RandomStorm publishes book on human nature security risks

Social Engineering Penetration Testing - RandomStormIT security management and compliance company, RandomStorm, has published a book explaining how organisations can perform structured tests to check for security vulnerabilities that are created by human weaknesses such as gullibility, pride and fear.

The book, “Social Engineering Penetration Testing,” was published by Elsevier on 30th June 2014 and is written for information security practitioners, network and computer system administrators and IT professionals. It portrays real life scenarios to help to train employees to recognise common social engineering tactics, to stop an attack in progress. Examples are provided showing how criminals have used phishing; telephone pre-texting and physical props to manipulate employees into divulging information, or performing activities on their behalf that compromise information security, or put physical assets at risk. Furthermore, the book provides detailed frameworks that enable organisations to assess how well a social engineering penetration test has been performed by their security auditor.

RandomStorm co-founder and technical director, Andrew Mason, was commissioned to write the book following a meeting with Elsevier at Infosecurity Europe last year. His co-writers are Richard Ackroyd and Gavin Watson, Senior Security Engineer and head of the RandomStorm Social Engineering Team.

At this year’s Infosecurity Europe show, Gavin Watson presented excerpts from the book, in the Business Strategy Theatre, to a packed audience.

Andrew Mason explains, “We have shared some of the social engineering pen testing techniques that we have successfully used at client sites to access restricted areas or sensitive information. Using the book’s examples, organisations can gain a much better understanding of the many ways that criminals employ social engineering. We walk you through the practical steps to improving defences in response to pen test results.”

Gavin Watson continues, “Too many times, social engineering pen tests will simply involve an auditor donning a high vis vest, or carrying a coffee cup and trying to blag their way past reception. What our book describes is how to develop a full risk framework that assesses every social engineering avenue that could be exploited by a criminal targeting your organisation.”

“We want to get away from just putting a tick in the compliance box and help organisations to genuinely improve their security through comprehensive tests that underpin policies, processes and training.”

References:

The Data Protection Act 1998, Section 55, “unlawful obtaining etc., of personal data.” http://www.legislation.gov.uk/ukpga/1998/29/section/55

Georgina Turner image

Georgina Turner

Sales Manager

Read the Latest Issue

Follow us on X

Follow us on X

Click Here

Follow us on LinkedIn

Follow us on LinkedIn

Click Here

Advertise here

Reach decision makers and amplify your marketing

Advertise here

Click Here

Related News

Graphic displaying a lockdown solution

Netgenium debuts next gen display and touchscreen technologies

Power-over-Ethernet (PoE) solutions specialist Netgenium will be showcasing its new range of IP…

ICT® Launches New TSL Access Reader Series

Integrated Control Technology (ICT®), a leading manufacturer of intelligent access control and…
Image Provided by Paxton

Paxton Partners with Skills for Security

The security technology manufacturer Paxton is proud to announce a partnership with Skills for Security…
Image Provided by ICT

ICT and Ingram Micro sign distribution agreement MEA

Integrated Control Technology (ICT), award-winning global manufacturer of intelligent electronic access control and security solutions..
Image Provided by Toshiba

Toshiba launches new HDD Innovation Lab

Toshiba Electronics Europe GmbH (Toshiba) has inaugurated a new HDD Innovation Laboratory (HDD Innovation Lab) at its site in Düsseldorf..
Image Provided by Verkada

Verkada Doubles Down on the Channel with Strategic New Hire

Verkada, a leader in cloud-based physical security, today announced the appointment of Micah Deriso as Head of Global Channel…
Image Provided by IPSA

IPSA Appoint Frontline Hero as Ambassador

Abdullah, the courageous security officer praised for foiling a horrific knife attack at Leicester Square, has been appointed as…
Image Provided by Codelocks

New Surface Latch from Codelocks

Codelocks is expanding its Gate Solutions by Codelocks range with the introduction of the new Codelocks’ Surface Latch…
Image provided by Genetec

Nicholas Smith to Lead Genetec UK and Ireland Operations

Genetec, provider of enterprise physical security software, announced the appointment of Nicholas Smith as its new Regional Sales Director…
Scroll to Top