Week 6: Hardening Users Against Social Engineering
Information security professionals invest effort and capital in building robust technical solutions and policies to harden our networks against attacks. However, all of this can be undone if our users aren’t aware of the policies—or fall victim to social engineering and violate the policies to help a “customer.” The 2019 Verizon data breach investigations report found that 33% of breaches included social attacks, illustrating the importance of security awareness at the basic user level. For example, a recent Princeton study (PDF link) found that telephone company employees regularly violated admittedly lax company authentication policies, which allowed attackers to reassign customer telephone numbers and bypass SMS-based two-factor authentication. This case underscores two problems: first, that telecom policies did not adequately protect customer account information, and second that customer service employees were too focused on what they perceived as their core function, hel...