I agree with sysmin about giving examples. Mitnick's book has plenty of them it seems, though I haven't read it yet and couldn't tell you for sure. I'm going off of what I've seen flipping through. And if I had to guess, I'd say a few probably actually happened...which would be even better.

Along with the whole psychology thing, human nature seems to be rather trusting...we want to trust each other. So maybe finding someting along those lines.

Also, the culture of a particular organization has a bunch to say about how vulnerable they are to such an attack. Are they paranoid (like they should be) or at ease and laid back? Do they follow their security policy to the T, etc...

Just some extra stuff to think about if you haven't already.

alpha