Skip over navigation

Social engineering tactics must be understood by businesses



    Date:
    7 May 2009

    Print friendly version

    ‘Social engineering’ is increasingly one of the most effective routes to stealing confidential data from organisations, warns new research from Siemens Enterprise Communications. 

    The professional services arm of Siemens Enterprise Communications recently ran a ‘social engineering’ exercise at a FTSE-listed financial services firm. A Siemens security consultant targeted the client company for a week to see what level of access to information he could achieve using social engineering tactics. Without the aid of any special equipment, the Siemens consultant was able to:

    • enter the company’s office without being challenged by security staff;
    • base himself in a third floor meeting room, where he worked for several days;
    • freely access different floors, store rooms (containing large amounts of confidential information), filing cabinets and confidential data left on desks; 
    • access the company’s data room, IT, and telecoms network;
    • use the internal telephone system to call employees, claiming to be from the IT department (backed up by the caller ID), and request information. Of 20 users targeted, 17 supplied their usernames and passwords, giving him easy access to confidential electronic data; and
    • establish that CCTV domes fitted on the ceilings were non-operational.

    “Social engineering is principally concerned with manipulating people into performing actions or divulging confidential information in order to access electronic or physical data,” says Colin Greenlees, a security and counter-fraud consultant for Siemens Enterprise Communications.

    “Hi-tech protection systems are completely ineffectual against such attacks, and most employees are utterly unaware that they are being manipulated. Worryingly, many staff positively assisted with information being compromised.

    “The scary thing is that it’s all simple stuff. It’s just confidence, looking the part and basic trickery such as ‘tailgating’ people through swipe card operated doors or, if you’re really going for it, carrying two cups of coffee and waiting for people to hold doors open for you.”

    During the week of the FTSE exercise, the Siemens consultant befriended a number of employees at the target company and was even on first name terms with the foyer security guard. On two separate occasions, he was even able to escort a second Siemens consultant into the building who was able to perform further analysis of the company’s IT network.

    “Most security experts agree that dishonest employees are the greatest risk to company data leaking outside an organisation, many of whom are working with a criminal gang before they even enter employment,” says Greenlees. “However, social engineering that tricks genuine employees into providing access to confidential data is a fast growing issue. It’s important that senior executives understand how easy this is, but also how they can effectively counter the threat by actually practicing what they preach.”

    Related topics:

    Add a comment


    Send me an email-alert when someone comments in this discussion:

    Please remember that your name and comment will be visible to all users of the Network, and that we may edit or remove comments without notice. Terms and conditions


    This document is for general guidance and research purposes only, and does not purport to give professional advice. Please check the date at the top of the article; the Workplace Law Network retains historic articles for general research.