wasif~
back

DECIDE - Before you Click

September 20, 2024
securitypsychologyphishing

Phishing remains a persistent threat despite all the cool tech we have available to us at our fingertips. It is ultimately these same ol' fingertips that are responsible for 100% of the phishing victims. It seems like nothing can escape the Pareto principle; Estimates suggest that 80% of all reported security incidents are related to some form of phishing or social engineering. Also, Roughly 82.6% of phishing emails now utilize Generative AI. Phishing has become an umbrella term at this point since there is Quishing, Smishing, Vishing, yes, these are actual words that made their way to the english dictionary. What's more, we have Phishing-as-a-Service codenamed PhaaS. It's a menace.

The links below belong to two VERY different sites:

https://www.google.com
https://www.googIe.com

Cialdini Principles

Dr. Robert Cialdini's Principles of Influence are seven scientifically proven psychological shortcuts that guide human decision making and persuasion. Here are distinct examples for each principle, linked to the mechanics of social engineering.

PrincipleDescription
ReciprocityPeople feel inclined to return favors and kindness they receive.
Commitment & ConsistencyOnce people make a commitment, they tend to act consistently with it.
Social ProofPeople often look to others' behavior to decide what is appropriate.
AuthorityPeople are more likely to follow recommendations from credible experts.
LikingPeople are more easily persuaded by those they like or relate to.
ScarcityThings appear more valuable when they are limited or hard to obtain.
UnityPeople are more persuaded by those they see as part of their own group or identity.

It is important to note that the most successful attacks rarely rely on just one principle. Attackers often stack them to amp up their success rate. For example: An attacker sends an email as the CEO (Authority), stating that most of the board has already signed off (Social Proof) on a new document, and that it must be reviewed by the end of the day (Scarcity).

Another example is an attacker impersonating a senior project manager (Authority), reminding an employee of their track record of promptly supporting critical initiatives (Commitment & Consistency). The message emphasizes that the rest of the project team has already reviewed the document (Social Proof) and that feedback is needed within the next hour before a client presentation (Scarcity).

Numbers Game

And when they are not spearphishing, they're playing a numbers game. Attackers often succeed by casting a wide net. Take the classical example of a statistical filtering attack.

Statistical Filtering Attack

There are many technologies to combat phishing, including Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), Domain-based Message Authentication, Reporting and Conformance (DMARC), IP blacklisting, spam filtering, secure email gateways, URL filtering, attachment sandboxing, machine learning-based detection, threat intelligence platforms, browser protections, endpoint security tools, DNS filtering, and security awareness programs... I could go on. Even so, no combination of tools eliminates risk entirely. Human error remains a constant factor, and attackers only need to succeed once, oh and they know it. A single mistaken click or credential entry can be enough to compromise an otherwise well defended environment. Assume that you will be phished, no one is immune to it. Not even the biggest cybersecurity gurus out there. A notable example involves Troy Hunt, a prominent figure in cybersecurity, who ironically fell victim to a phishing attack and subsequently found his own information listed on his website, HaveIBeenPwned.com.

DECIDE

The DECIDE model is a structured decision making process used in aviation to help pilots handle in flight problems systematically. It stands for Detect, Estimate, Choose, Identify, Do, and Evaluate. The pilot first detects that a change or problem exists, then estimates its significance. Next, they choose a course of action, identify how to carry it out, execute the decision, and finally evaluate whether the outcome solved the issue or if further action is needed. It is used mainly in aeronautical decision-making training to reduce errors under stress and improve consistency in problem solving.

Well, why limit it to aviation only? Brains are much like airplanes, after all. Modern planes rely on autopilot for long stretches of flight, and the human brain does something similar when handling repetitive, low attention tasks like going through 100 emails. That same 'autopilot' state can become a weakness in phishing situations, where a convincing message can slip past careful scrutiny because the reader is moving too quickly and not fully switching back into deliberate checking mode. This model can be adopted when DECIDEing to click, or tap, depending on your input device.

StepAction
DetectNotice triggers such as urgency, authority pressure, account warnings, or unexpected requests.
ExamineVerify sender identity and destination independently. Do not rely on display names or branding. Check full email headers or hover links.
CorroborateCross-check the request using a separate trusted channel (official site, app, or known contact method). Never use embedded links.
InterruptIf anything is suspicious, stop interaction immediately. No replies, no clicks, no downloads.
DefendImmediately protect accounts by changing passwords, revoking sessions, and blocking further access.
EvaluateReview what signals were misleading and update your personal filters or rules accordingly.

Practice builds mastery. It may feel like overkill to go through all of this before a click is executed, but muscle memory is a real advantage we all have. What feels difficult today becomes automatic tomorrow. DECIDE now, and stay safe out there.