Social Engineering Assessment Services

All the preventative controls in the world won’t stop a determined attacker from getting at your data, especially if your employees let them in the front door. Social engineering tests your employees’ reaction to unexpected visits, as well as giving you a complete picture of your facility’s physical security posture.

 Value of social engineering

Many organizations overlook the real value of social engineering: the ability to analyze the implementation of your organization’s policies and procedures from an alternate perspective. This information is valuable because it allows the organization to identify areas that require additional training or other controls. We will work closely with you to identify the highest risk procedures, facilities and business units in your organization, and devise tests to challenge your employees’ reactions to adverse situations.Social engineering tests typically place the consultant in one of two roles:

  • An outsider, such as a vendor or service technician, who is attempting to gain access to the facility
  • An insider, such as a new employee. Below are some sample scenarios
  Insider Employees
Outsider Service technicians
Visitors policies and procedures  

Physical security controls

Workstation security

Document storage and disposal

Separation of duties

 
Application access

Insider testing:

Insider testing typically places the consultant inside the organization as a new employee or vendor performing extended onsite work. In this way, the consultant is able to interact with and observe employees, test access controls, and attempt to escalate access to information systems.

Outsider testing:

Outsider testing is the most common form of social engineering. Using a ruse such as a water deliveryman, air condition repairman or pest inspector, the consultant attempts to gain access to your organization as a visitor. If allowed inside, the consultant will try to obtain documents or other sensitive information that visitors should not be granted access to.

 

For further information on our Social Engineering Assessment service, please contact one of our Sales representatives by calling (727) 537-9273 or by completing our Online Inquiry Form.

Contact Us

Contact ISGRM

We look forward to partnering with clients, new and existing, on their information security needs. Please don't hesitate to contact us if you have questions or wish to speak with us regarding one or more of our services.

Address

ISGRM
P.O. Box 41602
St. Petersburg, FL  USA 33743 USA

Email

sales@isgrm.com

Phone

(727) 537-9273

Ready to meet your security & compliance requirements?

Book A Consultation
Address

ISGRM
P.O. Box 41602
St. Petersburg, FL  USA 33743 USA

Contact ISGRM

Phone: (727) 537-9273

Email: sales@isgrm.com
Submit RFP

We welcome new clients
Save 20% on your assessments