No matter how secure an organisation’s network and web systems are, it is equally important that its employees have a certain level of information security awareness. In recent years there have been individuals known as social engineers who exploit human weaknesses and carry out information theft using deception and persuasion. The social engineering assessment emerged from taking the profile and methods of such attackers into account.
In industry terms, in a social engineering attack the attacker carries out a phishing attack in order to use an employee of the organisation for their own purposes. The aim of the attack is to gain unauthorised access, or to join the organisation’s local network from outside and steal information.
If the personnel within an organisation have not received sufficient information security training and their awareness level is not high, encountering social engineering attacks becomes likely. A social engineering assessment should therefore be carried out to determine employee awareness and resilience to phishing attacks.
The assessment is applied as a simulation, within defined scenarios. The stages and methods used may vary. For a staged assessment, the social engineering assessment may involve gathering information, identifying weaknesses, penetrating the system and producing a report. While these stages are applied, phishing may be carried out using a scenario such as a fake human resources page or a fake parcel tracking number.