Computer Security - Preventing Social Engineering Attacks

Social Engineering in its basic form is hacker talk for3. Outside Contractors - Outside contractors should
manipulating computer users out of their username andhave a security liaison to monitor their activities.
password. Social engineering really goes beyond justSecurity liaisons should be briefed on what work the
usernames and passwords. A well planned socialcontractor is hired to perform, area of operation,
engineering attack can destroy companies. All of theidentity of contractor and if the contractor will be
most devastating information thefts have used someremoving items from the work site.
sort of social engineering attack. Social engineering is4. Dumpster Diving - The easiest way to get
so effective because computer admins and securityinformation about anyone is to go through their trash.
experts spend all their time patching systems and notShredders should be used in all cases or shredding
training employees about information security.services should be hired. Also, the Dumpster should be
Information security goes beyond patching computers,in a secure location and under surveillance.
it is a combination of physical security, computer5. Secretaries - They are your first line of defense,
network policy and employee training.train them to not let anyone into your building unless
This article will describe many of the common securitythey are for certain whom they are. Security cameras
flaws that information thieves take advantage off andshould be place in the main entrance way and also on
how you can prevent them.the outside of the building. A thief who is probing your
1. Web sites Information - Company web sites are thenetwork will test to see if he is challenged upon
best place to start when gathering information. Often aentering the building, cameras can help identify patterns
company will post all their employees names, emailand suspicious people.
addresses, positions and phone numbers for everyone6. NO PASSWORDS - Make it company policy that
to see. You want to limit the number of employeesthe tech department will never call you or email you
and phone numbers listed on a web site. Also, liveasking for your username or password. If somebody
active links to employee email addresses should bedoes call and ask for a password or username red
avoided. A common mistake is a company's emailflags will go up every where.
user name will be the same as their network logon,7. LOG OFF - Social Engineering attacks get the
example: email address of has a user name of jsmithhacker into the building and they will usually find many
for the network with the same password for emailworkstations where the user hasn't logged off. Make it
and the network.company policy that all users must log off their
2. Phone Scams - Scamming someone on a phone isworkstations every time they leave it. If the policy is
very simple. Company employees need to be trainednot followed then the employee should be written up
to be courteous but cautious when giving callersor docked pay. Don't make a hacker's job any easier
information over the phone. One hacking scam is athan it already is.
hacker will call a company posing as computer8. Training - Information security training is a must for
salesmen. The salesmen will ask the secretary whatany size company. Information security is a layered
type of computers they have, do they have a wirelessapproach that starts with the physical structure of the
network and what type of operating systems they run.building down to how each work station is configured.
Hackers can use this information to plan their attack onThe more layers your security plan has the harder it is
the network. Train your employees to refer any ITfor an information thief to accomplish his mission.
related questions to Tech Support.