Richard Frost | Head | Technology Solutions & Consulting | Armata | mail me |
Attackers aren’t breaking in; they’re being invited, and the invitations are being written by the business. The easiest way to install malware on a business network is to persuade someone inside the business to do it.
Attackers don’t always need to bypass the firewall or exploit a zero-day vulnerability. Sometimes, all it takes is a convincing email, a moment of misplaced confidence and trust.
Thirty years of security investment have gone into hardening perimeters and strengthening systems. However, almost none has gone into the instinct that opens the door from the inside. Trust has become the most pernicious attack surface in 2026, and yet it remains the least defended. In this environment, the new attack surface is not simply technological. It is human.
The psychology behind the new attack surface
People trust inherently. They trust that the person calling and claiming to be the receptionist of a client is exactly who they say they are. They trust that the email from a colleague is just that, an email from a colleague.
Unfortunately, modern phishing is crafted around psychological triggers. Attackers aim their tactics at how a person thinks rather than how a network is configured. Understanding the attacker now means understanding human behaviour. That includes the behaviour of intelligent, driven C-suite executives or leaders who are too busy to pay attention.
A great example is an email about an FNB account sent to a Nedbank customer. The recipient knows it isn’t theirs, but they open it anyway to find out what the email is about. It could be a preferential interest rate or a sales pitch that leans into the current market’s need for cost-effective customer service.
This is trust dressed as curiosity. It is enough to create vulnerability in the business when the recipient clicks on the link to open a new account and instead releases malware into the system. The same weakness sits behind an unexpected payslip or the year-end bonus nobody was promised. Attackers aren’t targeting the sceptic. They are targeting the hopeful moment.
When businesses reveal their own defences
Companies are also handing over their defences voluntarily. If a sales representative asks what antivirus and email security the company runs, and the client answers in full, they are sharing very specific information with a stranger they just met.
A company running only the entry-level Microsoft tier for endpoint and email has now just identified itself as a soft target in under ten minutes. Nobody needs the password anymore. They just need an idea of the shape of the fence so they can design an attack that can clamber over it.
The best possible approach here is to stop any security conversation before the NDA has been signed. Otherwise, the new attack surface can include information that the business has voluntarily disclosed about its own security environment.
Trust also extends far beyond the people that a business can see. Third-party service providers have become a high-risk entry point for the business. Their systems are often not as complex and high-end as those of the enterprises they serve.
A contractor who works for your third-party contractor can accidentally send an invoice that infects the chain. The security system didn’t assess the third-party trench-digging company that worked for the fibre installation company’s system. This is because they sit three to four degrees of separation from the network.
Politeness as an exploit
The same instinct operates at the business front of house when a visitor asks the receptionist to call the person they are ostensibly here to see. The receptionist helpfully leaves the desk to fetch the person. The attacker then uses this time to insert a USB drive into the machine at the front desk.
The environment is compromised before she returns, and she did nothing wrong. Politeness was the exploit. Another risk factor here is the visitor register. This can be easily photographed, and the attacker leaves with every name and detail on the page. They can then use that information to deepen their attack surface while putting the business in breach of POPIA. In this sense, the new attack surface extends beyond networks and devices. It also includes seemingly harmless physical processes and everyday interactions.
Executives also open doors to the business with their public LinkedIn profiles. Attackers can easily read these profiles without making a connection request. The amount of information shared on LinkedIn by a CEO or C-suite executive provides enough material for attackers to build a believable message.
That message can become convincing enough to open doors in the business. Locking these profiles is becoming increasingly important. It can help ensure that social engineering attempts remain limited from the outset.
Treating trust as a security control
Treating trust as a control starts with third-party governance. This approach should insist that suppliers provide in-depth security controls and insights to the business. However, it should equally respect where they are in the business.
A milk delivery service should not face the same standards as a high-level enterprise. Then, beneath this layer, sit the multi-layered basics. These prioritise endpoint and email security alongside threat detection and rapid mitigation.
The risk footprint has grown so large that it is becoming genuinely challenging for companies to protect against every infraction. Therefore, until security catches up with crime, companies need to treat trust the same way they would a link in an email: with suspicion.
