Icon.svg

Social Engineering – Practical Red Teaming Lessons from the Field ** Join the Red Team **

SESSION

Social Engineering – Practical Red Teaming Lessons from the Field ** Join the Red Team **

9:00 am

/

10 May 2023

About this session

Deloitte will illustrate during our tutorial case studies from our field testing of Social Engineering Methodology. Examples in which we have video and audio will be presented of various techniques in action. As well as several hands on labs with some of the tools utilised during physical testing.

The tutorial will demonstrate how the team has infiltrated and extracted the most sensitive information from organisations (who have engaged Deloitte) around Australia.

The tutorial will delve into the mechanics of the attacks and how it was successful in exploiting the target.

Techniques which will be illustrated to allow attendees to understand the methods used as well as the why they work at almost all organisations.

These include:

  • In-Person Elicitation Techniques
  • Physical Security Control Bypassing
  • Communication based attacks
  • How to build a Security Awareness Training Program

For the common attack methods we will also present countermeasures which would have prevented all of the techniques from being successful.

Deloitte will provide real work policies and controls that have been implemented to protect against these attacks which have been field proven in organisations.

The tutorial will make use of printed material, presentations, live demonstrations and video footage of Social Engineering exercises being executed.