Knowledgebase

Understanding Social Engineering Assessment Print

  • 0

Testing people rather than systems.

WHAT IT INVOLVES

Attempting to obtain access or information by deceiving people, with authorisation.

WHAT FORMS IT TAKES

Simulated phishing messages Telephone approaches Attempts to gain physical access Requests for information

WHY IT IS ASSESSED

People are the route used in most real compromises.

WHY IT REQUIRES PARTICULAR CARE

It involves deceiving your own staff, and it can cause real harm to individuals.

WHAT TO ESTABLISH BEFORE COMMISSIONING IT

What the objective is How results will be used Whether individuals will be identified What support exists for those who fail

WHY THAT LAST POINT

Staff who are deceived frequently feel humiliated, and it affects whether they report real incidents.

WHAT TO ESTABLISH

That the purpose is improving defences, not identifying individuals for blame.

WHAT TO AVOID

Naming individuals in reports Disciplining those who failed Scenarios that are cruel or exploit personal circumstances

WHY

They produce fear, and fear produces concealment of real incidents.

WHAT TO PREFER

Aggregate results, and training as the response.

WHAT TO ESTABLISH ABOUT SCENARIOS

That they are realistic but not distressing.

WHAT TO EXCLUDE

Scenarios involving personal matters Scenarios suggesting job loss or emergencies Anything that would cause genuine distress

WHAT TO PROVIDE AFTERWARDS

Explanation to those involved Training on what to look for Recognition of those who reported it

WHY RECOGNITION

Reporting is the behaviour you want, and it should be visibly valued.

WHAT TO MEASURE

Reporting rate, as much as failure rate.

WHY

A workforce that reports quickly is better than one that never clicks.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot