If an unsual inquiry or email has an urgent plea, it's risky to act on. But many do.
Monday, March 8th 2010 @ 12:00 AM (not yet rated)
I often try to make the point that the human element is almost always the weakest link, and the easiest path of attack, for an enterprise. The article below by Dan Goodin of The Register gives some good examples of how this is the case. Security penetration testers, Mike Baily and Mike Murray, consistently illustrate how easy this is - just like with my Honey Stick Project.
http://www.theregister.co.uk/2010/03/04/social_penetration/
These guys just claimed a $10,000 prize for hacking the email account of StrongWebMail CEO, Darren Berkovitz.
They have a great observation in the following statement:
The come-ons often invoke a sense of urgency, such as an opportunity to make money only if the mark moves quickly. Scammers often try to form perceived bonds with their victims by thanking them for their attention or apologizing for an interruption. The ruses amount to hacks that suspend the marks' critical faculties just long enough to get them to make a critical mistake.
The bottom line is, if it's an unexpected message, and it has an urgent deadline, be VERY suspicious and check it out before taking action. Don't think the bad guys aren't every bit as inventive as these security testers.
| | Is your security awareness training just a set of old Powerpoint slides that you pull out once a year and present at an all-hands meeting? You can now provide much more effective security awareness training for your staff, for much less cost than you think. Contact me if you'd like to discuss how you can create a culture of security through a variety of live programs, and modern e-Learning techniques.
Scott Wright
The Streetwise Security Coach
Join the Streetwise Security Zone at: http://www.streetwise-security-zone.com/join.html
Phone: 1-613-693-0997 Email: scott@streetwise-security-zone.com Twitter ID: http://www.twitter.com/streetsec
To receive weekly security tips and other notices about helpful content available on this site, please make sure you are on my list by clicking HERE, and entering your name and email address.

|