Archive · 2021–2022
Writing
Nine posts on social engineering, phishing, and why people believe the emails they shouldn't. All first published on this site between January 2021 and May 2022, and kept here as they were written.
These are not backdated. Every post below appeared on james-linton.com at the date shown. The Internet Archive's capture of the original blog index, taken on 4 February 2024, lists all nine posts with the same titles and dates - you can check it here.
12 MAY 2022Scammers won’t hold back, why should we?
Simulated phish have unique traits no sender can hide from…
30 MAR 2022Ask&Do™ - The transactional relationship that gives life to email
Over email, we can ask someone to do something, and we can be asked to do something, too.
03 OCT 2021Design & UX is cyber body language
We digest phishing emails visually, so the design language and user experience they present to us is critical to their success.
28 JUL 2021CEO vs Scammer
You don’t only have to target biological or cognitive processes to be a successful social engineer…
11 JUN 2021Failure Dynamics
Phishing simulations will deliver failure to someone. Some thoughts on where the response to that failure could go…
04 MAY 2021Hacking a Hacker
Would I socially engineer a social engineer again? No. It wasn’t fair, and it was just showing off. But it does show how much OSINT a ‘crafted’ attack…
04 MAY 2021Cyber Social Engineering
Processes + UX + Social Engineering = Cyber Social Engineering…. Should it be a ‘thing?’ I’m not sure…
01 FEB 2021Inbox Hypnotism™
Being ‘in the zone’ is great for work, but it’s not great for making security decisions…
28 JAN 2021BattlePhish™ — Gamification of phishing employees
This explores one way of reimagining employee phishing simulations. Let employees phish each other…