Dienst van SURF
© 2025 SURF
From the article: This paper describes the external IT security analysis of an international corporate organization, containing a technical and a social perspective, resulting in a proposed repeatable approach and lessons learned for applying this approach. Part of the security analysis was the utilization of a social engineering experiment, as this could be used to discover employee related risks. This approach was based on multiple signals that indicated a low IT security awareness level among employees as well as the results of a preliminary technical analysis. To carry out the social engineering experiment, two techniques were used. The first technique was to send phishing emails to both the system administrators and other employees of the company. The second technique comprised the infiltration of the office itself to test the physical security, after which two probes were left behind. The social engineering experiment proved that general IT security awareness among employees was very low. The results allowed the research team to infiltrate the network and have the possibility to disable or hamper crucial processes. Social engineering experiments can play an important role in conducting security analyses, by showing security vulnerabilities and raising awareness within a company. Therefore, further research should focus on the standardization of social engineering experiments to be used in security analyses and further development of the approach itself. This paper provides a detailed description of the used methods and the reasoning behind them as a stepping stone for future research on this subject. van Liempd, D., Sjouw, A., Smakman, M., & Smit, K. (2019). Social Engineering As An Approach For Probing Organizations To Improve It Security: A Case Study At A Large International Firm In The Transport Industry. 119-126. https://doi.org/10.33965/es2019_201904l015
MULTIFILE
NL samenvatting: In dit verkennend onderzoek werden social engineering-aanvallen bestudeerd, vooral de aanvallen die mislukten, om organisaties te helpen weerbaarder te worden. Fysieke, telefonische en digitale aanvallen werden uitgevoerd met behulp van een script volgens de 'social engineering-cyclus'. We gebruikten het COM-B model van gedragsverandering, verfijnd door het Theoretical Domains Framework, om door middel van een enquête te onderzoeken hoe Capability, Motivational en vooral Opportunity factoren helpen om de weerbaarheid van organisaties tegen social engineering-aanvallen te vergroten. Binnen Opportunity leek sociale invloed van extra belang. Werknemers die in kleine ondernemingen werken (<50 werknemers) waren succesvoller in het weerstaan van digitale social engineering-aanvallen dan werknemers die in grotere organisaties werken. Een verklaring hiervoor zou een grotere mate van sociale controle kunnen zijn; deze medewerkers werken dicht bij elkaar, waardoor ze in staat zijn om onregelmatigheden te controleren of elkaar te waarschuwen. Ook het installeren van een gespreksprotocol over hoe om te gaan met buitenstaanders was een maatregel die door alle organisaties werd genomen waar telefonische aanvallen faalden. Daarom is het moeilijker voor een buitenstaander om toegang te krijgen tot de organisatie door middel van social engineering. Dit artikel eindigt met een discussie en enkele aanbevelingen voor organisaties, bijvoorbeeld met betrekking tot het ontwerp van de werkomgeving, om hun weerbaarheid tegen social engineering-aanvallen te vergroten. ENG abstract: In this explorative research social engineering attacks were studied, especially the ones that failed, in order to help organisations to become more resilient. Physical, phone and digital attacks were carried out using a script following the ‘social engineering cycle’. We used the COM-B model of behaviour change, refined by the Theoretical Domains Framework, to examine by means of a survey how Capability, Motivational and foremost Opportunity factors help to increase resilience of organisations against social engineering attacks. Within Opportunity, social influence seemed of extra importance. Employees who work in small sized enterprises (<50 employees) were more successful in withstanding digital social engineering attacks than employees who work in larger organisations. An explanation for this could be a greater amount of social control; these employees work in close proximity to one another, so they are able to check irregularities or warn each other. Also, having a conversation protocol installed on how to interact with outsiders, was a measure taken by all organisations where attacks by telephone failed. Therefore, it is more difficult for an outsider to get access to the organisation by means of social engineering. This paper ends with a discussion and some recommendations for organisations, e.g. the design of the work environment, to help increase their resilience against social engineering attacks. https://openaccess.cms-conferences.org/publications/book/978-1-958651-29-2/article/978-1-958651-29-2_8 DOI: 10.54941/ahfe1002203
In the current discourses on sustainable development, one can discern two main intellectual cultures: an analytic one focusing on measuring problems and prioritizing measures, (Life Cycle Analysis (LCA), Mass Flow Analysis (MFA), etc.) and; a policy/management one, focusing on long term change, change incentives, and stakeholder management (Transitions/niches, Environmental economy, Cleaner production). These cultures do not often interact and interactions are often negative. However, both cultures are required to work towards sustainability solutions: problems should be thoroughly identified and quantified, options for large change should be guideposts for action, and incentives should be created, stakeholders should be enabled to participate and their values and interests should be included in the change process. The paper deals especially with engineering education. Successful technological change processes should be supported by engineers who have acquired strategic competences. An important barrier towards training academics with these competences is the strong disciplinarism of higher education. Raising engineering students in strong disciplinary paradigms is probably responsible for their diminishing public engagement over the course of their studies. Strategic competences are crucial to keep students engaged and train them to implement long term sustainable solutions.
Designing cities that are socially sustainable has been a significant challenge until today. Lately, European Commission’s research agenda of Industy 5.0 has prioritised a sustainable, human-centric and resilient development over merely pursuing efficiency and productivity in societal transitions. The focus has been on searching for sustainable solutions to societal challenges, engaging part of the design industry. In architecture and urban design, whose common goal is to create a condition for human life, much effort was put into elevating the engineering process of physical space, making it more efficient. However, the natural process of social evolution has not been given priority in urban and architectural research on sustainable design. STEPS stems from the common interest of the project partners in accessible, diverse, and progressive public spaces, which is vital to socially sustainable urban development. The primary challenge lies in how to synthesise the standardised sustainable design techniques with unique social values of public space, propelling a transition from technical sustainability to social sustainability. Although a large number of social-oriented studies in urban design have been published in the academic domain, principles and guidelines that can be applied to practice are large missing. How can we generate operative principles guiding public space analysis and design to explore and achieve the social condition of sustainability, developing transferable ways of utilising research knowledge in design? STEPS will develop a design catalogue with operative principles guiding public space analysis and design. This will help designers apply cross-domain knowledge of social sustainability in practice.
Due to the existing pressure for a more rational use of the water, many public managers and industries have to re-think/adapt their processes towards a more circular approach. Such pressure is even more critical in the Rio Doce region, Minas Gerais, due to the large environmental accident occurred in 2015. Cenibra (pulp mill) is an example of such industries due to the fact that it is situated in the river basin and that it has a water demanding process. The current proposal is meant as an academic and engineering study to propose possible solutions to decrease the total water consumption of the mill and, thus, decrease the total stress on the Rio Doce basin. The work will be divided in three working packages, namely: (i) evaluation (modelling) of the mill process and water balance (ii) application and operation of a pilot scale wastewater treatment plant (iii) analysis of the impacts caused by the improvement of the process. The second work package will also be conducted (in parallel) with a lab scale setup in The Netherlands to allow fast adjustments and broaden evaluation of the setup/process performance. The actions will focus on reducing the mill total water consumption in 20%.
Het project Circulaire Parkkade (CPk) is een project aan de Heysekade in de Zuid-Rotterdamse wijk Heijplaat waarbij een circulaire en grotendeels zelfvoorzienende woonbuurt wordt gebouwd. Er worden 19 woningen gebouwd van hergebruikte en biobased materialen en de gemeenschappelijke tuin staat in het teken van de productie van groente en fruit. De toekomstige bewoners wekken en slaan gezamenlijk elektriciteit en warmte op en zuiveren zelf het opgevangen regenwater. De ecologie hangt hier nauw mee samen: diversiteit in planten, de begroeiing en het oppervlaktewater binnen de wijk. Doordat de bewoners hun eigen systemen beheren, wordt ook bijgedragen aan de sociale cohesie van de wijkbewoners. In de verkennende fase van het project wordt een studie uitgevoerd naar een passend businessmodel dat rekening houdt met de circulaire aspecten. Vanwege het karakter van het project, de wijk en de woningen, is een klassieke grondexploitatie niet van toepassing. Het ontbreken van afval, klassiek eigendom en voorzieningen, zijn atypische uitgangspunten voor het opstellen van een grond- en opstal exploitatie. De studie moet antwoord geven op circulaire aspecten van de systemen voor warmteopwekking en –opslag, elektrische distributie icm smart technologie, water, voedsel, groen en (het ontbreken van) afval. Op basis van deze aspecten kan een geïntegreerd circulaire businessmodel worden opgesteld, dat de noodzakelijke input is voor de engineering, ontwikkeling en bouw van de CPk. Tevens beoogt het project het netwerk betrokken bij de CPk te versterken en verbreden. Deze aanvraag is tevens voorbereidend op een subsidieaanvraag in het kader van de aankomende call NWA Route 12 Circulaire economie en grondstoffenefficiëntie.