Taking care of how you store your credentials and who is granted access to your data plays a significant role in protecting both your own, your firm and your clients’ information. 

Rather than attempting to defeat multiple layers of technical security, attackers often use social engineering – tactics designed to trick, pressure, or manipulate individuals into granting access.

These techniques rely on urgency, trust, familiarity, or simple fatigue to bypass security controls that would otherwise be effective.

‘You’ll never need to work again:’ A real-world insider threat.

A recent BBC report highlights just how far these tactics have evolved. In this case, a journalist was contacted and offered a cash payment in exchange for login credentials and security codes that would grant access to the BBC’s internal network. The attackers planned to use that access to extort the organisation for a ransom paid in bitcoin. 

Find out more