Social Engineering - The Real E-Terrorism?


One evening, during the graveyard shift, an AOL technical support operator took a call from a hacker. During the hour long conversation the hacker mentioned he had a car for sale. The technical support operator expressed an interest so the hacker sent him an e-mail with a photo of the car attached. When the operator opened the attachment it created a back door that opened a connection out of AOL's network, through the firewall, allowing the hacker full access to the entire internal network of AOL with very little effort on the hacker's part.

The above is a true story and it is an excellent example of one of the biggest threats to an organisation's security - social engineering. It has been described as people hacking and it generally means persuading someone inside a company to volunteer information or assistance.

Examples of techniques employed by hackers include:

  • Unobtrusively observing over your shoulder as you key in your password or PIN.

  • Calling helpdesks with questions or being overly friendly

  • Pretending to be someone in authority.

Social engineering attacks can have devastating consequences for the businesses involved. Accounts can be lost, sensitive information can be compromised, competitive advantage can be wiped out and reputation can be destroyed.

By implementing some simple techniques you can reduce the risk of your organisation becoming a victim or, in the event that you are targeted, keep the consequences to a minimum.

  • Make sure that all staff, especially non-IT staff, are aware of the risk of social engineering and what to do in the event of such an attack.

  • Conduct regular security awareness training so that all staff are kept up to date with security related issues.

  • Implement a formal incident reporting mechanism for all security related incidents to ensure there is a rapid response to any breaches.

  • Ensure that the company has security policies and procedures in place, that all staff are aware of them and that they are followed.

  • Put an information classification system in place to protect sensitive information.

Conduct regular audits, not only on IT systems but also on policies, procedures and personnel so that any potential weaknesses can be addressed as soon as possible.

About The Author

Rhona Aylward has extensive experience in the area of Quality Management and more recently in Information Security Management. She is a qualified Lead Auditor for BS7799 and CEO for Alpha Squared Solutions Ltd.

www.a2solutions.co.uk, raylward@a2solutions.co.uk


MORE RESOURCES:


Dividend.com (blog)

Letters: Ideas on Social Security
Houston Chronicle
The editorial "Social Security at 75" (Page B11, Sunday), suggests older workers remain on the job past age 65, without requiring payments into the Social ...
3 Ways to Decide When to Claim Social SecurityU.S. News & World Report (blog)
We Should Leave Social Security AloneNewsweek
Social Security: Hot Topic for GOP UpstartsWall Street Journal (blog)
Huffington Post (blog) -Cape Cod Times -Reading Eagle
all 89 news articles »


Blue Arkansas (blog)

Alan Simpson's brash e-mail told truths about Social Security
Washington Post
But his fundamental point is correct: Social Security is not on a sustainable footing. In his e-mail, Mr. Simpson pointed to a presentation by the chief ...
Joe Miller: No Social Security For Future GenerationsHuffington Post (blog)
Al needs some honest workCasper Star-Tribune Online
Key House Dems urge Obama to oppose Social Security cutsThe Hill (blog)
Superior Telegram -The Week Magazine -In These Times
all 69 news articles »


Computerworld New Zealand

New Cloud Security Certification Launched
InformationWeek
The Cloud Security Alliance (CSA), an industry group seeking to promote security standards for cloud computing, is offering an online certification program ...
Cloud Security Alliance offers certificationNetworkWorld.com
IT Virtual-Security Certificate Showing ExpertiseTopNews United Kingdom (blog)
Cloud Security Alliance's User Certification Now AvailableDark Reading
PR.com (press release) -Marketwire (press release)
all 18 news articles »


Common Dreams (press release)

Factbox: Security developments in Afghanistan, Sept 4
Reuters
TAKHAR - Troops from NATO-led International Security Assistance Force (ISAF) and Afghan forces killed six insurgents in ground and air assault in northern ...
Factbox: Security developments in Afghanistan, Sept 3Reuters
US Defense Secretary & President Karzai: Step Up NATO-Led Security Efforts in ...Comtex Smartrend

all 400 news articles »


Globe and Mail

Fascism in Ramallah
The People's Voice (blog)
In recent days and weeks, ruthless and undisciplined Security forces have been suppressing public dissent, especially opposition to futile talks with Israel ...
Pressure is on Palestinians' West Bank security force to stem anti-settler ...Los Angeles Times
Abbas vows to ensure security in Palestinian territoryXinhua
Abbas: Security is keyJewish Telegraphic Agency
Ynetnews -Voice of America -Montreal Gazette
all 11,457 news articles »


Brisbane Times

Spammers Quick to Embrace Ping, Security Firm Says
New York Times (blog)
On a positive note, Sophos said iTunes 10 had fixed 13 security vulnerabilities. It recommends people upgrade their software. Spam and malware filtering is ...
Apple's Ping a Scammer's Haven? Security Experts Say Watch OutPC World
Ping under fire from spammers, says security firmipodnn
Apple iTunes 10 and Ping: Scam and spam heavenOnly Kent (blog)
InformationWeek -I4U -Threatpost (blog)
all 986 news articles »



New York Daily News

Fo'shizzle: Snoop Dogg partners with Norton security to fight cybercrime
New York Daily News
Rapper Snoop Dogg is the new public face for security software company Symantec's Norton and the, er, odd partnership has one mission: ...

and more »


Frank McCourt portrays wife as having an appetite for houses, financial security
Los Angeles Times (blog)
In his fourth day on the stand, Frank McCourt portrayed his wife, Jamie, as a woman with a voracious appetite for houses and financial security. ...

and more »

Google News



Home | Sitemap | About the site | Privacy policy | Contact Us


© 2009 Info-Feed.com. All Rights Reserved