Workshop: Social Engineering for IT Security Professionals
Social Engineering engagements can appear to be easy, especially to someone who already has experience in the Information Security industry. All InfoSec consultants have experienced situations where they’ve been let into a meeting or to perform an onsite engagement without the correct paperwork or permission, and we’ve all heard the stories of successful Social Engineering assignments. Combined with frequent news stories on the success of spear phishing and „blagging“ it can seem as though the simplest of attacks will inevitably compromise a target. However selling, scoping, executing and reporting on regular Social Engineering engagements requires a thorough understanding of the processes, techniques and risks involved, as well as the concepts and issues around Social Engineering in general. With that understanding you can ensure that you have those stories to tell to your peers, and