Attackers aren’t breaking in; they’re being invited, and the invitations are being written by the business, says Richard Frost, Head of Technology Solutions and Consulting at Armata Cyber Security.
The easiest way to install malware on a business network is to persuade someone inside the business to do it. Attackers don’t always need to bypass the firewall or exploit a zero-day vulnerability. Sometimes, all it takes is a convincing email and a moment of misplaced confidence and trust. Thirty years of security investment have gone into hardening perimeters and strengthening systems, but almost none has gone into the instinct that opens the door from the inside. Trust has become the most pernicious attack surface in 2026, and yet it remains the least defended.
People trust inherently. They trust that the person calling and claiming to be the receptionist of a client is exactly who they say they are. They trust that the email from a colleague is just that, an email from a colleague. Unfortunately, modern phishing is crafted around psychological triggers and aimed at how a person thinks rather than how a network is configured. Understanding the attacker now means understanding human behaviour, and that includes the behaviour of intelligent, driven C-suite executives or leaders who are too busy to pay attention.
A great example is an email about an FNB account sent to a Nedbank customer. The recipient knows it isn’t theirs, but they open it anyway to find out what the email is about. It could be a preferential interest rate or a sales pitch that leans into the current market’s need for cost-effective customer service. This is trust dressed as curiosity, and it is enough to create vulnerability in the business when the recipient clicks on the link to open a new account and instead releases malware into the system. The same weakness sits behind an unexpected payslip or the year-end bonus nobody was promised – attackers aren’t targeting the sceptic; they are targeting the hopeful moment.
Companies are also handing over their defences voluntarily. If a sales representative asks what antivirus and email security the company runs, and the client answers in full, they are sharing very specific information with a stranger they just met. A company running only the entry-level Microsoft tier for endpoint and email has now just identified itself as a soft target in under ten minutes. Nobody needs the password anymore; they just need an idea of the shape of the fence so they can design an attack that can clamber over it. The best possible approach here is to stop any security conversation before the NDA has been signed.
Trust also extends far beyond the people that a business can see. Third-party service providers have become a high-risk entry point for the business as their systems are often not as complex and high-end as those of the enterprises they serve. A contractor who works for your third-party contractor can accidentally send an invoice that infects the chain. The security system didn’t assess the third-party trench-digging company that worked for the fibre installation company’s system because they sit three to four degrees of separation from the network.
The same instinct operates at the business front of house when a visitor asks the receptionist to call the person they are ostensibly here to see. The receptionist helpfully leaves the desk to fetch the person, and the attacker then uses this time to insert a USB drive into the machine at the front desk. The environment is compromised before she returns and she did nothing wrong. Politeness was the exploit. Another risk factor here is the visitor register – this can be easily photographed and the attacker leaves with every name and detail on the page, which they can then use to deepen their attack surface while putting the business in breach of POPIA.
Executives also open doors to the business with their public LinkedIn profiles that are easily read without attackers having to make a connection request. The amount of information shared on LinkedIn by a CEO or C-suite executive is enough material for attackers to build a message that is believable enough to open doors in the business. Locking these profiles is becoming increasingly important to ensure that social engineering attempts are limited from the outset.
Treating trust as a control starts with third-party governance that insists suppliers provide in-depth security controls and insights to the business, but that equally respects where they are in the business. A milk delivery service should not be held to the same standards as a high-level enterprise. Then, beneath this layer sits the multi-layered basics that prioritise endpoint and email security alongside threat detection and rapid mitigation. The risk footprint has grown so large that it is becoming genuinely challenging for companies to protect against every infraction, so until security catches up with crime, companies need to treat trust the same way they would a link in an email – with suspicion.



