Social Engineering - The Real E-Terrorism?


One evening, during the graveyard shift, an AOL technical support operator took a call from a hacker. During the hour long conversation the hacker mentioned he had a car for sale. The technical support operator expressed an interest so the hacker sent him an e-mail with a photo of the car attached. When the operator opened the attachment it created a back door that opened a connection out of AOL's network, through the firewall, allowing the hacker full access to the entire internal network of AOL with very little effort on the hacker's part.

The above is a true story and it is an excellent example of one of the biggest threats to an organisation's security - social engineering. It has been described as people hacking and it generally means persuading someone inside a company to volunteer information or assistance.

Examples of techniques employed by hackers include:

  • Unobtrusively observing over your shoulder as you key in your password or PIN.

  • Calling helpdesks with questions or being overly friendly

  • Pretending to be someone in authority.

Social engineering attacks can have devastating consequences for the businesses involved. Accounts can be lost, sensitive information can be compromised, competitive advantage can be wiped out and reputation can be destroyed.

By implementing some simple techniques you can reduce the risk of your organisation becoming a victim or, in the event that you are targeted, keep the consequences to a minimum.

  • Make sure that all staff, especially non-IT staff, are aware of the risk of social engineering and what to do in the event of such an attack.

  • Conduct regular security awareness training so that all staff are kept up to date with security related issues.

  • Implement a formal incident reporting mechanism for all security related incidents to ensure there is a rapid response to any breaches.

  • Ensure that the company has security policies and procedures in place, that all staff are aware of them and that they are followed.

  • Put an information classification system in place to protect sensitive information.

Conduct regular audits, not only on IT systems but also on policies, procedures and personnel so that any potential weaknesses can be addressed as soon as possible.

About The Author

Rhona Aylward has extensive experience in the area of Quality Management and more recently in Information Security Management. She is a qualified Lead Auditor for BS7799 and CEO for Alpha Squared Solutions Ltd.

www.a2solutions.co.uk, raylward@a2solutions.co.uk


MORE RESOURCES:
SMBs predicted to embrace hosted security - Techworld.com
SMBs predicted to embrace hosted security Techworld.com, UK - Sep 5, 2008 According to the analyst's Worldwide Web Security 2008-2012 Forecast, interest in hosted security will buck the troubled economy in developed countries to ...
Publ.Date : Fri, 05 Sep 2008 14:21:07 GMT

Clearswift Selected a 2008 Best Products and Services Winner In ... - MarketWatch
Market Wire (press release) Clearswift Selected a 2008 Best Products and Services Winner In ... MarketWatch - Sep 3, 2008 Clearswift makes it easy to deploy, manage and maintain no-compromise e-mail and Web security across all gateways and in all directions. ... About Network Products Guide Awards DMN Newswire (press release) iovation Wins Award for Best in Internet Security Business Wire (press release) all 30 news articles
Publ.Date : Wed, 03 Sep 2008 15:18:18 GMT

Social Security numbers exposed on Iowa land-records Web site - Computerworld
Social Security numbers exposed on Iowa land-records Web site Computerworld, MA - 21 hours ago The Web site provides online access to records from each of Iowa's 99 counties. Under a 2002 state law, Social Security numbers can't be included in public ...
Publ.Date : Fri, 05 Sep 2008 18:55:25 GMT

How do you guard IT against employees’ devices and Web 2.0 tools? - Financial Times
How do you guard IT against employees’ devices and Web 2.0 tools? Financial Times, UK - 15 hours ago Companies understand that some Web 2.0 tools are already considered mainstream for large portions of society. Today, security chiefs experience repeated ...
Publ.Date : Sat, 06 Sep 2008 00:08:00 GMT

MessageLabs Intelligence August 2008: Google's Picasa Web Albums ... - MarketWatch
MessageLabs Intelligence August 2008: Google's Picasa Web Albums ... MarketWatch - Sep 3, 2008 Web security : Analysis of Web security activity shows that 23.9 percent of all web -based malware intercepted was new in August. ... Spammers Use Free Web Services to Shield Links New York Times Spam Eating Surrender Monkeys iTWire all 18 news articles
Publ.Date : Wed, 03 Sep 2008 10:08:57 GMT

Security of Google's browser gets mixed marks - SecurityFocus
Times Online Security of Google's browser gets mixed marks SecurityFocus, CA - Sep 4, 2008 Yet, other features are missing, said Billy Hoffman, manager of Hewlett-Packard's Web security group. "They really have no features at all to help users ... Video: Tech Test: Google Chrome Lacks Polish AssociatedPress What are the security implications for Google Chrome? TechRepublic How Chrome puts the skids under Nokia Register Redmond Developer News - InternetNews.com all 3,448 news articles
Publ.Date : Thu, 04 Sep 2008 16:13:10 GMT

Another Google Chrome Security Flaw Identified - InformationWeek
Another Google Chrome Security Flaw Identified InformationWeek, NY - 13 minutes ago Vietnamese security company Bach Khoa Internet Security (BKIS) has found a flaw in Google Chrome 0.2.149.27 and posted details on its Web site. ...
Publ.Date : Sat, 06 Sep 2008 15:53:00 GMT
UBB Webdesign.com © 2008