Social Engineering…

Hello everyone, from time to time we will be posting how-to blogs as well as information that we think will be helpful for you in your day-to-day business and virtual living spaces. Today we are going to be talking about a critical topic known as “Social Engineering”.
What is Social Engineering?
From Wiki –
Social engineering, in the context of information security, refers to psychological manipulation of people into performing actions or divulging confidential information. A type of confidence trick for the purpose of information gathering, fraud, or system access, it differs from a traditional “con” in that it is often one of many steps in a more complex fraud scheme.
The term “social engineering” as an act of psychological manipulation is also associated with the social sciences, but its usage has caught on among computer and information security professionals.[1]
In less words – when people try to be nice to get you to divulge information that is confidential or that they can use to harm the company or sell info.
It is very important for you to protect your business and your customer data. The first step to this is the education of your employees to things like social engineering. This can come in all sorts of ways – phone calls, emails and even office visits from someone trying to “sell” you something often called “cold calls”. How can you protect against this? How can you protect your customers data? Are there signs that a person might be attempting to socially engineer your employees? These are all great questions. The second item to protect your business is to create a policy around what data can be shared with others and when. Now I know that policies are viewed as somewhat of a negative topic within organizations – and to be honest – yes they can be. However, the reason for this is that there are so many of them and half of them don’t make sense to those reading them and a third of them seem to make things more difficult to accomplish.
Sometimes it is hard for us to tell what is helpful versus hindering by just looking at the surface, and often times these policies have carried over from past employees that wrote them (and with good intent) but may not be relevant to the way you operate business today. It is a good practice to review these policies and make sure that you are running as efficient as possible and protected as much as you can be.
If you would like for Tier1 to help you evaluate this please contact us and let us help take some of the burdens off your own plates. Let’s face it – reviewing policy is not fun and is tedious and may be tied to emotion when done internally. Sometimes a third party neutral viewing is exactly what is needed to help shape the needs of the company without having a formed opinion of what is in place and why. Tier1 is also available to attempt to social engineer your company and help formulate a plan to educate the users – staying steps ahead of the bad guys is something that often makes the difference in keeping your info secure.
Until next time –
Happy computing and looking forward to hearing from you
Chris
We're Here To Help!
info@tier1networkz.com
Hours
M-F: 8am - 10pm
Call Us
937.422.7351
We Want to Say Thanks!
To all of our active and veteran military members, contact us to learn about our discounted prices.
