Employees or users are often considered the weakest link in security, and are typically the greatest threat to any organization in today's world. They are not likely to be well versed in security best practices, and often won't care about them. They are often more concerned about getting the job done as quickly and easily as possible. Therefore, this can be easily exploited.
As part of our penetration test, I will show you some examples of social engineering attacks designed around passwords. Hashing a password or guessing a password can be tough, and can take a long time, but it can usually be done. But, if I can just get the user to give me the password, it will save me a lot of work in the long run. This is the main reason why social engineering attacks are important, and why I will talk about three different kinds of attack now.