the art of convincing someone to believe a particular narrative to trick them into giving someone access to systems or information they had no authorization to access. It worked very well for people like Kevin Mitnick, who successfully talked his way into many facilities with just a phone call and a good story. Mitnick was eventually caught and spent some time in prison, but his social engineering techniques are legendary examples of what was criminally possible 40 years ago if a hacker had a sophisticated narrative. These are important pieces of cybersecurity history that professors should be teaching in the classrooms because making students aware of past successful nefarious activity prepares them for future attempts in similar categories. 

How Social Engineering Has Evolved 

The level of successful social engineering in the 1980’s is not as viable today, as we have become adept at training users to be suspicious of access requests, not believing something at face value, securing entry to office spaces, and requiring visitors to be escorted or monitored as they conduct any relevant business within a facility. It is rare to see someone talk their way past multiple levels of security in an organization today, especially leading to direct access to systems or networks. But students should be aware that hackers have adapted their tactics to use a different type of social engineering combined with statistical probabilities that often work in their favor. We refer to this methodology as phishing, which is widely known today and has recently become more sophisticated.   

Why Phishing Has Become a Primary Attack Vector 

Cybersecurity professionals have done a great job in the past 40 years developing systems, applications, and methodologies that have made our networks incredibly secure, if all the right pieces are in place. We owe a debt of gratitude to the professors who have trained students to advance security to greater levels. Hackers have recognized these improvements and shifted back to the old strategy of social engineering. In the 2000s, a common target of attack was internet-facing systems like web, email, and DNS servers, which, if successfully penetrated, could become entry points to devices on the internal network. We teach our students about hacking methodologies, looking for vulnerabilities, and working our way through networks because vulnerable systems are still potential entry points into networks, though our improved security posture has greatly reduced hacker success rates in direct attacks. This is likely why phishing attempts are once again on the rise. 

Teaching Students to Recognize Modern Phishing 

As professors teach about phishing in their classrooms, they should be noting that the goal of the hacker today is much more focused on tricking a user into providing access than on direct attacks. If one studies the major digital data thefts that have occurred in the past five years, they will find that several were the result of someone successfully being socially engineered through phishing. Older phishing attempts were easily recognizable because the grammar was atrocious and the social engineering method was elementary at best. But today’s attempts are so well put together that users have to pay careful attention to any message that mandates clicking on links or taking external actions, especially when they include some form of a threat of negative action if the requirement is not immediately met. The problem is that students may not have as much experience with phishing as those working in professional environments, so professors should provide common modern examples of these attacks. 

Connecting Phishing to Broader Security Lessons 

Professors should also explain to students that the reason for the increase in volume and sophistication of phishing is that we have done a great job in securing so many other avenues of attack. This requires criminals to pivot to a newer methodology, which is a rebirth and refinement of the earliest types of nefarious activity, hoping to gain surreptitious access. To be fair, older in-person social engineering still works if the perpetrator has developed their skillset enough to convince someone to believe a particular narrative. But these attempts often take place away from the workplace and are akin to the application of spycraft that develops an asset who eventually may purposefully or accidentally give the perpetrator the access they seek. Students should also be aware of other physical methods of social engineering that involve malware-laden USB drives being placed on corporate bathroom counters or in company parking lots with the hope that an unsuspecting user may simply insert it into their company computer to see what it contains. It only takes one insertion to gain access to a network. 

Emphasizing Vigilance in the Classroom 

Phishing is largely a numbers game. Penetration testers have learned that if they send a phishing email to everyone in a large company, there is a probability of at least one person clicking on the malicious link. One click is all that is needed. This should be a key piece of student training. Professors should teach vigilance as part of phishing education blocks to ensure students learn to be suspicious of any activity that could potentially be a phishing attempt, and that they carry this with them into the professional world. 

The User Remains the Perimeter 

Social engineering is not new. It has been around since the early days of computing and has taken many different forms, many of which have been successful in different environments. Teaching about the various forms of social engineering in classroom settings should include more than a cursory discussion, as it has once again come to the forefront as a common attack methodology. Students need to be hyper-aware of the possibility that a hacker can gain access very easily if they can simply trick the right person. We have done well in securing other aspects of network security; we cannot afford to let this one slip through the cracks.

Stay Connected

Categories

Clear

Search Blogs

Featured Posts

The User is the New Perimeter

by  Dr. Gene Lloyd     Aug 13, 2026
user-cyber

When I first started learning about hacking, defending against hackers, and the various components that make up a good cybersecurity plan, the topic that was most intriguing was that of social engineering. People were naïve to security in the early days of computing and generally allowed physical or digital access to anyone who presented themselves as an authorized user. Social engineering was the art of convincing someone to believe a particular narrative to trick them into giving someone access to systems or information they had no authorization to access. It worked very well for people like Kevin Mitnick, who successfully talked his way into many facilities with just a phone call and a good story. Mitnick was eventually caught and spent some time in prison, but his social engineering techniques are legendary examples of what was criminally possible 40 years ago if a hacker had a sophisticated narrative. These are important pieces of cybersecurity history that professors should be teaching in the classrooms because making students aware of past successful nefarious activity prepares them for future attempts in similar categories. 

How Social Engineering Has Evolved 

The level of successful social engineering in the 1980’s is not as viable today, as we have become adept at training users to be suspicious of access requests, not believing something at face value, securing entry to office spaces, and requiring visitors to be escorted or monitored as they conduct any relevant business within a facility. It is rare to see someone talk their way past multiple levels of security in an organization today, especially leading to direct access to systems or networks. But students should be aware that hackers have adapted their tactics to use a different type of social engineering combined with statistical probabilities that often work in their favor. We refer to this methodology as phishing, which is widely known today and has recently become more sophisticated.   

Why Phishing Has Become a Primary Attack Vector 

Cybersecurity professionals have done a great job in the past 40 years developing systems, applications, and methodologies that have made our networks incredibly secure, if all the right pieces are in place. We owe a debt of gratitude to the professors who have trained students to advance security to greater levels. Hackers have recognized these improvements and shifted back to the old strategy of social engineering. In the 2000s, a common target of attack was internet-facing systems like web, email, and DNS servers, which, if successfully penetrated, could become entry points to devices on the internal network. We teach our students about hacking methodologies, looking for vulnerabilities, and working our way through networks because vulnerable systems are still potential entry points into networks, though our improved security posture has greatly reduced hacker success rates in direct attacks. This is likely why phishing attempts are once again on the rise. 

Teaching Students to Recognize Modern Phishing 

As professors teach about phishing in their classrooms, they should be noting that the goal of the hacker today is much more focused on tricking a user into providing access than on direct attacks. If one studies the major digital data thefts that have occurred in the past five years, they will find that several were the result of someone successfully being socially engineered through phishing. Older phishing attempts were easily recognizable because the grammar was atrocious and the social engineering method was elementary at best. But today’s attempts are so well put together that users have to pay careful attention to any message that mandates clicking on links or taking external actions, especially when they include some form of a threat of negative action if the requirement is not immediately met. The problem is that students may not have as much experience with phishing as those working in professional environments, so professors should provide common modern examples of these attacks. 

Connecting Phishing to Broader Security Lessons 

Professors should also explain to students that the reason for the increase in volume and sophistication of phishing is that we have done a great job in securing so many other avenues of attack. This requires criminals to pivot to a newer methodology, which is a rebirth and refinement of the earliest types of nefarious activity, hoping to gain surreptitious access. To be fair, older in-person social engineering still works if the perpetrator has developed their skillset enough to convince someone to believe a particular narrative. But these attempts often take place away from the workplace and are akin to the application of spycraft that develops an asset who eventually may purposefully or accidentally give the perpetrator the access they seek. Students should also be aware of other physical methods of social engineering that involve malware-laden USB drives being placed on corporate bathroom counters or in company parking lots with the hope that an unsuspecting user may simply insert it into their company computer to see what it contains. It only takes one insertion to gain access to a network. 

Emphasizing Vigilance in the Classroom 

Phishing is largely a numbers game. Penetration testers have learned that if they send a phishing email to everyone in a large company, there is a probability of at least one person clicking on the malicious link. One click is all that is needed. This should be a key piece of student training. Professors should teach vigilance as part of phishing education blocks to ensure students learn to be suspicious of any activity that could potentially be a phishing attempt, and that they carry this with them into the professional world. 

The User Remains the Perimeter 

Social engineering is not new. It has been around since the early days of computing and has taken many different forms, many of which have been successful in different environments. Teaching about the various forms of social engineering in classroom settings should include more than a cursory discussion, as it has once again come to the forefront as a common attack methodology. Students need to be hyper-aware of the possibility that a hacker can gain access very easily if they can simply trick the right person. We have done well in securing other aspects of network security; we cannot afford to let this one slip through the cracks.

Tags

Clear