
Starting my internship in Identity & Access Management at Orbital IAM, has opened my eyes to something I didn’t expect.
Exactly how much of cybersecurity isn’t just about technology, it’s about human behaviour.
One pattern I keep noticing is how often people respond to digital messages because of FOMO otherwise known as “The Fear of Missing Out”.
Before changing career to Cybersecurity, and more specifically working within IAM.
I thought FOMO was mostly about social media or events.
I had terrible FOMO in my teens and 20’s. Sometimes I still get it!
However, now I’m understanding how it plays a huge role in identity risk too.
I used to think a voicemail saying “Please call me back urgently” meant something serious.
Ill do the usual of letting an unknown number got to voicemail with the old thought of “If its important they’ll leave a message”
Now I am understanding that urgency is a tactic.
It’s designed to make us act before we think.
Calling back can reveal personal details, confirm your identity, or open the door to social engineering.
I have seen examples before coming into cybersecurity and IAM.
Emails that looked really convincing, but were prime examples of phishing.
Some said things like : “Your account will be suspended today” , “Claim your reward before midnight.”
You might think they are easy to spot however if they were, they wouldn’t continue to send them.
Which shows, at least some of the population are falling foul to them.
It’s fascinating and worrying, how easily these messages tap into our fear of missing something important.
FOMO can encourage people to click links or open attachments without checking the sender.
That’s often all an attacker will need.I’ve started paying more attention to how attackers use messaging apps.
A simple “Hi, is this you?” can make someone reply in seconds these days.
Replying confirms your number is active, and sometimes your identity too.
From there, attackers have a way in.
As someone building my professional network, I understand the temptation to accept every LinkedIn request.
But in IAM, I’m learning to slow down.
As a note from experience, profiles with no posts, no mutual connections, vague job titles and AI-generated photos are often created to gather information quietly.
I’m learning that accepting these requests can expose your job role, contact details, habits, and even your organisation’s structure.
All of this is valuable information for targeted attacks.
One of the biggest lessons I’ve learned so far is that IAM is about verifying trust.