Social engineering is the 'greatest security risk'

The greatest security risk facing large companies and individual Internet users over the next ten years will be the increasingly sophisticated use of social engineering to bypass IT security defences, according to analyst firm Gartner.

Gartner defines social engineering as "the manipulation of people, rather than machines, to successfully breach the security systems of an enterprise or a consumer". This involves criminals persuading a user to click on a link or open an attachment that they probably know they shouldn't.

Rich Mogull, research director for information security and risk at Gartner, said social engineering is more of a problem than hacking.

"People, by nature, are unpredictable and susceptible to manipulation and persuasion. Studies show that humans have certain behavioural tendencies that can be exploited with careful manipulation.

"Many of the most-damaging security penetrations are, and will continue to be, due to social engineering, not electronic hacking or cracking," said Mogull.

According to Mogull, identity-theft is a major concern because more criminals are "reinventing old scams" using new technology.

"Criminals are using social engineering to take the identity of someone either for profit, or to gather further information on an enterprise. This is not only a violation of the business, but of someone's personal privacy," said Mogull.

Rob Forsyth, managing director at Sophos in Australia and New Zealand, told ZDNet Australia  about a 'malicious and cynical' scam that recently targeted unemployed Australians.

According to Forsyth, the potential victim received an e-mail that purported to come from Credit Suisse bank advertising a job opportunity. The e-mail asked the recipient to go to a Web site that was an almost exact replica of the actual Credit Suisse site -- but this version contained an application form for the 'vacancy'.

Forsyth said the replicated Web site was recreated so thoroughly that it took experts 'some time' to confirm that it was actually fake.

"It took us some time to determine it was a fake site. It was not necessarily groundbreaking but quite a clever combination of technology.

"They are targeting those people in the community that are most in need - those seeking work. It is exactly those people that might be vulnerable to this kind of overture," said Forsyth.

Gartner's Mogull said: "We believe social engineering is the single greatest security risk in the decade ahead".

Advertisement

Talkback 0 comments


Latest Videos

Blogs

  • Chris Duckett PayPal launches Aussie developer program
    PayPal announced the opening of its certification program for Australian developers today, making Australia the first country outside of the US to offer certification.
  • Array Cash cow in a BigTinCan?
    Around one third of Australia's telcos have shut their doors over time, but that isn't stopping new ventures hoping to chip away at carriers' mobile call bonanza. By fighting carriers at the smartphone rather than the home phone, could the latest two contenders be onto something big?
  • Array A third of the way to a zettabyte
    This week on Twisted Wire we look at how internet usage is changing in Australia and around the world. How are we meeting this demand and how is the cost structure changing for the service provider?
  • More blogs »

Tags

Back to top

Featured