A busy table with staff sitting around it and many.

Why Social Engineering Works

Modern work is fast, interrupted and cognitively demanding. People are expected to make decisions quickly, switch between tasks constantly, and respond to messages in real time. This environment matters when considering how individuals actually think and behave, particularly as social engineering and business email compromise attacks continue to grow in sophistication.

Behavioural science helps explain why these attacks succeed. Psychologist Daniel Kahneman, in Thinking, Fast and Slow, describes two modes of cognitive processing: System 1 and System 2 thinking. System 1 is fast, automatic and requires little effort. It allows people to make quick judgements based on experience and pattern recognition. System 2 is slower, more deliberate and requires conscious attention and reflection.

In high-pressure environments, people default to System 1 thinking. Emails, messages and requests are processed quickly, often on autopilot. Expecting individuals to consistently switch into slow, reflective System 2 thinking and recall policies or training content in the moment is unreliable.

Cognitive Load and Decision-Making

Cognitive load refers to the total mental effort being used at any given time. Behaviour is shaped by context, habit, time pressure and mental effort. When workloads are high and interruptions are constant, people naturally rely on heuristics. These are mental shortcuts that simplify decision-making in complex situations.

Heuristics are not flaws. They are essential for functioning effectively under pressure. However, they are exactly what attackers exploit. Social engineering attacks mirror legitimate workflows, creating situations that feel familiar and urgent. This combination triggers fast thinking and automatic responses, allowing attackers to bypass traditional safeguards.

How Redflags Applies Behavioural Science

Redflags uses behavioural insights to detect abnormal patterns at the point of decision-making. Instead of relying solely on awareness or abstract guidance, it focuses on recognising when context and behaviour diverge from what is expected.

According to the UK Government’s Cyber Security Breaches Survey 2025, 43% of UK businesses reported experiencing a cyber breach or attack in the last 12 months, with phishing attacks remaining the most common threat vector. Redflags can identify subtle deviations from normal workflow and alert users before mistakes occur. By understanding how people operate under pressure, Redflags turns behavioural science into practical defence.

Practical Steps to Reduce Human Risk

Understanding cognitive load, fast thinking and behavioural shortcuts is critical to addressing modern attacks. Organisations can improve human risk management by:

  • Designing workflows with cognitive load in mind. Reduce unnecessary interruptions and provide clear, structured processes.

  • Applying behavioural detection tools like Redflags. Use technology that supports decision-making rather than relying solely on training.

  • Focusing on context, not blame. People make fast decisions for a reason. Controls should account for how employees actually work.

By aligning security practices with human behaviour, organisations make it harder for attackers to succeed and protect both people and data.

Key Takeaways

  • Fast thinking and cognitive shortcuts are natural, not negligent.

  • Social engineering exploits these mental patterns.

  • Behavioural science can inform practical defence strategies.

  • Redflags integrates these insights into real-time risk detection, helping organisations stay one step ahead.