Companies are under constant attack from malicious actors seeking to exfiltrate critical business data. One popular attack vector is social engineering, which a recent report claimed plays a part in all cyber attacks.
Many companies conduct penetration tests to ensure software and networks are secure but should also use pen testing for social engineering attacks to prevent phishing, vishing, pretexting and more.
In Practical Social Engineering: A Primer for the Ethical Hacker, author Joe Gray, senior investigator at SpyCloud, covered how security professionals should conduct pen testing for social engineering and how to do so without going too far, legally or ethically.
Here, Gray explains why pen testing around social engineering interested him enough to embark on a career focused on it, as well as restrictions ethical hackers should follow and how one might begin their career in a social engineering pen tester role.
What interested you in pen testing specifically around social engineering?
Joe Gray: I got into social engineering specifically thanks to security podcasts, like Chris Hadnagy’s. They made me aware of the concerns that involve social engineering. At the time, I was enrolled in a Ph.D. program. I was at a colloquium session to determine my problem statement for dissertation. We had to review academic journals and find our specific discipline. As I went through journals, I found a lot of focus on cryptography, zero-trust architecture and similar topics but not much on ransomware, specifically in regards to Locky. Its exploit kit used automatic phishing to propagate. From there, I started pulling resources together and ended up with my ‘binder of doom’ — a three-inch binder packed with nothing but scholarly work on social engineering, phishing and vishing. That spawned my passion.
Who would benefit most from your pen testing for social engineering book?
Gray: I wrote the book with several audiences in mind. It’s broken into three sections. The first section is foundational material anyone could benefit from. The second part is on how to conduct operations, which is more beneficial to pen testers. The final part of Practical Social Engineering is more for blue teams. CISOs may also be interested in the third section. In comparison to caring about how many people open an email or click an email, you can’t say something’s efficient without reading it. Looking at that through a set of metrics would benefit CISOs and give them something more operational to work with their incident response teams with to build better playbooks.
https://searchsecurity.techtarget.com/feature/How-to-ethically-conduct-pen-testing-for-social-engineering