Chapter 16

Internal Social Engineering Assessments

Andrew Mason,    Technical Director, RandomStorm Limited

This chapter looks at the role of an internal social engineering assessment as a defensive strategy. An internal social engineering assessment is one which is run against your own staff as a way to highlight security weaknesses and to improve security awareness internally within a business. This chapter looks at why you would run such a test and also recommends some frameworks for carrying out such an assessment.

Keywords

Internal testing; Hacktober; vulnerability scanning; password auditing

Information in this chapter

• The need for internal testing

• Facebook Hacktober

• Designing the internal test

• Testing the infrastructure

• Vulnerability ...

Get Social Engineering Penetration Testing now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.