Cryptzone: Education central to defeating social engineering attacks

Responding to a five-year analysis of data from Google’s Safe Browsing service, Cryptzone says that it is clear that the threat landscape of today has evolved considerably from that of just five years ago.

According to Grant Taylor, UK vice-president of the European IT threat mitigation specialist, five years ago a then-fledgling Facebook was just three years old, whilst Twitter was only a year old, having been launched in July of 2006.

“What has happened in the intervening period is that the Internet has become a lot more social – and, with it, has come a communications revolution with both business and consumer users of the web interacting with each other as never before. This has significantly raised the threat profile of almost every user as a consequence,” he said.

“In parallel with this, security vendors have developed more sophisticated technologies to stop attacks, making the task of executing technical exploits by hackers a lot more difficult,” he added.

The problem with the trend of rising levels of social engineering, Taylor explained, is that it primarily exploits human weaknesses, so is almost impossible to prevent using technical controls.

"In the IT security industry we obsess about data protection, but the reality is that many employees remain completely unaware of the value of the information they work with from day to day. As a result they become complacent about protecting it. User education backed up by well communicated policies and procedures - is the best way to help people understand the security implications of their actions.

“Only by raising user awareness to the potential threats and keeping people permanently on their toes to identify when they are being manipulated to reveal confidential information – or provide a piece of the security puzzle for data thieves to steal valuable corporate assets – can we hope to counter this social phenomenon,” he said.

    Share Story:

YOU MIGHT ALSO LIKE


Resilience Rooted in Reality
In this podcast, CIR speaks to CLDigital’s Tejas Katwala about why organisations must move beyond checklist compliance to build living, data driven resilience. He explains how rethinking governance, risk and compliance, breaking down silos and focusing on value streams can create sustainable, real time resilience that is rooted in the way businesses actually operate today.

Building cyber resilience in a complex threat landscape
Cyber threats are evolving faster than ever. This episode explores how organisations can strengthen defences, embed resilience, and navigate regulatory and human challenges in an increasingly complex digital environment.