Information Age: News, analysis & insight for IT & business leaders

 
Information Age Blog

Meet the man who’s hiding in your office, reading your files

7 May 2009  

Pete Swabey

Businesses spend billions of pounds on sophisticated intrusion detection and prevention technologies every year to protect their information. And yet according to Colin Greenlees, all it takes to gain access to the invaluable data located around their headquarters, or stored in their data centre, is two cups of coffee. Or maybe a cigarette.

And Greenlees should know; he’s done it. Part of his job as a security consultant for Siemens Enterprise Communications involves auditing clients' existing security precautions, or to put it another way, seeing what he can get away with.

In the case of one client, a high profile financial services firm, Greenlees was able to con his way into the building and set up a makeshift office in a third floor conference room. He worked there for several days acquiring all manner of sensitive information. All this happened without confrontation; indeed Greenlees managed to befriend many of the company’s employees, and even secure access for another colleague.

The so-called ‘social engineering’ techniques that Greenlees uses to gain entry to corporate offices – and that he says are often used by more malicious intruders – can be beguilingly simple. Approach a security door carrying two cups of coffee and many people will hold it open for you; join the smokers at the back of the office holding a piece of paper and wearing no jacket, and they’ll probably let you come in with them.

Once he is through the door, the pickings are easy. “Getting through the door is the hard part,” he explains. In the case of the finance firm, he adds, the most staggering thing was the sheer amount of information he could get his hands on.

Greenlees argues that employees need to be more mindful of strangers walking around the office. This doesn’t mean any unfamiliar face must immediately be accosted. “If there is somebody you don’t recognise, ask ‘Can I help you?’,” he says. “There are plenty of ways to identify an intruder without confrontation.”

Other tips include installing turnstyles at the entrance to a building, as they are harder to sneak through without a pass.

It is hard to gauge how much of a threat light-fingered ‘social engineers’ really represent. As Greenlees himself acknowledges, “it’s very hard to report against; the best social engineers get away undetected.”

But while social engineering has always been a problem, Greenlees argues, the current recession will only increase the number of people who are willing to take a punt at walking into an office and walking out with potentially lucrative information.


Comments  [1]

David
Wednesday 13th May 2009

As has been often said, employees remain and always will be the weakest link for network administrators. Without proper training and education, they are often too eager to help a ‘colleague’ in need thinking they are doing the right thing. As a result, social engineers have exploited this opportunity and refined tactics to identify the easy targets and manipulate situations to gain the access they require.

But the solution isn’t as easy and singular as ramping up security on the office entrance. For starters, social engineering can easily occur via email and so emails filters are essential, which will stop phishing attempts. But from an education standpoint, employees must be provided with clear instructions that passwords and usernames cannot be divulged to third parties and that the IT manager must be consulted in any such situation – even if the person concerned claims to be from IT support or even the board of directors!

Lastly, there is an onus on the network administrators to implement the principle of least privilege, thereby restricting access so that only the functions and permissions necessary to perform the job role are given to each employee. This will mean that even if unauthorised access is gained, the intruder will not have limitless ability to roam the network and the effects of penetration are curtailed.

David Vella
Director of Product Management
GFI Software
www.gfi.com

Report this comment »

People who read this also read...

Platform Computing - Category winner

Since 1992, Platform has established a reputation as an industry leader in High Performance Computing (HPC) management software, bringing the most powerful commercial HPC solutions to leading global enterprises.

Outback blackout

A nationwide Internet outage has revealed the precarious nature of Australia's communications infrastructure

The glamour life of spammers

Research reveals that commission-based spam networks work like affiliate programs, with spammers earning up to $4000 a day plus holidays, gifts and free tech support for the most successful

Carbon obsession may hamstring efficiency drives

A recent debate on public sector IT efficiency quickly turned to talk of carbon. But simply focussing on emissions may limit the ability of technology to support efficient services

IT can track your calories, says Dell to women

Dell has launched new site called 'Della' that tackles the IT gender disparity head on

 

White Papers

Read article

Developing ios Solutions for Business

Whitepapers

Quickly develop and deploy custom iPad and iPhone solutions. With FileMaker Pro, iPad and iPhone solutions can be prototyped and completed in hours or days versus weeks or months. No iOS application programming or design experience is required.

Read article

IDC Spotlight: Access Control and Certification

Whitepapers

Read this brief for best practices on managing user access compliance.

Read article

GPS World

Whitepapers

Is the PREMIER global media brand serving the exploding world of positioning and navigation for OEM, commercial and consumer applications.

More

Latest Posts

Watching the watchdog

There are occassions when one might hope for a little more bite from the Information Commissioner's Office

Identity Assurance warrants more public debate

The way in which the government indentifies who we are is one of the fundamental mechanisms of our society. The government's plan to involve private organisations in that process deserves more discussion than it has received so far

The IT projects no-one wants to pay for

Multi-year integration projects may be critical for the long-term interests of the business, but do CIOs have a framework with which to articulate their value? 

Is information a human right?

Some notable luminaries have called for connection to the Internet to be protected as a human right, but what about the information the Internet allows people to access? 

Your brain on Twitter

New science reveals that older brains may find social networking services distracting, but also that there are similarities between Twitter and the brain itself

Advertisement
Video Feedback - Social & Mobile Business Conference Surveys
div class="banner">