29
Social Engineering the CEO Recovery from Cyber Attack October 2016 www.linkedin.com/company/cyber-rescue-alliance

Social Engineering the CEO

Embed Size (px)

Citation preview

Page 1: Social Engineering the CEO

Social Engineeringthe CEO

Recoveryfrom Cyber Attack

October 2016www.linkedin.com/company/cyber-rescue-alliance

Page 2: Social Engineering the CEO

First presented in Oct 2016. For other presentations at this eventwww.linkedin.com/company/cyber-rescue-alliance

Page 3: Social Engineering the CEO

How CEOs open doors to cyber attackHolly Williams13 Oct 2016

Page 4: Social Engineering the CEO

I’m a hacker.

I break in to computersand buildings for a living

Page 5: Social Engineering the CEO
Page 6: Social Engineering the CEO

Attackers can abuseopen source intelligence

effectively gatheringInformation about targets

online

Page 7: Social Engineering the CEO

People make it super easy

Page 8: Social Engineering the CEO

Now I’m not saying that you need to abandon all social media.

I personally use social media more heavily than anyone here (trust me!)

Page 9: Social Engineering the CEO
Page 10: Social Engineering the CEO

LinkedIn can help too

Page 11: Social Engineering the CEO

Some scams are obvious

Page 12: Social Engineering the CEO

Some scams aren’t

Page 13: Social Engineering the CEO

50% of users

will hit the link

33%of users will submit

credentials

Page 14: Social Engineering the CEO
Page 15: Social Engineering the CEO

Please confirm your account details below:

Page 16: Social Engineering the CEO

Password reuse makesThings so much worse!

Page 17: Social Engineering the CEO

Your account has been locked!

Register for the event!

Attending IPExpo?

Can we arrange a meeting?

Page 18: Social Engineering the CEO

But why a meeting?

Page 19: Social Engineering the CEO

Meetings allow for semi-legitimate access to a building…

But why a meeting?

Page 20: Social Engineering the CEO
Page 21: Social Engineering the CEO
Page 22: Social Engineering the CEO

So we can get passwords…

What else can we get?

Information Gathering

Page 23: Social Engineering the CEO

Can we go any further?

Information Gathering

Page 24: Social Engineering the CEO

Full NameDate of BirthSpouse’s NameChildren’s Names

Phone NumberAddress

Information Gathering

Page 25: Social Engineering the CEO

Mobile Device Data Leak

Auto Probe Group

Page 26: Social Engineering the CEO
Page 27: Social Engineering the CEO

Bespoke Commercial Response Plan

Commercial Coach for Cyber Attack Response

Cyber Rescue Alliance

Practice your Response in Executive Simulations

Page 28: Social Engineering the CEO

Example Alliance Partners

Security Scorecard to auto review Suppliers

Cost effective onlineStaff Training

SEC-1 to conduct penetration testing

Page 29: Social Engineering the CEO

Join Cyber RescueCyber Rescue is a Membership organisation that helps CEOs lead recovery from cyber attack. 

Cyber Rescue operates in 9 countries across Europe, helping leaders protect reputation and revenues when hackers break through.  Membership costs £10,000 per year.

Members benefit from Executive Role Plays, bespoke Commercial Response Plans, and expert Coaching during a catastrophic breach. Cyber Rescue's advisors have led response to thousands of cyber attacks and hundreds of breaches.  The Cyber Rescue team have expertise the many functional areas that are impacted by a successful cyber attack, for example Legal, PR, HR, Operations, Finance and Customer Service, as well as IT Forensics and Remediation. 

+44 (0)20 7859 4320www.linkedin.com/company/cyber-rescue-alliance