THREATS WITHIN SOCIAL ENGINEERING
2
Threats Within Social Engineering
Article Reference
Workman, M. (2007). Gaining access with social engineering: An empirical study of the threat.
Information Systems Security, 16(6), 315.
Summary
In the study conducted by Michael Workman “Wisecrackers: A Theory-Grounded
Investigation of Phishing and Pretext Social Engineering Threats to Information Security”
Workman goes over different types of threats and vulnerabilities that are targeted at social
engineering such as phishing which is the exploit of impersonating a third part to gain access
(Greitzer & Strozer, 2014) and the effects that they can cause to businesses and individuals. In
the article Workman highlights the technologies that have been through ongoing development to
help mitigate some of the threats that affect social engineering such as risk analyses, risk
mitigation, and the addition of more advanced cryptography all these procedures have been
implemented to provide more security. With the current security systems that are designed to
address social engineering threats there needs to be a lot done to ensure the safety of a businesses
information as well as the employees. Some of the ways criminals can use social engineering to
be able to pull off a scam or hack to steal information can be very easy for them such as walking
into a business without a badge or card and get past the security measures by simply acting as if
they worked there and maintained confidence while doing so. Another common method is
gaining the trust of an employee and acquire their password or send a malicious link that mocks
a website or program to grab their login information.
THREATS WITHIN SOCIAL ENGINEERING
3
Results
With the study completed Workman mentions in the article that people who are in a
higher normative commitment will succumb to social engineering more frequently than those
who are lower in normative commitment (Workman, 2007). It seems that the best way to
mitigate these attacks is not as easy as one would think, and it is harder to be able to protect a
business completely against someone using social engineering. Some of the best methods that
have been found to protect a business against social engineering is by educating yourself and all
your employees on the subject and show them scenarios in which social engineering could be
used against them and the business. The author continues to point out that likeability, trust and
the ability to be persuaded becomes a threat and a huge risk for the security systems that combat
social engineering. The employees who could potentially be deceived easily could become a
threat to the company as well by potentially downloading malicious software that the social
engineer has tricked the employee into downloading onto a business network. Some of the
software could be a disguised keylogger or another type of malware which could lead to having
company data stolen such as sensitive information including passwords, usernames, and
confidential files. Through Workman’s study he also concluded that employees who are more
obedient to authoritative commands will end up succumbing to social engineering schemes more
frequently than others who are less obedient (Workman, 2007).
Discussion
With these vulnerabilities within the security of social engineering mentioned there are
plans and policies that can be put into place that would help reduce the risk of these attacks
happening to businesses such as putting a policy into effect that would stop all employees from
THREATS WITHIN SOCIAL ENGINEERING
4
letting unknown people into the building by holding the door open for someone who has said
they have forgotten their key or employee card on them and implementing better security plans
that have the goal of stopping people from using social engineering to try to obtain sensitive
information. With the right polices and security plans put into use and education employees on
what to be aware of certain aspects of social engineering threats could be mitigated more than
they have before.
THREATS WITHIN SOCIAL ENGINEERING
5
References
Workman, M. (2007). Gaining access with social engineering: An empirical study of the threat.
Information Systems Security, 16(6), 315.
Greitzer, F. L., Strozer, J. R., Cohen, S., Moore, A. P., Mundie, D., & Cowley, J. (2014).
Analysis of unintentional insider threats deriving from social engineering exploits. Paper
presented at the 236-250. doi:10.1109/SPW.2014.39
Workman, M. (2008). Wisecrackers: A theory-grounded investigation of phishing and pretext
social engineering threats to information security. Journal of the American Society for
Information Science and Technology, 59(4), 662-674. doi:10.1002/asi.20779
Powered by TCPDF (www.tcpdf.org)