One evening, during the graveyard shift, an AOL technical support operator took a call from a hacker. During the hour long conversation the hacker mentioned he had a car for sale. The technical support operator expressed an interest so the hacker sent him an e-mail with a photo of the car attached. When the operator opened the attachment it created a back door that opened a connection out of AOL's network, through the firewall, allowing the hacker full access to the entire internal network of AOL with very little effort on the hacker's part.
The above is a true story and it is an excellent example of one of the biggest threats to an organisation's security - social engineering. It has been described as people hacking and it generally means persuading someone inside a company to volunteer information or assistance.
Examples of techniques employed by hackers include:
Social engineering attacks can have devastating consequences for the businesses involved. Accounts can be lost, sensitive information can be compromised, competitive advantage can be wiped out and reputation can be destroyed.
By implementing some simple techniques you can reduce the risk of your organisation becoming a victim or, in the event that you are targeted, keep the consequences to a minimum.
Conduct regular audits, not only on IT systems but also on policies, procedures and personnel so that any potential weaknesses can be addressed as soon as possible.
About The Author
Rhona Aylward has extensive experience in the area of Quality Management and more recently in Information Security Management. She is a qualified Lead Auditor for BS7799 and CEO for Alpha Squared Solutions Ltd.
www.a2solutions.co.uk, raylward@a2solutions.co.uk





Imagine my surprise when I received a phone call from a friend who told me... Read More
There is no doubt that "how-to articles" have become a separate genre. One can find... Read More
From the "Ask Booster" column in the June 17, 2005 issue of Booster's Auction News,... Read More
We all know that it's dangerous to use the same password for more than one... Read More
Identity theft ? also known as ID theft, identity fraud and ID fraud ? describes... Read More
Spies, spyware, internet parasites are among what they are usually called. These are scouts that... Read More
Spyware is the most troublesome software to appear on the Internet in recent times. When... Read More
Business on the internet is getting down right shameless. This week, my email box was... Read More
Every single time you access a website, you leave tracks. Tracks that others can access.... Read More
With the Internet entering our lives in such an explosive manner, it was inevitable that... Read More
In 1997, I decided after 15 years as a practicing... Read More
The E-Mail Identity Theft Scam is running Rampant. These E-Mail... Read More
This is not some new fangled techno-speak, it is a... Read More
Do you really have to know how feeds work? Not... Read More
Before you enter your name, address or any other data... Read More
Recently I have received email from my bank/credit Card Company,... Read More
Someone recently told me, "You would have to be a... Read More
Let us take the example of scrambling an egg. First,... Read More
File sharing on p2p is soaring despite the music and... Read More
The menacing campaigns that drive the corporate spyware and adware... Read More
The Message Must Get Through ----------------------------- The year is 300A.D.,... Read More
One evening, during the graveyard shift, an AOL technical support... Read More
A new variation of the Nigerian Scam theme ... Read More
A couple of days ago, I was searching for a... Read More
Have you ever got an email asking you to confirm... Read More
Spyware symptoms happen when your computer gets bogged down with... Read More
Is your enterprise following the rules?The bulk of financial information... Read More
There is no doubt that "how-to articles" have become a... Read More
So you want to know who your kids are chatting... Read More
I'm in the Anti-Spyware business, and I'm doing a lot... Read More
The Federal Bureau of Investigation has identified "phishing" as the... Read More
It seems that nowadays cybercriminals prefer cash to fun. That... Read More
The Threat10 years ago you could probably have run no... Read More
Can you protect your computer from all possible viruses and... Read More
Credit card fraud is a growing problem for online businesses... Read More
Internet Security |