Innovation
Insights · Innovation

Bugs in the Human Hardware

An overview of social engineering, cybersecurity, and how human error becomes the biggest security risk for organizations.

When One Mistake Changes Everything

Who amongst us has not done something so incredibly dumb that we didn’t wish we could just go back in time and change just that one event? The Exxon Valdez oil spill comes to mind, with 20 million gallons of oil dumped into Alaska’s Prince William Sound. The drunk, sleeping captain, Joe Hazelwood, could have used a time machine. One poor personal choice and he gets to be the primary player in what is considered to be one of the most devastating human-caused environmental disasters of all time.

Cybersecurity, while not as emotionally charged as the Alaskan oil spill, is now littered with the devastating effects of individuals who have unthinkingly cost their companies, the country, and countless unknowing consumers billions of dollars in stolen money and unproductive effort. Company reputations have been lost, and stolen military secrets may have cost American lives. If only we had a time machine.

The Real Cause of Most Cybersecurity Breaches: Human Error

The ultimate blame for security attacks and the damage caused is, of course, at the feet of the malicious hackers and activists, who have initiated and orchestrated these attacks. But, by all accounts, the majority of successful security attacks are a direct result of benign, well-educated company staffers who did something stupid or forgot to do something easy.

What is Social Engineering in Cybersecurity and Why It Works

The term social engineering is used to describe the act (maybe art is a better word) of enticing people to bypass computer security by performing actions or divulging confidential information. Clever cyber criminals somehow convince naïve users to provide an inroad into a company’s protected systems. Just as frustrating (to companies) are individuals who unknowingly (or sometimes sloppily) open or leave holes in a company’s security defenses. In all cases, and by every measure, the largest security danger to a company or organization is the staff that works within the organization.

Why should a hacker bother to spend endless amounts of time and energy hacking into a computer system when he or she can easily convince someone to hand over the keys to the castle?

Common Social Engineering Ploys

Social engineering takes many forms. A few of the more entertaining (dumber) ones are:

The High Cost of Human Error

One inadvertent click or conversation often erases millions of dollars of hardware and software security protections. Computer security is rarely at the top of anyone’s mind. While the downside of a security breach is sometimes devastating to a company, the average person does not perceive a personal risk, and the malicious hackers are usually very smooth.

Humans are, by all accounts, imperfect. Yet we drive potentially deadly cars and trucks every day with very few fatal accidents. We seldom make mistakes when handling money, and infrequently forget to wear socks to work. What makes an otherwise intelligent race click on a link when we know it could be a trap? What makes us ignore obvious security holes when we see them right before our eyes? My father probably would have said it’s from watching too much TV – that probably isn’t the answer, but it’s the best I have right now.

Talk to us

Bring us the hard version of your challenge.

Thirty minutes with a senior engineer, no pitch and no pressure. Whatever you decide, you'll leave with a clearer map of what you're about to do.

Start the conversation Keep reading