Security: How Can You Patch People?
People are just as critical as technology in safeguarding your network, says Terry Greer-King of Check Point
Organisations often overlook the human fallibility factor and don’t train or engage their workforce in helping protect their sensitive information. This is the case despite heavy investment being made in the deployment of point products used to guard corporate networks when, in fact, combatting a wide range of security threats requires a strong combination of technology and user awareness.
Human targets on the rise
Hacking techniques that focus on exploiting employees, such as social engineering, are certainly on the rise. Nearly half of UK enterprises have been the victim of 25 or more such attacks in the past two years, with spear phishing via email and social networks being the most common attack vectors. At an average cost of £15,000 per incident this is a threat businesses can ill-afford to ignore.
Driving this trend are two main factors. First, for many UK employers, there is a lack of policy guidelines or employee training programs in place. And second, there is a rise in the number of social media platforms now available – each providing a wealth of on-tap information about individuals and the organisations they are employed by. With this information, hackers create profiles on people, customising target attacks to create new entry points into an organisation and increasing the likelihood an attack will succeed.
Once inside, the hacker can use a series of tools to work their way up the food chain to board-level staff, giving them unrestricted access to commercially sensitive data. But how do these attacks happen and what methods do hackers employ?
Social networking reconnaissance
Unlike a brute force through the front door approach, social engineering attacks require more finesse and planning. Surveillance is the key to knowing a potential ‘mark’ and provides would-be hackers with answers to critical questions including:
- Key personnel – who are the gatekeepers?
- Security policies – what does the organisation have in place?
- Encrypted traffic – is outbound SSL traffic allowed out of business hours?
Continued on page 2