HomeinetWhy a hacker's best friend is your employee

Why a hacker's best friend is your employee

“Castles fall from within,”  says our wise people, and this proverb will always be true. Unfortunately, many companies do not take into account that the employee himself, with the parchments, the degrees, and the credentials, can be, or become, the Trojan horse that the evil “hacker” will use to do the damage.

It is noteworthy that more and more Greek companies are now investing money (as much as they can, of course, due to the economic crisis), to better insure their homes. They are building a "castle" and upon completion of the "construction", they believe they are impregnable!

So that dark hour comes and the entire client list of the above company is posted on secnews.gr (the site's mention is completely random, as you understand), with addresses, names, etc., and the CxOs (where x is whatever you want: CEO, CTO, CMO...) start to smoke and blame IT as always.

Those of us who work in IT (at least in Greece), know that we are characterized as the necessary evil of businesses that eats up money!!

So here comes the IT department accused of the hacker and must apologize because very important company information was "leaked" and made public, causing significant damage to the brand, since a lot of money has already been spent to build the "castle".

The first thing a hacker will do when targeting a company is reconnaissance. That is, they will gather as much information as they can about the target company, whether from social media, articles, acquaintances, or the phone at the call center, etc.

Acting as a “hacker”, and as one of the many things I would do, I would start from the company’s LinkedIn page and not from Facebook. I would start by looking at whether there were any announcements that would give me enough information about its infrastructure and structure. I would look at the members of the page to see names and titles and I would note … I couldn’t say, from this step, what I could do with this information alone, as you understand, but I would certainly be able to have several things as tools.

So how could any CxO imagine that the new employee, or the old one, it doesn't matter, with the parchments, the degrees and the credentials, would share his success with his online "audience" by mentioning that he is the new super-duper salesperson and works remotely from his super-duper trendy hangout? How could he imagine that by chance "I" was there too, as the bad hacker, where completely by accident and you have to believe me, I dropped a USB stick at the feet of the super-duper salesperson? How could he imagine that 99% of those who find a discarded USB will run to put it on their computer, just like our super-duper salesperson did? Who would have thought that this USB had some happy family photos and a completely random hidden RAT that I had forgotten there (and the hacker is human and “forgets”), which took the entire customer list and sent it to me?

USB-Drive-hacker

How will they understand that it wasn't ultimately the fault of the "castle" and the money it took to build it, of the otherwise expensive or costly IT, but of the lack of procedures and training on what a hacker does?

How many companies have incorporated into the employee induction plan a security booklet that provides instructions on the proper use of information systems, company data, rules and consequences? (Most don't even have an induction plan, but that's another topic). How many companies conduct security training seminars for their employees? How many companies implement practices to simulate such attacks?

How many companies can finally understand that in a digital society you must invest not only in physical means (Firewall, IDS, IPS, etc.) but above all you must invest in the people who will handle them?

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS