Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Upright And Under Cover
Articles

Upright And Under Cover

ISBuzz TeamBy ISBuzz TeamMay 28, 2018Updated:July 8, 20246 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Sarka Pekarova, Cybersecurity Consultant at SureCloud looks at how social engineering can help improve data security

Organizations worldwide invest billions of dollars in cybersecurity technology each year. The latest estimations by Gartner predict that $93 billion will be spent on solutions in 2018, and for good reason. Those looking to protect sensitive data and prevent costly downtime need technology. According to estimates by Accenture, cybercrime cost US businesses an average of $11.7M in 2017, when organizations suffered an average of 130 successful data breaches per company; 27% more than the previous year. Cybersecurity software is an essential weapon in the ongoing fight against insidious cybercriminals, but it’s not the only unit that can be deployed.

While we face this onslaught of cyber threats, we are held more accountable for our security posture. On May 25, 2018, the EU will enforce the General Data Protection Regulation (GDPR). From then, regulators can apply hefty fines to businesses failing to safeguard EU citizens’ data. In today’s increasingly regulated world, cybersecurity software provides an essential layer of protection against a breach and the potential fine that could come with it.

However, what’s often overlooked are the physical access points, where criminals can steal data and information in person. If you can see something, you can look after it, right? Not necessarily – just ask one of our social engineers, who shows companies how easy it could be for a cyber-criminal to walk in and escape with their most precious assets.

What is social engineering?

Using cybersecurity experts who are on the front lines of prevention daily, social engineering emulates a targeted attack using the samesophisticated tactics of genuine threat actors. Companies from every sector use the results to raise awareness throughout the company and transform their employees into their best defence.

It’s the job of social engineers to think like a hacker.  They blag their way into buildings, access confidential documents, and walk out with laptops. This sneaking around tests the limits of our customer’s security and demonstrates how easy it would be for a cyber-criminal to gain access to sensitive information and expensive hardware.

Social engineers are successful because they blend in. Just like a potential cybercriminal, they don’t look dangerous, malicious or suspicious. They dress like any other office worker and engage in friendly chat with their “colleagues,” often pretending they’re a visitor from another office or partner company.

What can social engineers get away with?

On a typical mission, social engineers will walk in with a list of questions. They aim to get away with anything a malicious hacker would try.

They get past card readers without a card to swipe and have staff open doors to offices and staff-only areas. They manipulate people into believing a made-up pretext, and even to hand over sensitive information.

Once they’re trusted, the social engineer will plug into the network and attempt to compromise information. They access confidential documents left at printers and have been known to walk out with laptops easily. Staff leave them alone in server rooms, where they’re trusted with the office’s data like any reliable employee.

How do they do it?

At the beginning of a typical engagement, a social engineer will try to find out anything they can about the target. They start by gathering Open Source Intelligence (OSINT). Using a fake LinkedIn profile, they hunt for anything from which they can build their pretext. The organization might list their partner companies or suppliers, so they could say they have come as a representative of one of those third parties.

The sleuthing continues using social media, where social engineers can find out which employees are on holiday, what staff wear to work, and if they’re lucky, find a picture with a staff pass on view that they can replicate.

Nobody usually challenges them; once they make their way into the offices, their pretext works. As “someone from head office,” they have an air of authority. When inside, they give a plausible story. They might be coming to gather asset IDs of all laptops, printers, servers and phones, for example.

The chances are, their polite and personable employees don’t like to see a fellow member of staff struggling, so when our social engineers hold on to a coffee cup and a clipboard and stand helplessly by secure entrances, doors are politely held for them and the company’s staff will swipe them in. Sometimes though, they just walk straight in and over to the staff-only areas. They make it look like they know exactly what they’re doing, and nobody asks any questions. Social engineers know how to read people, and they know how to blend in using the same skills as cybercriminals.

These techniques are employed in certain circumstances, depending on the possible points of compromise. They’re not always used.

Lessons Learned

While all this sneaking around might sound intrusive, it’s done for a very important reason. The client has asked to be targeted, and at the end of the invasion they get an overview of their security posture without losing any of the data taken on the job.

When each mission ends, the client will get some good news and some bad news. Maybe they’ve done some good things by placing their data centre behind security doors, but these can be bypassed. Maybe they’re locking confidential documents in filing cabinets, but an artfully twisted hairpin could open these easily. The client is taught exactly how important security awareness is within the company, and how much needs to change.

This isn’t about telling your employees they shouldn’t be nice or helpful. We work through all the information gathered to raise awareness across the entire organization. Maybe it will encourage them to raise concerns if someone with no proof of identity other than a printed piece of paper in a badge holder is hanging around.

It’s an important lesson, and it’s only through a realistic, rigorous simulated attack that the limits of your organization’s physical security can be truly tested.

[su_box title=”About Sarka Pekarova” style=”noise” box_color=”#336588″][short_info id=’105421′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}