Humans are the weak link in any corporation’s carefully crafted security perimeter. That’s the prevailing theme of Kevin Mitnick’s new book, The Art of Deception: Controlling the Human Element of Security (Wiley, October 2002), in which he shares stories of “social-engineering” hacks that involve everything from fake phone calls to dumpster-diving to illustrate how a dedicated and wiley hacker can use human fragility and carelessness to crack a network.Although CIOs may quickly tire of tales highlighting the boundless bravado of hackers, the book does offer some good advice on hardening your employees against such exploits. Mitnick recommends that companies encourage employees to adhere to the following security guidelines. Do not give out any personal or internal company information to anyone, unless their voice is unquestionably recognized and he or she has a need to know. Never disclose your password or any information about your password. Do not download, open or respond to e-mails and files from any unknown source. When in doubt (whether verifying a request for information or opening a file), ask for guidance from the security group. Do not judge a book by its cover. Just because a caller knows the corporate structure and lingo, sounds authoritative or looks the part, doesn’t mean she is for real. It’s acceptable and expected to challenge authority when there’s a security risk at stake. Do not transfer files to people you don’t know, even if the destination appears to be within company boundaries. Related content brandpost Sponsored by Palo Alto Networks Operational technology systems require a robust Zero Trust strategy in 2024 Zero Trust provides a foundation for creating a stronger security posture in 2024. By Navneet Singh, vice president of marketing, network security, Palo Alto Networks Dec 05, 2023 6 mins Security brandpost Sponsored by AWS in collaboration with IBM How digital twin technology is changing complex industrial processes forever As the use cases for digital twins proliferate, it is becoming clear that data-driven enterprises with a track record of innovation stand the best chance of success. By Laura McEwan Dec 05, 2023 4 mins Digital Transformation brandpost Sponsored by AWS in collaboration with IBM Why modernising applications needs to be a ‘must’ for businesses seeking growth Around one-third of enterprises are spending heavily on application modernisation and aiming for cloud native status. The implications for corporate culture, structure and priorities will be profound. By Laura McEwan Dec 05, 2023 5 mins Digital Transformation opinion 11 ways to reduce your IT costs now Reorienting IT’s budget toward future opportunities is a big reason why CIOs should review their IT portfolios with an eye toward curbing unnecessary spending and realizing maximum value from every IT investment. By Stephanie Overby Dec 05, 2023 11 mins Budget Cloud Management IT Governance Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe