Bug Watch: The threat of social engineering

It ain't what you do, it's the way that you do it

Written by Tim Ecott, Integralis

Advertisement

Each week vnunet.com asks a different expert from the IT security world to give their views on recent virus and security issues, with advice, warnings and information on the latest threats. This week Tim Ecott, managing consultant at IT security consultancy Integralis, looks at the threat of social engineering.

Be under no misconception - people who really want access to your company's data can get it. Technology provides the determined hacker with the ability to access unauthorised information, but it is their cunning that often gets them the initial foot in the door.

Social engineering is the name given to the non-technical processes that hackers will use to obtain information, yet there is seemingly little awareness of the threat that this poses to businesses.

There are several misconceptions about how companies can best protect themselves against attacks, intrusion and data leaks. Firewalls, passwords and smartcards can all work to provide businesses with a secure infrastructure, but frequently the biggest threat is overlooked.

Without being aware, employees can pose one of the greatest threats to company security. Conversations in the pub after work, using a laptop on the train, holding the door open for someone instead of making them swipe an ID card - all of these things can potentially compromise the overall security of a business.

All it takes is for a hacker to overhear a conversation mentioning company names, departments or projects, and they can begin to build-up insider knowledge to use to their advantage. Once a certain amount of inside information is gained, something as harmless as a telephone call can be used as a tool to obtain further privileged information.

By implementing an IT usage policy document, businesses can highlight to employees what social engineering is. To relay this information in a legally binding document helps employees to become more vigilant, by virtue of the fact that they are aware of the implications of their actions.

Once a user policy is in place, businesses need to further encourage the vigilance and diligence of employees in security matters. Organisations need to create a culture that makes employees understand their integral role in the security equation.

The process of convincing users to be alert to the threat of social engineering is by no means a simple task. Many of the most effective ways of reducing the vulnerability actually go against human nature: why wouldn't you hold the door open for someone if they had their hands full? Education is key to the implementation of an effective security strategy.

One way in which businesses can lessen the threat of social engineering is to have their defences tested for weaknesses. For example, penetration tests can cover everything from network security right through to how willing people are to volunteer information that will help a perpetrator to gain secure information. The tests are bespoke and can be as comprehensive and detailed as necessary to determine the risk level at which a business stands. They provide businesses with a clear picture of their weaknesses and allow them be proactive in preventing security breaches.

Tags:

Related articles

Related whitepapers

Related jobs

Do you agree?

Most commented stories

IT white papers

Search vnunet IThound

Top categories

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Watch

05 Sep 2008

8.64 MBPodcast Special: Views from the Valley More...

Podcast image

04 Sep 2008

12.7 MBComputing podcast 4 September 2008 More...

Podcast logo

02 Sep 2008

8.39 MBEco-Entrepreneur Podcast: Bulldog More...

Poll

INTERNET EXPLORER 8

INTERNET EXPLORER 8

Are you intending to download Internet Explorer 8 when it becomes available?

Previous poll results

Spotlight

LogMeIn Rescue+Mobile

BlackBerry gets LogMeIn remote support

Rescue+Mobile lets a support technician take control of the handset   More...

Dell manufacturing plant

Dell planning factory closures to cut costs

Report claims that PC maker is looking to sell off...  More...

Google Chrome

More growing pains for Chrome

Google wrestles with licensing and security problems   More...

Smartphone

US takes 3G crown from Europe

Americans finally catch up with Europeans in adoption of 3G   More...

Primary Navigation