White Box Or Black Box For Social Engineering Testing?

White Box Or Black Box For Social Engineering Testing?

When conducting social engineering testing as part of an audit or security assessment, should the client provide a listing of employees to test? Doing so is generally termed white box testing, as detailed information is provided to the auditor. The term “white box testing” was ori

Sep 03, 2013
Social Engineering Attacks Are A Significant Business Risk

Social Engineering Attacks Are A Significant Business Risk

Social engineering attacks, or attacks on the human component of security, are a significant threat to businesses. With the proliferation of online tools and resources or attackers, the threat continues to grow. Although a business can sp

Aug 27, 2013
Survey of IT Professionals Social Engineering Risks

Survey of IT Professionals Social Engineering Risks

In 2011, Dimensional Research and Check Point conducted a survey of IT Professionals on The Risk Of Social Engineering On Information Security. The report provides some key insights into security professionals concerns related to social engineering risks and what they are doing about such threats.

Jul 23, 2013
Symantec Internet Security Threat Report: Social Engineering Facts

Symantec Internet Security Threat Report: Social Engineering Facts

The Symantec Internet Security Threat Report includes vast information on security related issues, including social engineering facts. Spam, phishing, and malware data is captured through a variety of sources. These res

Jun 04, 2013
Symantec Security Report Turns Conventional Wisdom Upside Down

Symantec Security Report Turns Conventional Wisdom Upside Down

Symantec security report turns conventional wisdom upside down. Small businesses thought they were immune from social engineering attacks. Not so.

Apr 23, 2013
Social Engineering Attack Prevention and Mitigation

Social Engineering Attack Prevention and Mitigation

When Microsoft security experts offer advice, organizations should listen, particularly with regards to social engineering attacks. Microsoft has provided insight into social engineering attack prevention and mitigation.

Mar 26, 2013
On-site or Offsite Social Engineering Testing

On-site or Offsite Social Engineering Testing

Although there is value in onsite social engineering, for the money offsite social engineering, such as that provided by PhishingBox is much more cost effective. Only in rare circumstances, will attackers attempt anything that require their physical presence. As such, most organizations do not need onsite testing.

Feb 21, 2012
Password Weaknesses Are Exploited By Social Engineering

Password Weaknesses Are Exploited By Social Engineering

Password weaknesses can be exploited. Today, users are susceptible to social engineering because they access more web-based systems. With the increased adoption of cloud computing, users are logging int

Feb 20, 2012