Social Engineering Attacks

Training information

Introduction

Social engineering is a technique used to access information by manipulating people. It can occur in everyday life and particularly in the workplace (Telephone, email, social networks, physical presence).


General information

Target Audience: Anyone wishing to identify social engineering attacks. Prerequisites: None.

Target Competencies:

  • Identify social engineering threats.

  • Raise colleagues' awareness of the social engineering threat.

Learning Objectives:

  • Define social engineering practices.

  • Identify potential threats.

  • React and alert your organization.


Program

Part 1: Human Vulnerabilities & Attack Vectors (4 Hours)

  • 1.1 Fundamentals of Manipulation: Understanding psychological risks, exploiting human feelings and behaviors, and an introduction to neuro-linguistic programming (NLP) in attacks.

  • 1.2 Advanced Attack Vectors: Document forgery, identity theft mechanics, physical tailgating, and baiting scenarios.

Part 2: Detection, Phishing & Incident Prevention (3 Hours)

  • 2.1 Phishing & Spoofing Identification: Analyzing email headers, detecting web spoofing, handling malicious phone calls (Vishing), and SMS phishing (Smishing).

  • 2.2 Prevention & Organizational Defense: Establishing reporting procedures, staff awareness campaigns, facility access controls, and analyzing real-world audit case studies.


Logistical information

  • Duration: 1 day (7 hours).

  • Capacity: 12 participants maximum.

  • Registration Deadline: 5 working days before the training.

  • Teaching Methods: Alternation of theoretical and practical inputs, expert trainer in social engineering and related attacks, course materials provided at the end of the training.

  • Assessment: Continuous and final assessment.