Organisations that run on trust have something special to protect. Donors, members, clients, volunteers, and partners assume that their data is secure, that communication is reliable, and that employees act with care.

But precisely that trust is being abused more and more often.

Phishing and social engineering are clear examples of this. It's no longer just about poorly written emails with suspicious links. Modern attacks are often more personal, credible, and better timed. A message appears to come from a colleague, supplier, bank, donor, IT helpdesk, or well-known software provider. The tone is professional, the context is correct, and the urgency feels real.

And that's precisely where the risk lies.

Social engineering doesn't start with technology, but with behaviour

In social engineering, criminals try to influence people to do something they normally wouldn't. Think about clicking on a link, logging into a fake website, approving a payment, installing software, or sharing sensitive information.

Phishing is one of the best-known forms of this. The National Cyber Security Centre describes phishing as a method by which malicious actors try to penetrate organisations or obtain sensitive data. Often, such a phishing message is not the endpoint, but the beginning of an attack: first gaining access, then looking around, expanding rights, and finally stealing data or money.

This is what makes phishing so treacherous. The damage often arises not at the moment of the click, but in everything that becomes possible afterwards.

Why phishing is becoming increasingly difficult to recognise

Previously, you could often recognise phishing by spelling mistakes, odd sentences, or sloppy formatting. That time is largely over. With the help of AI, criminals can quickly write, translate, personalise and adapt professional texts to a specific target audience.

This means that old tips like “watch out for language errors” are no longer enough. Of course, language, sender, and links remain important, but the better question is:

Does this request fit with what we normally do?

An email can look perfectly legitimate and yet still be dangerous. A request may appear to come from a well-known organisation and yet still be a scam. A message may refer to genuine information, which is precisely what makes it all the more convincing.

Think, for example, of a message that addresses a donor, member, or customer with details that appear to be accurate. If someone knows who your customers are, what reservations you've made, which organisation you support, or which system you use, a phishing message becomes much more credible.

Why organisations that run on trust are extra vulnerable

Charitable organisations, member organisations, care providers, and other impact organisations are often structured relationally. Employees want to help. Donor services want to respond quickly. Finance wants to correct errors neatly. Project teams rely on partners. IT or Salesforce administrators want to resolve blockers so that work can continue.

Helpfulness is a strength. But without clear agreements, it can also become a vulnerability.

An employee pressured into doing a “quick” payment check. A colleague opening a link because it appears to be from a known supplier. A service employee wanting to help a donor and therefore skipping a normal check. These are not silly mistakes. They are human reactions in situations where someone is trying to abuse trust.

Therefore, it's important not to frame phishing and social engineering as an individual vigilance issue. It's an organisational problem.

The most important signs of social engineering

A suspicious request is not always technically complex. Often, the danger lies precisely in the pressure that is applied.

Pay particular attention to requests where someone:

  • swift action required;

  • confidentiality emphasized;

  • to work outside the normal process;

  • requests login details, MFA codes, or remote access;

  • requests a payment or refund;

  • to change a bank account, email address, or contact person;

  • A link leads to a login page.;

  • an unusual channel is used, such as WhatsApp for something that would normally go via email or Salesforce.

A practical rule of thumb is:

The more urgent a request feels, the more important it is to slow down.

Awareness is needed, but not enough

Training and awareness remain important. Employees need to know how phishing works and what signs are suspicious. However, organisations shouldn't act as if everything depends on one alert employee.

It's true that even well-trained people can sometimes click the wrong thing. Especially on busy days. Especially if a message is well-crafted. Especially if the request seems to come from someone in authority.

Therefore, the organisation must be structured in such a way that a single human error does not immediately cause major damage.

That requires three layers.

  1. The first layer is behaviourStaff learn to slow down, check, and report.
  2. The second layer is ProcessThere are clear agreements on payment requests, refunds, data requests, supplier changes, and incident reports.
  3. The third layer is technologysystems are configured to limit damage. Consider MFA, restricted permissions, good logging, monitoring, and secure Salesforce configuration.

Only when those three layers work together, does true digital resilience emerge.

Reporting culture: better too soon than too late

An important condition is a healthy reporting culture. Employees must dare to report suspicious messages or situations, even if they might have already clicked.

An organisation that primarily responds with guilt, shame, or blame makes itself more vulnerable. People will then wait longer to report things. While speed is precisely crucial.

A good security culture does not say: “Never make mistakes.”

A good security culture says:

“Let's get together quickly so we can limit the damage and learn from it.”

This calls for clear reporting routes. Who do you call? Where do you send a suspicious message? What do you do if you have entered details anyway? Who decides whether accounts, sessions or permissions are temporarily revoked?

Without that clarity, people will improvise. And improvisation is precisely what social engineering exploits.

What has Salesforce got to do with this?

For many impact organisations, Salesforce is a core system. It holds relationships, donors, members, cases, programme information, marketing data and reports. If an account is misused, the damage depends heavily on how Salesforce is configured.

  • Does the user have access to too much data?

  • Are export duties restricted?

  • Is MFA configured correctly?

  • Are old accounts closed?

  • Are permission sets still current?

  • Are suspicious logins checked?

  • Are couplings and API users still needed?

Phishing may start with a human, but the impact is often determined by systems, permissions, and processes.

Therefore, phishing resilience shouldn't just be an IT or security concern. It also involves Salesforce administration, finance, fundraising, operations, marketing, and management.

How TwoPurpose views this

At TwoPurpose, we examine digital resilience through the lens of impact organisations’ practical experience. Not just from a technical perspective, but also from an organisational one.

Because a good Salesforce setup only helps if the processes are correct. Phishing training only helps if employees know what to do afterwards. And policy only helps if it is feasible for the people who work daily with donors, members, customers or partners.

This is why we look at the coherence between people, processes, and technology. Where does pressure arise? Where do exceptions occur? Which systems contain sensitive data? Which rights are truly necessary? Which connections are open? And how do you ensure employees can act safely without the organisation becoming rigid or distrustful?

Security is not a brake on impact. Good security protects the trust on which impact organisations build.

Abuse of human trust

Phishing and social engineering exploit human trust. While that trust is a strength for impact organisations, it is also a vulnerability.

The solution isn't just: pay more attention. The solution is: ensuring that employees, processes, and systems reinforce each other.

The main question is therefore not:

Are our employees able to recognise phishing?

But:

Are our people, processes, and systems arranged so that one misleading request does not directly cause major damage?