Activity 01
Role-Play: Phishing Phone Call Simulation
In pairs, one student plays an attacker using a provided pretexting script (e.g., IT helpdesk asking for password verification) and the other plays a target employee. After two minutes, they switch and debrief: what psychological triggers were used and what questions would have exposed the deception?
Explain why the human element is often the weakest link in security.
Facilitation TipDuring the phishing phone call simulation, provide each student with a role card that includes a clear pretext and emotional trigger to practice, ensuring everyone experiences the pressure tactics feel real.
What to look forProvide students with three short scenarios describing potential cyber threats. Ask them to identify which scenario is an example of social engineering, name the specific tactic used (e.g., phishing, pretexting), and explain why it works.