Social Engineering Tests

Social Engineering Tests

Social engineering is the act of manipulating people into revealing private data and/or providing access to personal accounts or company computer systems.  These information thieves rely on trickery and deception while preying on individual goodwill.

A social engineering assessment provides a comprehensive review of how well an institution has actually implemented their information security program.  We spend undercover time on-site, attempting to infiltrate the staff and data processing system.  This is not intended to be a high tech break-in attempt.  While we may use some everyday IT equipment used in main stream computing, it’s really attempting to take advantage of human nature and gain access to information and the network through the users.

Our social engineering tests evaluate the people-side of security controls. Tests include simulated attempts to gain information through phone calls and/or in-person visits.

This process identifies staff procedural breaches.  Social engineering tests are recommended at least once per year and for all new hires.