Information Age: News, analysis & insight for IT & business leaders

 
2 September 2010
Information Age Blog

Meet the man who’s hiding in your office, reading your files

7 May 2009  

Pete Swabey

Businesses spend billions of pounds on sophisticated intrusion detection and prevention technologies every year to protect their information. And yet according to Colin Greenlees, all it takes to gain access to the invaluable data located around their headquarters, or stored in their data centre, is two cups of coffee. Or maybe a cigarette.

And Greenlees should know; he’s done it. Part of his job as a security consultant for Siemens Enterprise Communications involves auditing clients' existing security precautions, or to put it another way, seeing what he can get away with.

In the case of one client, a high profile financial services firm, Greenlees was able to con his way into the building and set up a makeshift office in a third floor conference room. He worked there for several days acquiring all manner of sensitive information. All this happened without confrontation; indeed Greenlees managed to befriend many of the company’s employees, and even secure access for another colleague.

The so-called ‘social engineering’ techniques that Greenlees uses to gain entry to corporate offices – and that he says are often used by more malicious intruders – can be beguilingly simple. Approach a security door carrying two cups of coffee and many people will hold it open for you; join the smokers at the back of the office holding a piece of paper and wearing no jacket, and they’ll probably let you come in with them.

Once he is through the door, the pickings are easy. “Getting through the door is the hard part,” he explains. In the case of the finance firm, he adds, the most staggering thing was the sheer amount of information he could get his hands on.

Greenlees argues that employees need to be more mindful of strangers walking around the office. This doesn’t mean any unfamiliar face must immediately be accosted. “If there is somebody you don’t recognise, ask ‘Can I help you?’,” he says. “There are plenty of ways to identify an intruder without confrontation.”

Other tips include installing turnstyles at the entrance to a building, as they are harder to sneak through without a pass.

It is hard to gauge how much of a threat light-fingered ‘social engineers’ really represent. As Greenlees himself acknowledges, “it’s very hard to report against; the best social engineers get away undetected.”

But while social engineering has always been a problem, Greenlees argues, the current recession will only increase the number of people who are willing to take a punt at walking into an office and walking out with potentially lucrative information.


Comments  [1]

David
Wednesday 13th May 2009

As has been often said, employees remain and always will be the weakest link for network administrators. Without proper training and education, they are often too eager to help a ‘colleague’ in need thinking they are doing the right thing. As a result, social engineers have exploited this opportunity and refined tactics to identify the easy targets and manipulate situations to gain the access they require.

But the solution isn’t as easy and singular as ramping up security on the office entrance. For starters, social engineering can easily occur via email and so emails filters are essential, which will stop phishing attempts. But from an education standpoint, employees must be provided with clear instructions that passwords and usernames cannot be divulged to third parties and that the IT manager must be consulted in any such situation – even if the person concerned claims to be from IT support or even the board of directors!

Lastly, there is an onus on the network administrators to implement the principle of least privilege, thereby restricting access so that only the functions and permissions necessary to perform the job role are given to each employee. This will mean that even if unauthorised access is gained, the intruder will not have limitless ability to roam the network and the effects of penetration are curtailed.

David Vella
Director of Product Management
GFI Software
www.gfi.com

Report this comment »

People who read this also read...

Outback blackout

A nationwide Internet outage has revealed the precarious nature of Australia's communications infrastructure

The glamour life of spammers

Research reveals that commission-based spam networks work like affiliate programs, with spammers earning up to $4000 a day plus holidays, gifts and free tech support for the most successful

Carbon obsession may hamstring efficiency drives

A recent debate on public sector IT efficiency quickly turned to talk of carbon. But simply focussing on emissions may limit the ability of technology to support efficient services

IT can track your calories, says Dell to women

Dell has launched new site called 'Della' that tackles the IT gender disparity head on

 

White Papers

Read article

10 Mistakes when Buying a Business Phone System

Whitepapers

Why learn things the hard way? Here are 10 mistakes to avoid when buying your business phone system.

Read article

10 Questions to Ask Your Hosted IP PBX Provider

Whitepapers

This informative best practices will help you understand the crucial questions and the information you need to understand before you buy.

Read article

10 Steps to an Enterprise Mobility Strategy

Whitepapers

Regain control of your enterprise mobility strategy with these ten steps.

More

Latest Posts

The social science of sentiment

Can sentiment analysis technology really detect the zeitgeist in social networks?

Brits that pursued “bad ideas” tipped for tech’s top accolade

Millenium Technology Prize nominees Steve Furber and Richard Friend reached their respective breakthroughs by pursuing ideas discounted by their peers

Censoring the Internet

China's isn't the only government seeking to control the content of the web

How will semantic technology boost the UK’s economy?

Gordon Brown might believe the semantic web is a ‘simple concept’ but its potential contribution to the UK economy is anything but

Should IT keep its distance from social media?

It looks as though a hands-off approach might be the only way to guarantee the success of internal social media projects

North Korea’s software self reliance

The communist state has developed its own distribution of the Linux operating system

Advertisement
Video Borough council improves the efficiency of IT support Surveys