Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 78 guests and 1 member online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Social Engineeringarrow Social Engineering emphasis in security program
EH-Net
May 26, 2012, 07:24:57 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Social Engineering emphasis in security program  (Read 1932 times)
0 Members and 1 Guest are viewing this topic.
l33t5h@rk
Guest
« on: October 05, 2011, 10:24:12 PM »

I'm looking to overhaul our current security awareness program and I've been reading a lot of Lance Spitzner's blog and it does seem like social engineering is increasing in quality at an incredible rate. I'm curious how often anyone doing sec. awareness training updates the social engineering topics or what are some of the methods used for this topic. Any information would be helpful.
Logged
cd1zz
Sr. Member
****
Offline Offline

Posts: 393


View Profile WWW
« Reply #1 on: October 05, 2011, 10:52:07 PM »

Here is what's been successful for us:

  • Try to discuss things that could impact their personal lives, like online banking, stolen email creds etc and how that would impact their personal lives. This seems to get people to listen and pay attention. After they're listening you can explain how these same tactics can impact your business.
  • I've found that live demo's that aren't too technical but prove a point are very effective. Using the sound recorder or web cam modules in metasploit are perfect for this. We've noticed that people begin to really pay attention when they see this.
  • Keep your meeting short and sweet, otherwise no one will take anything away and it will be a waste of time. Try to drive home a few points but don't over saturate them.
  • A little paranoia can go a long way, but don't scare them.

Bottom line for us is trying to "hook" the audience early so our users actually might learn something and become a little less risky on the network Smiley  These things have been very effective for us.
Logged

l33t5h@rk
Guest
« Reply #2 on: October 06, 2011, 08:34:54 PM »

Thanks cd1zz.

I definitely have enough paranoia to go around (why else would I be in infosec field) but I liked the spin on the personal lives. Most of the current program focuses on company resources and generally people could care less apart from just signing off on the "I completed the mandatory training" paper. As everyone uses their company internet for personal reasons these days, it could provide a nice eye opener.
Logged
Jamie.R
Hero Member
*****
Offline Offline

Posts: 626



View Profile WWW
« Reply #3 on: October 10, 2011, 05:22:28 AM »

I agree social engineering is I would say the most affective way to get access. As humans we alway want to trust people and sometimes are afraid to ask question we just take people for face value.

I agree with cd1zz comments I think the training process is a life cycle and should alway try keep employee on there toes about the subject.

Live demo and trying to map the situation to them is a good way to get the message across.

Logged

OSWP | eCPPT | HackingDojo Nidan
www.jamierougive.co.uk
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.132 seconds with 22 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.