A New Role for Human Resource Managers: Social Engineering Defense
[Excerpt] The general risk of social engineering attacks to organizations has increased with the rise of digital computing and communications, while for an attacker the risk has decreased. In order to counter the increased risk, organizations should recognize that human resources (HR) professionals have just as much responsibility and capability in preventing this risk as information technology (IT) professionals. Part I of this paper begins by defining social engineering in context and with a brief history pre-digital age attacks. It concludes by showing the intersection of HR and IT through examples of operational attack vectors. In part II, the discussion moves to a series of measures that can be taken to help prevent social engineering attacks.
HR Review; social engineering; human resources; corporate culture; incentive management; penetration testing
Required Publisher Statement: © Cornell HR Review. This article is reproduced here by special permission from the publisher.