How to Protect Data From Social Engineering

662 views
•
March 11, 2016
by
RSAC Cybersecurity
YouTube video player
How to Protect Data From Social Engineering

TL;DR

Protect sensitive data by treating cybersecurity as everyone’s responsibility, questioning unfamiliar people, reviewing the combined meaning of online posts, and practicing security procedures repeatedly. Attackers can assemble social media, dating profiles, photographs, location details, usernames, and exposed metadata into a revealing pattern of life, then use that information for impersonation or highly targeted phishing.

Transcript

Thank you. Well, thank you so much for having me. It's such an honor to be here. My name is Tyler Cohen Wood, and I am cybersecurity expert at Inspired eLearning and also the media spokesperson. But how many of you guys have read a Jason Bourne novel? Most of you. How many of you guys have read Tom Clancy? Well, you know those cool gadgets that the... Read More

Key Insights

  • Cybersecurity is everyone’s responsibility because employees use personal phones, tablets, laptops, and other connected devices for work. IT personnel cannot independently control every device, online disclosure, physical encounter, or personal action that might provide an attacker with access to a corporate network.
  • Attackers target employees personally and professionally because a person can become the route into an organization. Social media, dating sites, applications, family information, and location posts can help an attacker develop a pattern of life and craft an approach that appears relevant or trustworthy.
  • Seemingly harmless information can become sensitive when separate details are combined. A coffee check-in, conference attendance, photographs, routines, workplace biographies, and family information may collectively reveal locations, relationships, schedules, interests, or corporate activity that no individual post appears to disclose.
  • Operative-style preparation requires understanding potential problems and maintaining backup plans. Applied to cybersecurity, this means repeatedly reviewing likely threats, learning the environment, practicing appropriate responses, and ensuring that everyone from interns and contractors to executives receives mandatory and engaging education.
  • Healthy suspicion is a practical security behavior when it prompts people to examine posts, metadata, credentials, and unusual requests. The goal is careful scrutiny rather than constant fear, particularly when online content or an unfamiliar person could expose personal details, corporate information, or physical access.
  • Physical access controls fail when politeness replaces verification. In the example, an unfamiliar man claimed to be a newly hired engineer, received tours of the server room from multiple employees, and was eventually given both access and an employee’s password despite not being recognized by human resources.
  • Reverse image searching can connect identities across unrelated websites. A photograph from a company biography led to a dating profile under another name, which then revealed a reusable username, hometown clues, weekly routines, a house photograph, personal interests, friends, and additional public accounts.
  • Peer review reduces the risk of overlooking personal disclosures. Even trained people can forget secure practices or misunderstand how their posts combine, so a trusted colleague or friend can review social media activity and identify information, privacy settings, or patterns that the account owner missed.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: Why is cybersecurity no longer only an IT problem?

Cybersecurity is no longer only an IT problem because organizational networks and work activities involve many connected devices, including smart televisions, remote HVAC systems, personal smartphones, personal tablets, and laptops. Employees work while moving between locations and may mix personal and professional technology. Attackers also target employees and their families directly, using information about people as a path into corporate systems.

Q: How can social media expose sensitive information?

Social media can expose sensitive information through the combined effect of posts that seem harmless individually. Location services, coffee check-ins, conference attendance, photographs, family details, schools, friends, work locations, interests, and recurring activities can form a pattern of life. An attacker can assemble those details to understand routines, identify relationships, locate a person, or design a convincing targeted message.

Q: What does it mean to think like an operative about cybersecurity?

Thinking like an operative means preparing for possible problems, learning the relevant environment, considering what could go wrong, and maintaining backup plans. It also means applying careful scrutiny to online disclosures, unfamiliar people, credentials, and unusual requests. Because no person is perfect, the approach includes repeated training and support from colleagues or friends who can notice risks that an individual overlooks.

Q: How should organizations train employees to protect sensitive data?

Organizations should provide mandatory, repetitive, and engaging cybersecurity education to everyone who can affect the network. That includes interns, contractors, employees, and executives. Training should not become a routine exercise in rapidly clicking through slides and completing a test. Participants should actively examine threats, understand their operating environment, rehearse appropriate behavior, and connect corporate protection with the safety of themselves and their families.

Q: Why should employees challenge people without proper credentials?

Employees should challenge unfamiliar people without badges or proper credentials because friendliness, confidence, professional clothing, and technical language do not establish authorization. In the example, a man claimed he was a newly hired engineer, although human resources did not know him. Employees showed him the server room, and one person provided access and a password. Verification could have interrupted that physical security breach.

Q: How can reverse image search reveal a hidden identity?

Reverse image search can connect the same photograph to accounts created under different names. The speaker used a company biography photograph to find an operative’s dating profile. That profile supplied a username and additional clues, which led to blogs, friends, social media, hometown information, routines, interests, and other personal details. A separate identity therefore offered little protection once the photograph connected the accounts.

Q: Why is photograph metadata a privacy risk?

Photograph metadata can reveal information that the person posting an image did not intend to share. The transcript specifically identifies EXIF data as a potential source of exposure and describes a dating site that preserved it. In the operative example, the metadata associated with a house photograph could be used to investigate its location, adding another sensitive detail to the broader profile assembled from public sources.

Q: How can a trusted friend help protect online privacy?

A trusted friend or colleague can review social media activity with a perspective the account owner may lack. The reviewer can examine multiple posts together, identify sensitive patterns, question weak privacy settings, and flag information about work, family, locations, or routines. This buddy approach recognizes that even trained people forget, make mistakes, or fail to notice how separate disclosures become revealing when combined.

Summary & Key Takeaways

  • Connected televisions, HVAC systems, personal phones, tablets, and laptops have expanded organizational exposure beyond traditional computers. Employees also carry work across locations and devices. Because attackers increasingly target people and their families to reach corporate networks, cybersecurity can no longer be treated as a problem that an IT department can solve alone.

  • An operative mindset begins with preparation, repeated education, backup plans, and careful attention to information that may appear harmless in isolation. Organizations should provide mandatory, engaging security education for interns, contractors, employees, and executives. Individuals should also review posts collectively, examine privacy settings, and ask trusted partners to identify unexpected disclosures.

  • A trained operative was identified through a company photograph, reverse image searching, a dating profile, reused usernames, public blogs, social connections, location clues, and photograph metadata. The accumulated information exposed his routines, interests, family, education, workplace, and an accidentally posted password, creating material for impersonation and targeted spear phishing.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚