If you are only testing your security through traditional means of compromising computer systems, you are potentially overlooking the area of greatest risk to your organisation – attacks against your people.
A determined attacker, who is targeting you, will look for the easiest point of access to your systems and data. In many cases, this will not be a weakness in your technology infrastructure, but rather by taking advantage of the trusting nature of your people, aka, the ‘human element’.
This threat of exploiting the ‘human element’ – social engineering - is very real and is typically an attack vector with the greatest chance of achieving an outcome against you, (when compared to more traditional ‘hacking’ methods by targeting software vulnerabilities).
Whilst we understand that there is always going to be the risk of the ‘human element’, there are various ways to reduce these risks. Since 2003, Securus Global has helped our clients do just that through our social engineering services.
These social engineering exercises are fantastic ways to justify a security budget and to help understand exactly how susceptible your company is and to recognise the potential consequences, to such attacks.
Our Services:
SG Red Cell: This is our traditional form of testing, where we will work with you to develop a testing approach and then replicate the role of the attacker targeting your company in various social engineering scenarios. [See below for details].
Social Engineering Web Service: This is our new and unique set of services that allows you to control and customise the testing, at your own pace for your organisation. Here, you can monitor the progress for all your activities on your own SG Social Engineering Web Service secure dashboard.
Below are details of what this currently includes, however our team are completely flexible in terms of options depending on your business requirements. We are willing to work with you to address specific social engineering concerns or to develop and conduct further tests as appropriate.
Social Engineering Services – Manage yourself or engage the Securus Global team;
|
Web Service |
SG RedCell |
|
|
SG Red Cell Assessments. This service includes, but is not limited to; face-to-face social engineering, email and phone social engineering, secure area bypass, alarm system avoidance, physically tailing, badge access testing and security system exploitation. In addition, your SG Red Cell assessment strategy may also include some, or all of the offerings available in the Social Engineering Web Service. |
|
|
|
Email Phishing Service (New and Updated Service) |
|
|
|
Trojan USB Keys (New Service) People are naturally curious and will want to see what resides on a USB stick. Test to see if your security training and awareness programs are working and if your employees are appropriately cautious about what they bring into your network. |
|
|
|
Trojan Keyboard An advanced level of service and attack but is your data and systems valuable enough for someone to want to launch such advanced attacks? For many of our clients, this is most definitely the case. |
|
|
|
Disguised Data Exfiltration Device How easy would it be for someone to exfiltrate data from your network? This is another advanced level of attack service which again, allows you to demonstrate how easily your data and systems can be compromised. |
|
|
|
Malicious QR Codes As the attack vectors into your organisation expand, Securus Global can help you to expand how you test the security awareness of your staff. |
|
|
|
Malicious Website Generator The applications and types of tests you can perform are limited only by your imagination and the results you are interested in finding out about. This type of test is simple to set up and typically proves effective with high success rate.
|
|
|
|
Malicious Wireless Access Points |
|
|
|
SMS Spoofing Service |
|
|


