Arcanum’s Festive Stories – Fagin’s Digital Pickpockets – The Art of Phishing & Social Engineering

Arcanum’s Festive Stories – Fagin’s Digital Pickpockets – The Art of Phishing & Social Engineering

In the third of a series of Festive Stories, Chief Consultant Lawrie Abercrombie takes us through a journey of cyber security discovery through the lens of Charles Dickens.

In Dickens’ Oliver Twist, Fagin trains his gang of pickpockets to exploit trust and distraction.  Today’s cybercriminals operate in much the same way, only their “streets” are inboxes, social platforms and business networks.  Phishing and social engineering remain the most successful tactics for breaching organisations and UK businesses are prime targets.  Phishing is not about technology, it’s about psychology.  Attackers prey on human trust, urgency and fear.

 

Yet many organisations still underestimate the sophistication of these scams.  Earlier this year a phishing email targeting an outsourced IT contractor at Marks & Spencer rapidly escalated into a ransomware breach.  The result? A £300M profit warning, 46 days of online outage and stolen customer data.  This wasn’t a technical failure, it was a human one, just not the IT contractor’s.  Who thought it appropriate that someone with admin level access should have email capability on that account?

 

According to UK government data, 85% of businesses reported phishing attacks in the last 12 months, making it the most disruptive cyber threat.  In one case, attackers impersonated internal IT staff at the Co-op and convinced help desk personnel to reset passwords.  With those credentials, they deployed ransomware, crippling operations.  According to Mike Danseglio, Security Program Manager, Microsoft “there’s no patch for human gullibility.”

 

Just as Fagin exploited the naivety of his young recruits, modern attackers exploit gaps in awareness, competence and governance.  Technology alone cannot stop phishing and social engineering.  The solution lies in culture, leadership accountability and having suitably qualified and experienced people in your cyber security team.

 

There are some key takeaways for Boards.  Firstly, don’t waste your money on phishing simulations.  Everyone in the company has their own job, be that sales, admin, manufacturing, finance etc.  It’s not their job to prevent the AI developed phishing attacks that are becoming ever more undetectable to the eye. That is entirely down to the IT and Cyber team, they need to enforce strict separation of duties, ensuring that no-one with admin rights has email on the same account.  Don’t get me wrong, training is good, but make it the right sort of training.  Use phishing to test your SIEM and incident response or a vishing exercise to train your call centre in social engineering by all means.  But you don’t expect your finance team to go out selling for you, so why expect everyone to be cyber experts?

 

Secondly, make sure your cyber team has enough competent people to prevent most attacks and to get your business back up and running as soon as possible if an attack does succeed.  Resilience and recovery are now the name of the game rather than all out prevention.  Really focus on practicing your incident response procedures, because it’s far too late to go and find the handbook when all your systems are shutting down around you.

 

And lastly, have someone on your Board who owns cyber security governance because, ultimately, when it goes wrong, it’s the Board’s fault and they need to take responsibility.

Read more as part of the Arcanum Festive Stories series:

Arcanum’s Festive Stories – A Dickensian Tale of Cyber Peril in the Age of Legacy

Arcanum’s Festive Stories – Don’t Wait for the Ghost of Breaches Past – Incident Response Readiness