
I was on a flight recently, minding my own business (mostly), when something caught my attention. A businessman was sitting in the middle seat and had his laptop open, knocking out emails before takeoff. Next to him was a woman casually reading every single word on his screen. There was no hiding or pretending on her part. In fact, I am not even sure she realized she was doing it. Maybe curiosity, or just plain boredom, got the best of her. Either way, she had access to information she was never meant to see.
That is called shoulder surfing, and despite the funny name, it is one of the oldest forms of social engineering.
We spend thousands of dollars on firewalls, endpoint protection, multifactor authentication, and cybersecurity training. Then we open confidential emails in public and give everyone nearby a front-row seat.
Let’s explore why social engineering goes beyond digital exploitation.

Social Engineering Is Not Always Digital
When most business owners hear “social engineering,” they think about fake invoices, phishing emails, or someone pretending to be IT support.
But social engineering is really about exploiting human behavior. People are naturally curious. When a nearby screen displays customer information, payroll numbers, legal documents, or an interesting email subject line, people may look. Sometimes they do it intentionally. Other times, it happens almost without thought. Either way, someone outside the company may see information that was meant to remain private.
What Can Be Learned From a Glance
The person looking at your screen may not see a password or confidential financial report, but that does not mean the information is useless.
A customer name, vendor relationship, employee issue, travel schedule, payment discussion, or upcoming meeting may be seen accidentally, out of simple curiosity, or by someone intentionally looking for information they can exploit. Once that information is exposed, you no longer control where it goes, how it is interpreted, or whether it becomes useful to a criminal.
Social engineering attacks are often built from small pieces of information. Even a quick glance can reveal who you work with, what your company is focused on, who has authority, and what may be happening behind the scenes. Those details can provide enough context to make a later phishing email, impersonation attempt, or fraudulent request feel familiar and believable.
How to Prevent Prying Eyes
I get it. Those few minutes at the airport, over lunch, or while waiting for your Uber can be a great time to knock out a few emails.
Here are a few simple habits that can make a meaningful difference when you are working in public:
- Use a privacy screen on your laptop, tablet, or phone.
- Position your screen away from nearby people and reduce the brightness when practical.
- Avoid opening highly sensitive emails, financial reports, contracts, payroll information, or employee records in public.
- Turn off lock-screen and desktop notification previews so private messages and subject lines do not appear unexpectedly.
- Use biometric sign-in and a password manager so you are not typing passwords where others can see them.
- Enable multifactor authentication in case login information is seen or stolen.
- Set devices to lock automatically after a short period and lock them manually whenever you step away.
- Use headphones for calls and avoid discussing client names, payment details, employee issues, or other sensitive information where others can hear.
- Use a mobile hotspot or trusted VPN instead of unsecured public Wi-Fi.
- Enable device tracking and remote wipe in case a laptop, tablet, or phone is lost or stolen.
These are small adjustments, but they reduce the amount of personal and business information you may expose without realizing it.
The businessman on my flight probably never knew someone was reading along with him, and that is what makes shoulder surfing easy to overlook. There is no alert, no warning, and usually no way to know what someone saw or what they may do with it later.
So, the next time you open your laptop in an airport, coffee shop, hotel lobby, or airplane, take a few precautions to prevent shoulder surfing. After all, cybersecurity does not stop at the edge of your network. It travels with you.

