Publication: Combatting social engineering attacks in South Africa: a critical analysis
Loading...
Date
Authors
Journal Title
Journal ISSN
Volume Title
Publisher
North-West University
Abstract
Social engineering has emerged as one of the most pervasive and damaging forms of cyber-enabled crime, exploiting human psychology rather than technological vulnerabilities. In the South African context, the increasing sophistication of these attacks poses serious risks to individuals, businesses and state institutions, resulting in financial losses, reputational harm and public distrust of digital systems. Despite legislative efforts through the Cybercrimes Act 19 of 2020 and the Electronic Communications and Transactions Act 25 of 2002, gaps persist in behavioural awareness, criminological enforcement and organisational preparedness. These shortcomings collectively undermine national cyber resilience and contribute to South Africa's vulnerability to social engineering attacks. The main objective of this study was to critically analyse how social engineering attacks can be effectively combatted in South Africa through an interdisciplinary framework that integrates legal, psychological, criminological and cybersecurity perspectives. In order to meet this overarching objective, the following areas were critically examined: The operational and behavioural foundations of social engineering attacks. This analysis identified the common manipulation techniques, offender motivations and cognitive biases that enable deception-based cybercrimes such as phishing, pretexting and baiting. South Africa's legal and institutional response to social engineering. This involved an evaluation of the Cybercrimes Act 19 of 2020 and Electronic Communications and Transactions Act 25 of 2002 to determine their effectiveness in addressing social engineering attacks, as well as identifying enforcement, awareness and policy gaps that impede their implementation. The study adopted a qualitative research design grounded in an interdisciplinary literature review to evaluate both the human and systemic dimensions of social engineering. The study synthesised insights across the four analytical domains and identified recurring deficiencies in user awareness, reactive law enforcement and the limited integration of behavioural science within cybersecurity practice. In conclusion, the findings demonstrate that while South Africa has made legislative progress in addressing cyber-enabled offences, the current framework remains fragmented and overly reliant on legal compliance rather than behavioural resilience. The study recommends a national strategy that incorporates behaviourally informed awareness programmes, criminological profiling of offenders, enhanced digital literacy education and cross-sector collaboration to enhance proactive defence mechanisms. Future research should further explore how interdisciplinary cooperation between law enforcement, academia and the private sector can embed behavioural science principles into national cybersecurity policy. South Africa can move towards a more sustainable and adaptive model of cyber resilience by adopting this integrated approach, one that not only prosecutes cybercrime but also prevents its human exploitation at scale.
Description
Thesis, Master of Commerce in Forensic Accountancy -- North-West University, Potchefstroom
