A firewall cannot be talked into anything. An employee can. That is the whole principle of social engineering: rather than forcing a digital lock, the scammer convinces someone to open the door for them. And that door is often the least watched one in the company.

This needs to be said from the outset, because it is the most misunderstood point: getting caught out is not a sign of naivety. These techniques are well-honed, repeated thousands of times, and adjusted to whatever works. They exploit perfectly healthy social reflexes. They work on seasoned executives just as well as on apprentices.

A massive, underestimated phenomenon

Switzerland’s official figures give a sense of the scale of the problem. In the second half of 2025, fraud was the most frequently reported phenomenon to the National Cyber Security Centre, with 15,090 reports, or 52% of the total, ahead of phishing (6,299) and spam (4,284). Over the whole of 2025, 64,733 voluntary cyber-incident reports were recorded, compared with 62,954 in 2024.

In other words, most of what is reported in Switzerland involves manipulation, not sophisticated hacking. The attacker breaks nothing. They ask, and they are given what they ask for.

At the same time, companies’ confidence is eroding. According to the SME Cybersecurity 2025 study, 42% of Swiss SMEs consider their protection sufficient, down from 55% a year earlier. A welcome wake-up call, provided it translates into concrete measures.

What are the four psychological levers exploited?

Whatever their disguise, all these scams rely on a small number of mechanisms. Knowing them is already enough to defuse them.

Authority. We obey more readily someone who appears to be in a position to ask: a boss, a police officer, an IT specialist, a bank employee. The scammer does not need to actually be that person, they only need to adopt the vocabulary and tone.

Urgency. “You must act right now”, “the payment goes out tonight”, “your account will be blocked within the hour”. Time pressure prevents verification. It is the most universal lever, and the most telling one.

Fear. A fine, a complaint, a virus, a data leak. Fear triggers a fast, poorly considered reaction, exactly what the scammer is after.

The wish to help. The most insidious lever, because it exploits a virtue. A colleague stuck, a supplier in difficulty, a technician who “just needs a code to finish”. Refusing to help carries a social cost, and scammers know it.

The universal signal: you are being pressured

A legitimate request can always wait ten minutes. A scam almost never can. If you feel urgency, fear or discomfort at refusing, these are more reliable indicators than any technical detail. Make it an internal rule: any urgent, unusual request triggers a verification, without exception and without the person having to justify themselves.

Vishing, smishing, fake support: recognising the three forms

The techniques change channel, but the mechanics stay the same.

TechniqueChannelTypical pretextWarning sign
VishingPhone callYour bank, the police, a supplier, a company executiveYou are asked for a code, a password or an immediate payment, and pressed to stay on the line
SmishingText message or messaging appA blocked parcel, an unpaid invoice, a tax refund, a message from a “new number”A shortened link, an address that does not match the announced sender, a reply expected within the hour
Fake technical supportCall, pop-up window, e-mail”This is Microsoft, your computer is infected”You are made to install remote-access software or read out a security code
On-site impersonationPhysical visitTechnician, delivery driver, inspector, external auditorNo visit was announced, no internal contact to confirm, a request to access the premises unaccompanied

Vishing is the most effective, because a voice creates an immediate connection. A calm, polite caller who knows your director’s name and your bank’s name naturally inspires trust. This information is often public: a website, the companies register, professional networks.

Smishing relies on volume and routine. People check texts between two meetings, without paying attention. The message links to a page that mimics a familiar service, and the credentials entered go straight to the scammer.

Fake technical support combines fear and authority. The victim is convinced they are being helped while they open their computer to a stranger.

On-site impersonation remains rare but formidable: a work vest, a laminated badge and a plausible reason open many doors. No one likes to challenge a stranger who looks like they know what they are doing.

A typical scenario: a Friday, 4:40 pm

The phone rings at the accounting desk. "Hello, this is your bank's payments department. We have blocked a suspicious transaction of 8,400 francs on your business account." The number shown really is the bank's. The caller mentions the director's name and the last four digits of the IBAN, two pieces of information found on a public invoice.

They offer to cancel the transaction. To do so, a "security check" must be confirmed: a code will arrive by text message, and it just needs to be read out over the phone. The employee hesitates, and the caller reassures her: "I'll stay on the line, whatever you do don't hang up, or the transaction will go through." She reads out the code. It actually validates a real transfer, the scammer's own.

The one action that would have stopped everything: hanging up and calling the bank back on the number shown on the bank statement. No technical knowledge was needed.

Why are executives prime targets?

It is tempting to assume the boss is the best equipped to resist. It is often the opposite, for three structural reasons.

An executive decides quickly, that is their job. They are frequently travelling, so reachable by phone rather than in person. And above all, no one in the company dares question a request that appears to come from them.

This is exactly what CEO fraud targets, a high-end variant of social engineering in which a fake executive demands a confidential, urgent transfer. The instruction for discretion (“don’t mention this to anyone, it’s a sensitive operation”) serves precisely to prevent verification.

The corollary is simple: a verification rule only works if it also applies to management. A procedure the boss can bypass is not a procedure.

Which behavioural defences actually work?

No software blocks a persuasive phone call. Effective defences are habits, and they come down to a few rules.

Hang up and call back. This is the ultimate defence. You end the call, look up the official number yourself (bank statement, contract, internal directory) and call back. Never call back a number given by the caller. This single habit neutralises almost all vishing.

Never share a code received by text. No legitimate institution asks you to read an authentication code out loud. That code is the key to your account, it is not to be dictated. This is also why two-factor authentication must come with this clear instruction.

Introduce dual control on payments. Any transfer above a defined amount, or to a new bank detail, requires validation by two people through a channel separate from the one used for the request. Simple, free, extremely effective.

Explicitly authorise refusal. Write it down and repeat it: no one will be penalised for refusing a request, asking to verify, or making a caller wait, even a superior. Without this authorisation, politeness always wins over caution.

Manage visits. Any external visitor is announced in advance, welcomed and accompanied. An unannounced technician waits while the provider is checked with.

The number shown proves nothing

Caller ID can be spoofed. A scammer can display the number of your bank, an administration or even an internal extension of your own company. Many victims later explain they trusted the call "because the number was right." The number visible on your screen is not an identity: only a call-back that you initiate yourself has any value.

Keeping these reflexes alive in the company

A memo forgotten in an inbox changes no behaviour. What works is short repetition and the right to make a mistake.

Three habits are enough to build a solid culture. Spend fifteen minutes in a team meeting recounting a real attempt, your own or a colleague’s. Share the alerts published by the National Cyber Security Centre and the national S-U-P-E-R campaign, which describe the campaigns currently underway in Switzerland. And publicly thank, without irony, the person who reports an attempt, including when they were initially taken in.

This last point is decisive. In a company where people fear looking foolish, incidents stay hidden, and a scam detected late costs far more. The underlying reasons are covered in our article on the value of raising your teams’ awareness, and the practical implementation in building an awareness programme.

Finally, keep in mind that social engineering is almost never an end in itself. It serves as an entry point: credential theft, ransomware deployment, access to personal data. Your other defences therefore remain essential, in particular the 3-2-1 backup rule and compliance with your FADP obligations in the event of a data leak. The other forms of attack, starting with e-mail phishing, are grouped in the Threats pillar.

To see where your company stands today, the cyber check-up devotes several questions to payment procedures, request verification and staff training. And if an incident has just occurred, start with the first hours after an attack.