Security Information

Social Engineering - The Real E-Terrorism?


One evening, during the graveyard shift, an AOL technical support operator took a call from a hacker. During the hour long conversation the hacker mentioned he had a car for sale. The technical support operator expressed an interest so the hacker sent him an e-mail with a photo of the car attached. When the operator opened the attachment it created a back door that opened a connection out of AOL's network, through the firewall, allowing the hacker full access to the entire internal network of AOL with very little effort on the hacker's part.

The above is a true story and it is an excellent example of one of the biggest threats to an organisation's security - social engineering. It has been described as people hacking and it generally means persuading someone inside a company to volunteer information or assistance.

Examples of techniques employed by hackers include:

  • Unobtrusively observing over your shoulder as you key in your password or PIN.

  • Calling helpdesks with questions or being overly friendly

  • Pretending to be someone in authority.

Social engineering attacks can have devastating consequences for the businesses involved. Accounts can be lost, sensitive information can be compromised, competitive advantage can be wiped out and reputation can be destroyed.

By implementing some simple techniques you can reduce the risk of your organisation becoming a victim or, in the event that you are targeted, keep the consequences to a minimum.

  • Make sure that all staff, especially non-IT staff, are aware of the risk of social engineering and what to do in the event of such an attack.

  • Conduct regular security awareness training so that all staff are kept up to date with security related issues.

  • Implement a formal incident reporting mechanism for all security related incidents to ensure there is a rapid response to any breaches.

  • Ensure that the company has security policies and procedures in place, that all staff are aware of them and that they are followed.

  • Put an information classification system in place to protect sensitive information.

Conduct regular audits, not only on IT systems but also on policies, procedures and personnel so that any potential weaknesses can be addressed as soon as possible.

About The Author

Rhona Aylward has extensive experience in the area of Quality Management and more recently in Information Security Management. She is a qualified Lead Auditor for BS7799 and CEO for Alpha Squared Solutions Ltd.

www.a2solutions.co.uk, raylward@a2solutions.co.uk


MORE RESOURCES:

Voice of America

Security Council wants UN peacekeepers in Somalia
The Associated Press - 14 hours ago
UNITED NATIONS (AP) — The Security Council unanimously approved a resolution on Thursday calling for a UN political presence in conflict-wracked Somalia for ...
UN Security Council Supports Possible Peacekeepers for Somalia Voice of America
Security Council express strong support for Secretary-General's ... ReliefWeb (press release)
Resolution urges UN Somalia force Aljazeera.net
AFP - PR-Inside.com (Pressemitteilung)
all 87 news articles


eFluxMedia

Verizon wins Homeland Security contract
ZDNet - 19 hours ago
Verizon picked up a huge contract from the Department of Homeland Security: a $670 million deal to provide IP and security services over 10 years, ...
Verizon and AT&T Win Homeland Security Contract RedOrbit
Verizon land 10-year deal to unify DHS networks Register
Verizon to supply Homeland Security TeleGeography
FOXBusiness - Reuters
all 179 news articles


PRESS TV

Iran calls UN Security Council sanctions illegal, proposes new talks
International Herald Tribune, France - May 15, 2008
AP VIENNA, Austria: Iran slams UN Security Council sanctions against it as illegal in a letter to Secretary General Ban Ki-moon that has been seen by The ...
Tehran hands proposals to Russia, China on nuclear security RIA Novosti
Iran Calls UN Sanctions Illegal Fars News Agency
Tehran maps out initiative to resolve host of key international ... Daily Star - Lebanon
Reuters - Fars News Agency
all 180 news articles


CISF takes over security of Bangalore airport
Business Standard, India - 2 hours ago
In preparation for the launch of the Bengaluru International Airport, the Central Industrial Security Force (CISF) has been handed over the responsibility ...


DigitalJournal.com

Out of place in heartland
Chicago Tribune, United States - 8 hours ago
Charged by the feds with either: 1) "making false representations about Social Security numbers," 2) "aggravated identity theft" or both, 390 workers were ...
Video: ICE Agents Raid Meat Packing Plant AssociatedPress
Letters for Friday Dallas Morning News
Court kept busy by parade of detainees Waterloo Cedar Falls Courier
WHO-TV - Chicago Tribune
all 835 news articles


Security cameras stolen from Taj Mahal
NDTV.com, India - 2 hours ago
And to reach this gem of architecture, tourists have to go through three layers of security and 34 cameras. Fifteen of the security cameras watching the Taj ...


Qld Health housing audit finds 'extreme' security risks
ABC Online, Australia - 12 hours ago
Mr Robertson says some of the safety concerns relate to poorly maintained smoke alarms, bad external security lighting and a lack of security screens on ...
Most health staff quarters 'unsafe' The Australian
Move to ramp up nurses' safety Toowoomba Chronicle
Security risks found in Qld Health housing ABC Online
ABC Online
all 15 news articles


Stonesoft Security in Virtual Environments
ZDNet - 4 hours ago
As I mentioned in the post, Virtualization and security, quite a number of suppliers focused on security in virtualized environments have come forward to ...


National Security Act to be amended: Moily
Business Standard, India - 2 hours ago
PTI / Hubli May 16, 2008, 18:30 IST The National Security Act (NSA) will soon be amended to strengthen anti-terror legislations in the country, ...


AFP

Canada may abandon bid for Security Council seat: media
AFP - May 14, 2008
OTTAWA (AFP) — Canada may abandon its bid for a two-year-term seat on the UN Security Council in 2010-2012, to avoid potential embarrassment in the event it ...
National security – it’s now a private matter Canada Free Press
Harper Must Answer Canadians’ Questions on National Security Liberal.ca (press release)
Bloc calls for Bernier security probe Toronto Star
AHN - Globe and Mail
all 378 news articles

Security - Google News

home | site map

Visit our other sites:
GamesBlog | GamingDepot | GimmeaRide | GimmeNetwork | Golf Biz | HotorNotGame | I Want Computers | I Want Games | I Want Hosting | I Want Music | I Want Security | JokeBox | ScriptShock | Wantedfonts | Webalize
© 2006