What is baiting?
Baiting is a social engineering technique where an attacker uses a physical “decoy” to trick someone into a careless action that undermines security. Think of abandoned USB sticks, external hard drives or seemingly innocent charging cables that someone picks up or connects, or attentions that can unlock confidential spaces or devices. In a test, the aim is not to cause damage, but to measure how employees react to tempting objects and whether there are procedures that prohibit the use of unknown media or devices.