Skip to main content

Social engineering within agreed limits

Mail, telephone and the way in through the door, with limits fixed beforehand. The report describes what happened and names nobody.

Test des menschlichen Faktors Drei Wege auf eine Person zu: eine Mail, ein Anruf und jemand am Empfang. Der Rahmen dafuer wird vorher vereinbart. MAIL CALL AT RECEPTION AGREED BOUNDARIES SOCIAL ENGINEERING · MAIL, PHONE, ON SITE
Trusted by
What this is

The route through people goes past the technology

Technical measures hold against technical attacks. A call from the supposed IT department, a mail with a plausible invoice, or someone in overalls at reception goes around them.

We test those routes within limits agreed beforehand: which pretexts are allowed, which areas stay out of scope, and when we stop. The result describes what happened, not who did it.

Every pretext starts with open research, OSINT: names, roles, responsibilities, current projects, the pattern of the email addresses. The more precise that is, the more credible the call, and the more honest the exercise.

Three routes

Mail, telephone and the way through the door

Test des menschlichen Faktors Drei Wege auf eine Person zu: eine Mail, ein Anruf und jemand am Empfang. Der Rahmen dafuer wird vorher vereinbart. MAIL CALL AT RECEPTION AGREED BOUNDARIES SOCIAL ENGINEERING · MAIL, PHONE, ON SITE

The mail tests whether a request gets acted on without anyone checking back. The call tests whether someone has to identify themselves on the phone before having a password reset. The visit tests whether an unknown person with a work order and a high-vis vest gets as far as the server room.

Every route ends at an agreed limit. We take no data with us, we report where we would have got to, and we name nobody. Who clicked a mail is of no importance to the report; that no check-back was provided for anywhere is the finding.

How it runs

How an exercise runs

The limits decide the value of the exercise, not the day itself. They are fixed in writing before the first call goes out.

1

Fix the limits

Which routes are allowed, which areas stay out of scope, which pretexts are ruled out, and when we stop. The works council sits at this table, and the undertaking not to evaluate on individuals is written into the engagement.

2

Open research

Names, roles, responsibilities, current projects, the pattern of the email addresses. That is the same work an attacker does, and it determines which pretext is credible at all.

3

The attempt

Mail, telephone and the way in on foot, in the agreed order. Every step is logged, every one ends at the agreed limit, and we take no data with us.

4

Write-up

What gets described is procedures and safeguards, not people. The finding is not who clicked but that at some point no check-back was provided for.

Common questions

Common questions about social engineering

The simulation is the repeatable mass send with a rate and a learning effect. Social engineering is targeted, uses the telephone and the way in on foot as well, and works with pretexts cut for your organisation. To begin with, the simulation is the better step.

It belongs at the table before anything starts. We do not evaluate on individuals and deliver no lists of names. That undertaking is written into the engagement, and the works council can check it.

Then the test worked. Recognising practised attackers is luck or suspicion. A procedure that requires a check-back does not depend on the day someone is having.

Credentials

Certifications and memberships.

Certifications held in the team
Memberships
eco – Verband der Internetwirtschaft
networker NRW
Next step

Talk to us.

A first conversation usually takes 30 minutes. We look at where you stand and tell you frankly whether we are the right partner.

Telephone
0231 39814905
Mon–Fri · 9am–5pm CET
Email
info@yekta-it.de
PGP key available
Location
Dortmund
Ruhrallee 9 · 44139