WE HAVE MOVED - CHECK OUT OUR NEW HOME!

Please hold the line........the caller knows you are waiting and we are trying to connect you........
Showing posts with label Social Engineering. Show all posts
Showing posts with label Social Engineering. Show all posts

Wednesday, 6 October 2010

Beer Googles!

Some of the Internet Search Engines
I recently read an article (its here) which mentions some of the pitfalls when using the Internet to search for information (including pictures) for potential recruiters. I think this is a very interesting subject and I would recommend reading the article and the subsequent comments at the end which offer both arguments for and against from the HR professionals prospective.

Any information posted on the internet is in the public domain so surely I/you shouldn't put anything on here that you don't want others to potentially see (for whatever reason), however the issue then comes when someone else puts something on the internet without your knowledge and which could potentially lead to reputational damage for you! Obviously the privacy settings within social networking sites could help here, but these are only as good as the users awareness of these and also your friends of a friend of a friends awareness of these also!!

My personal view (as is all of the content on this site) is that a Google search (or Yahoo! for that matter) is a tool which can be utilised with caution within the pre-employment screening process for certain roles. For example security sensitive positions where an internet search may highlight information which would prompt you to ask some more probing questions during the interview stage i.e. you may find that someone worked for company XYZ, wasn’t sacked but mentions on their social networking profile how they were able to procure £2000 fraudulently and further more this role doesn’t appear on their CV within the employment history section.

From a legal or DPA prospective I am not too sure what the view on this is(but I can guess that it’s not particularly pro). Now with my security hat on surely advising a candidate at the initial stages that an internet search may take place will potentially deter the candidates who could pose a problem................in the current climate good candidates are a plenty, we all want to recruit the best, but we also don't want to recruit the candidate within the accounts department who has previous for fraud (but never convicted) or the candidate who has links to a terrorist organisation that joins your business to gain valuable intelligence and pose an insider threat.....or the person that lacks integrity and is clearly not a team player!

Update 7/10/10: Sal Remtulla, Head of Employee Screening at Risk Advisory has recently circulated some snapshots of recent CV liars. You can read her analysis here

Saturday, 2 October 2010

Don't Put Your Life Online!


I have this available in PDF format. If required send me an email.

Friday, 24 September 2010

Chatham House Rule

Chatham House is the location of the Royal Institute for International Affairs based in St James SW1. So what is the Chatham House rule? Firstly many people make the mistake of saying ‘Chatham House Rules’, this is a common misconception because there is actually only one rule which reads as follows:

"When a meeting, or part thereof, is held under the Chatham House Rule, participants are free to use the information received, but neither the identity nor the affiliation of the speaker(s), nor that of any other participant, may be revealed".

The rule is widely used and seems to be mentioned regularly at business meetings, security committees and security conferences in an attempt to aid free discussion. The rule allows attendees to speak as individuals and to encourage free discussion without the concern for their official duties or personnel reputation.

The rule is not a gagging order, as you can chat freely about the meeting afterwards but the amenity of the attendees must stand (e.g.: name and originations), for example a list of attendees should not be circulated beyond those participating in the meeting.

The success of the rule is really only morally binding and is at best relying upon someone’s integrity and professionalism......and here lies the potential problem!

I recently attended a meeting where the Chatham House Rule was invoked. However, I knew that one person in the room had previous for a lack of confidentiality and integrity and as a result it was impossible for me to speak freely and rely upon this ‘morally binding’ rule, which according to some internet sources the rule is half-jokingly summarised as, "You may be quoted, but you cannot be fired," or the lesser, “what happens on tour, stays on tour”

I know that as a individual both working within business and being a member of various professional bodies, I am governed by lots of different legislation, codes of conducts and ethics. There are also a number of rules that I am bound by as a security professional and by my own personal beliefs and morals. All of which if breached would result in a significant amount of damage both professionally, reputationally and legally.

So why oh why, should I put all my faith in a morally binding (nice to have) rule that is actually only enforceable in Chatham House itself..... because in the absences of knowing any one persons integrity or honesty, I have to rely on this rule. Whether I choose to speak freely will now have to depend on my interpretation of who is around me.

Thursday, 16 September 2010

Social Engineering Definitely a Massive Threat!

The thing is with Social Engineering we all experience it on a regular basis in one shape or form and we do not even know its happening to us, luckily the vast majority don't pose a security risk.

When was the last time you spoke to a recruitment company? The consultants use a form of Social Engineering to 'tease out' information about you, the organisation you work for (or previously worked for) and also some information about your colleagues. This information is not only used by them to help you but its also utilised by them to make more contacts, to get a better understanding of what the job market is doing and to ultimately make more money (and why not).

Personnel Security is now a very important part of any organisations security strategy. The potential risks from an 'insider threat' are reducing (with the appropriate processes in place), but attackers no longer need to gain legitimate employment they can gain the trust of the unsuspecting staff (normally at a junior level) to provide the sensitive information they require to penetrate your organisation (physically or electronically).
What I'm trying to say is be cautious who you are talking to, why are they asking so many questions, why are they stroking your ego and of course be careful what information you put into the public domain about you and your organisation (including the Internet).
Check out the link for the 'Help Net Security' website article.