Exploring employee perceptions regarding organizational social-engineering attack defense and human-based, nontechinical controls

Tome Steiner, Darrin L. Todd · 2011

Social-engineering attacks are a growing concern for leaders of modern organizations. The attacks bypass organizational technical countermeasures and deceive people into performing actions or divulging sensitive information. Though the attacks are increasing in frequency and severity, a deficiency of empirical research regarding the phenomenon continues to exist. Organizations lack a proven paradigm to determine how organizational nontechnical controls affect employee susceptibility to social-engineering attacks. This qualitative research study used a phenomenological design to explore the perceptions and experiences of organizational employees regarding social-engineering attacks and the nontechnical defensive measures employed to defeat them. Fifteen employees representing a variety of organizations were chosen using non-probability sampling. The interviewed employees include eight managers, two network engineers, two network support technicians, one federal government contractor, one housing coordinator, and one educator. The fifteen interview participants represented a variety of organizations: 6 were federal government employees; 6 were private sector employees; one was a hospital employee; one was a county government employee; and one was a military professional. Key findings indicated that the threat of social-engineering attacks caused a loss of trust because of the risk. The findings revealed that participants believed they were less susceptible to social-engineering attacks in comparison to their peers. The findings also indicated that perceptions concerning organizational reliance upon their employees were related to organizational use of nontechnical defensive measures. This research adds to the body of knowledge regarding social-engineering attacks, and provides insight into employee perceptions regarding contemporary organizational defensive strategies that increase or decrease attack susceptibility. The findings may assist contemporary organizations to understand employee perceptions and motivations, develop methods to decrease employee susceptibility to social-engineering attacks, and increase the effectiveness of organizational nontechnical measures against the attacks. Future research should focus on the elements of trust intrinsic to organizations, and how those elements contribute to social-engineering attack success. A review should be conducted regarding the effects of self-efficacy upon the effectiveness of organizational nontechnical controls. An observational study should be conducted to review the relationship between organizational use of nontechnical controls, and employee-organization trust and reliance. A holistic examination should be conducted to ascertain factors influencing the phenomenon.

Read the paper · More papers on PaperTik