The Cyber Security Review | Tuesday, December 14, 2021
Fundamentally, social engineering is the skill of exploiting human nature.
FREMONT, CA: Social engineering is a psychological attack on a business or organization that takes advantage of people's natural inclination to trust others. A social engineer creates a familiar pretext and then exploits targets' cognitive biases to lull them into a false sense of security and faith. In summary, the attacker creates an alter ego in which targets are expected to have implicit faith.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
The attacker uses this fabricated trust relationship to coerce targets into disclosing sensitive information or doing an action they would not ordinarily perform. Some of the exposed data, such as credentials, may be the attacker's ultimate purpose. Other information, such as the name of a department manager, may be used to accomplish a goal.
These are four frequently used social engineering techniques:
Social engineering assaults carried out over the phone: Attackers call targets and direct them to phishing sites or request sensitive data.
In-person social engineering attacks: Attackers pose as maintenance employees, construction workers, or other similarly fictitious occupations to access restricted places.
Tailgating: Attackers act as staff and pursue authorized individuals through closed doors and into restricted areas.
Third-party social engineering attacks: Attackers approach targets via a third party—that is, someone who is not affiliated with the target organization. The objective is to infect an individual's phone or computer with malware, which will subsequently connect to the network of the target enterprise. A third party could be a dating or social networking website.
Check Out This: Construction Demolition and Recycling
How can a business protect itself from a social engineering attack?
Assessments by the red team: Many organizations conduct red team assessments to identify areas for improvement to mitigate the damage caused by social engineering infiltration. A red team evaluation simulates a real-world social engineering attack scenario. The value of a red team assessment is that the assessors can recommend measures that will better the organization's overall security posture while also being customized to the organization's business goals.
Awareness training: Social engineering awareness training is one of the most effective defenses against social engineering attacks. Such training will make staff aware of potential dangers and instill a healthy suspicion of suspicious conduct. The ultimate objective of this type of training is to build a business culture that values sound judgment and action—for example, prohibiting tailgating, confronting suspicious individuals, validating the identification of unfamiliar individuals before divulging sensitive information, and reporting suspicious activities.
Secure architecture: A secure system is designed from the ground up to anticipate that one or more components may get hacked at some point. As a result, secure systems incorporate fail-safes that automatically limit the collateral damage caused by such failures. Following a secure design and architecture assessment, these design characteristics can be implemented retroactively to a system.
More in News