skip to content

How do you price the claim that serious attackers write a bespoke phishing lure per person?

level: seniorimportance: should knowfreq 45%

answer

  1. answer in hours, not adjectives
  2. forty recipients, two hours each
  3. about two operator-weeks, and less
  4. tailoring prices the message, not the sender
  5. selection is a signal, polish is not

basics

~10 s

In operator hours the claim is cheap: forty recipients at two hours each is roughly two operator-weeks, and much of that reading is shared across all forty. Tailoring prices the message, not the sender.

solid answer

~40 s

The claim smuggles in an inference from effort to capability, and the arithmetic refuses it. Two hours of reading published material per recipient, across forty recipients, is roughly eighty operator hours - two weeks of one person - and the true figure is lower because the organisation-level facts are collected once and reused across all forty. Nothing in that requires capability beyond literacy, patience and a target's own public surface. So tailoring prices the message, not the sender: it tells you an hour or two went into this one, and it tells you nothing about budget, persistence or what follows a successful landing. The practical consequence is that plans which treat tailored, contextually correct lures as a rare, high-end event are mispriced. Tailoring is the routine case and should be the planning assumption.

go deeper

for a junior

Recall that tailored messages are common and cheap to produce, and that a convincing message is not evidence of an unusually capable sender.

for a middle

Be able to do the arithmetic aloud: recipients times per-person hours, minus the organisation-level research that is collected once and reused.

for a senior

Defend the claim under pushback and draw the consequence - controls that depend on the reader noticing implausibility are priced against the cheap rung only.

for a principal

Own the planning baseline this sets. Assume a credible request reaches your people, and direct spend at what survives a perfect message rather than at making lures look wrong.

### The claim and the hidden step 'Serious attackers write a bespoke lure per person' sounds like a statement about attackers. It is actually two statements glued together: that bespoke lures exist, which is true, and that writing one is expensive enough to be diagnostic of a well-resourced sender, which is false. The second half is where interviews probe, because it is the assumption that quietly sets the wrong planning baseline. ### Answer it in hours The discipline is to refuse adjectives and produce a number. Take forty named recipients at one organisation. Nominal research is two hours each. That is eighty operator hours, or about two weeks of one person's time - the labour cost of a fortnight, not of a programme. And eighty overstates it, because the research decomposes into a shared block and a small increment. The name of the expense system, the hostname pattern, who signs payments, the department structure and the shape of the weekly process are organisation-level: paid once, reused forty times. The per-person part - reporting line, current project, plausible timing - is tens of minutes. Realistically the crew spends a day or two on the organisation and a morning on the batch of people. So the honest price of 'bespoke per person' is: cheap, repeatable, and available to anyone who can read. ### What tailoring does and does not predict What it predicts: that someone spent one to two hours on this specific recipient, and that they chose your organisation rather than reaching it by accident. That second part is genuinely informative - selection is a real signal, and it is different from polish. What it does not predict: budget, staffing, persistence, or what happens after a credential is entered. Reading the sender's resources off the quality of a message is the same error as reading a burglar's sophistication off the neatness of their handwriting. The message is the cheapest artefact in the entire operation. ### The corollary that actually changes decisions If tailoring is cheap, three planning conclusions follow. First, a control chosen on the assumption that lures will look wrong is a control with a short shelf life. Anything whose value depends on the reader spotting implausibility is priced against the cheap rung only. Second, the planning default should be that a credible, contextually correct request will reach the people you care about, and the useful question is what survives that. Control classes that do not depend on the reader's judgment - authentication that cannot be relayed to an attacker-controlled site, an out-of-band confirmation bound to the specific ask, a payment-change process that requires a second path - keep working when the message is perfect. Third, the small share of genuinely expensive social engineering lies somewhere other than in writing. Facts that are not on the public surface, and time that cannot be amortised across recipients, are the expensive inputs. Tailored prose is not one of them. ### What a rushed research budget looks like A useful inversion: when an operator's hours run short, the person-level increment is the first thing dropped, because it is the only part that does not amortise. The organisation-level facts survive, since they were already paid for. The result is a lure that is exactly right about the company - correct system name, correct process, correct signatory - and vague or generic about the individual. That shape is the visible edge of a research budget, not evidence of a lazy adversary. ### How to say it in an interview Give the number first, then the decomposition, then the consequence. 'About two operator-weeks for forty people, and less than that because the company-level facts are shared. So tailoring tells me hours were spent on the message, not who spent them, and I would not plan on lures looking wrong.' That answer demonstrates the thing the question is testing: that you can defend a claim about what an adversary can afford with arithmetic rather than atmosphere.

  • If tailoring is cheap, what part of social engineering is genuinely expensive?
    Two things: facts that are not on the public surface, which have to be obtained some other way, and time that cannot be amortised across recipients. Writing fluent, specific prose is neither. Any cost argument that rests on the effort of composing the message is arguing about the cheapest input in the operation.
  • An operator's hours run short mid-campaign. What does the lure look like?
    Right about the organisation and vague about the person. The company-level facts were already paid for and stay in, while the per-recipient increment - reporting line, current project, timing - is the only part that repeats, so it is the first thing cut. That mismatch is the visible edge of a research budget.
  • Does a tailored lure at least prove the sender chose your organisation deliberately?
    That inference is much safer than inferring resources. Organisation-specific facts have to be gathered for a specific organisation, so their presence indicates selection rather than accident. It still says nothing about how much stands behind the operation or how long the sender intends to persist.

saying these in an interview costs you the question

  • Reads adversary resources off how polished a message is
  • Assumes per-person tailoring implies weeks of work
  • Prices attacker effort in adjectives rather than hours
  • Treats contextually correct lures as a rare high-end event
  • Plans controls on the assumption lures will look wrong

context