Raxis Presents at the (ISC)² Atlanta Chapter Meeting

the exploit blog logo
The Exploit: Penetration Testing Insights From The Frontlines
Posted on July 29, 2019
Raxis presenting at (ISC)² Atlanta Chapter Meeting

Written by Brad Herring

Brad Herring and Scott Sailors had the pleasure to present at the (ISC)² Atlanta Chapter Meeting last Thursday. The topic was on Social Engineering and understanding how the high success rates of social engineering impacts network security. Herring and Sailors shared the most common attack vectors, which include phishing, spear phishing, vishing, physical with a pre-text bias and physical with a technology bias.

The members were shocked at the 90% success rate Raxis sees with social engineering across all verticals and business size. Further sobering is the fact that, once Raxis gains access to an internal network, our team is successful in achieving an “impactful breach” 85% of the time.

Once the realization hit that determined and skilled hackers are commonly able to breach armed security, card keyed systems, numeric keypads and other physical controls, it became apparent the importance of achieving and maintaining a strong internal network security program.

This engaging meeting facilitated many conversations about physical security as well as the effectiveness of a mature phishing campaign. The group was able to heighten their awareness of the types of attacks to which businesses often fall prey, understand the behind the scenes actions that take place once credentials or access is achieved, and discuss meaningful remediation steps for combating these attacks.

Brad Herring

Brad Herring

Brad joined Raxis in 2016. He enjoys helping customers find solutions that work for them to achieve their specific testing objectives. When he’s not helping customers fortify defenses, Brad enjoys spending time with his wife and kids, fishing and shooting. (Yes, that’s fishing – not phishing!)

Search The Exploit Blog

Stay up to date with the latest in penetration testing

Name(Required)
Newsletter(Required)
Do you wish to join our newsletter? We send out emails once a month that cover the latest in cybersecurity news. We do not sell your information to other parties.