Social engineering is currently the ultimate con! The fraudsters are incredibly knowledgeable and have the resources to easily penetrate and infiltrate systems with thefts, breaches, and more. They will lie, convincingly and successfully, cheat, and steal their way past your organization's security controls, most likely with little trouble, if you do not have the proper security. Their goals: theft, fraud, malice, espionage, and more! Your best line of defense: ensuring that your staff acquires the necessary knowledge, precautions, and possible responses.
Fraud incidents are on the rise - especially in financial services and healthcare - and many of these crimes result from social engineers achieving deception in person, via the telephone, and/or through popular social networking sites. Being cognizant of these types of attacks, and educating your employees about the methodologies, signs, triggers, and techniques of these attacks, and having plans in place to respond and rectify them, are absolutely essential to surviving these manipulations.
Despite all the media hype about the threats from hackers and viruses, the greatest threats to an organization's information security are actually the employees of the company! They are the people who, too often, too willingly, and too ignorantly and obliviously fall victim to Social Engineering ploys, opening your company's doors wide open to slick-tongued fraudsters, theft, viruses, breaches, and much more.
When an intruder targets an organization for attack, be it for theft, fraud, economic espionage, or any other reason, the first step is reconnaissance. They need to learn as much information as they can about their target. The easiest way to conduct this task is by scamming employees, those who know the company best, for this information through slick, devious tactics. Their information gathering can range from simple phone calls to dumpster diving. It is not beneath a social engineer to use any and all the terrible tricks in the book to obtain their goals.
With 22 years of experience and certifications in CEH, CISSP, CHFI, CISA, CGEIT, and more, we specialize in Security, Compliance and Risk Management. We deliver analyst prepared reports, NOT stock canned output from scan tools.