Physical security add-on for the
Vulnerability Assessment and Penetration Test service

We comprehensively test
your company's physical security

We aim to deliver a complete professional security service. That is why we cannot overlook attacks that exploit social engineering techniques and physical tampering with systems. 

With these add-ons to our Vulnerability Assessment and Penetration Test services, we put your company’s security through a full 360° test, assessing its resilience to physical security attacks.

Some of the physical security services we offer

Sicurezza fisica Social Engineer

Social Engineer

The art of deceiving people through empathy or outright scams could be your company's fatal weakness

sicurezza fisica Rogue AP

Rogue AP

Malicious access points that are mistaken for legitimate ones. Sometimes being connected to a particular Wi-Fi network is not enough to be sure you are safe

sicurezza fisica attacchi in loco

Network data capture

Are your network communications truly secure? Is your corporate VPN working properly? Do your employees always use it?

sicurezza fisica dumpster diving

Dumpster Diving

We rarely pay attention to what gets thrown in the trash, yet it is worth watching closely what is discarded and how

sicurezza fisica attacchi in loco

On-site attacks

Not everything goes through the network. Some attacks may exploit physical weaknesses in the building or the careless way employees handle their login credentials.

Social Engineering

It is far easier and cheaper to hack a person than a machine.

Social engineering is the art of manipulating people into disclosing confidential information. This information can vary and may include passwords, banking details or remote access credentials for a computer. 

Here are some of the most common attack methods to watch out for.

Social Engineering in person
Unusual encounters

Through seemingly chance encounters, requests for help that play on empathy, or verbal deception, social hackers can get people to reveal important information about the company. Not necessarily sensitive information such as passwords, but also details about the company's structure that can then be used to carry the attack forward.

Social Engineering phone
Phone requests

Large companies with dozens or hundreds of employees, often spread across multiple sites, should pay close attention to the information shared over the phone. There are well-known cases of hackers who, posing as new hires from other offices, managed to obtain login passwords or security codes.

Social Engineering via web
Online support

These techniques fall under phishing, for which we offer a dedicated service. These are emails, web pages or websites that look like legitimate portals but are actually created by hackers, who use these copies to trick users into downloading malware or entering their credentials.

How to prevent it

Fortunately, protecting against this type of attack is neither complicated nor expensive: the key is training employees and company users in general.

We can help by putting your company to the test and uncovering its weak points. This makes it much easier to implement a proactive prevention strategy. Contact us for more information!

Rogue Access Point Installation

One of the most common threats to wireless security is the rogue access point, which is used in many attacks. 

Rogue AP concept

By definition, a rogue AP is a wireless access point that is not part of the network but may have the same name as the corporate network. One of the most common uses of a rogue AP is to impersonate the corporate network with an identical SSID (or a seemingly legitimate one). Computers then connect to it believing they are on the company’s secure network and behave accordingly, lowering their guard.

The risk is that these access points can be used to steal sensitive information such as passwords and user data. The stolen data can then be used to access the real corporate network and carry out targeted attacks.

Our team can detect and analyze rogue APs and then take action to mitigate the risk.

Capturing sensitive data on the network

With the ever-growing use of public and home networks, the risk of unknowingly exposing your data has increased significantly. Without a corporate VPN or at least some form of encrypted communication, the theft of data exchanged between devices is a real risk.

sicurezza fisica man in the middle
Man in the Middle

Man in the Middle refers to a type of attack in which the hacker relays or alters the messages between two users or machines, extracting sensitive data from the responses.

Sicurezza fisica Wireless sniffing
Wireless Sniffing

Similarly to Man in the middle attacks, sniffing a Wi-Fi network means intercepting the packets exchanged between connected computers and the access point, then attempting to decrypt them to obtain sensitive data.

In both cases, we at Cyberfero offer a testing service to assess your response to these types of attacks. However, we do not stop at attempting these attacks. Among our on-site attack testing services, we also offer testing of devices connected only to internal networks, such as Wi-Fi CCTV cameras and other IoT devices.

On-site attacks
Network tampering, Tailgating, Shoulder surfing

A company is protected not only by its Wi-Fi networks, but also by its physical infrastructure. These types of attacks exploit weaknesses in security staff, in the protection of network cabinets, and in the way employees use IT devices.

Network tampering

Companies are connected to the telephone and internet networks like any other building. If attackers gain access to the network cabinets, and therefore to the physical cable connections, they can install devices that intercept the data passing through a specific cable. Access to the cable can be gained by force or through tailgating.

Tailgating

This technique, widely used on the London and New York metro systems, consists of entering a building by following closely behind an employee, taking advantage of the brief moment while the door is closing to avoid using doorbells or badges. Once inside, the attack opportunities multiply.

Shoulder Surfing

This technique involves watching a user type a password or access code in order to reuse it later. For example, if the company's doors are protected by a code, an attacker could simply wait for an employee to enter it and see which digits make up the code.

A single technique is usually not enough to complete an attack, but it is not difficult to combine several to achieve surprising results.

To protect your company comprehensively, you also need to consider these types of attacks, which can be extremely insidious and hard to detect, as they leverage employees’ empathy and the company’s physical weaknesses. Cyberfero’s physical penetration tests identify weak points so that corrective action can be taken.

Dumpster diving

Dumpster diving, also known as trashing o information diving, is the practice of sifting through waste in search of sensitive documents or data that can then be used to carry out cyber attacks.

 

When it comes to physical security, this factor is often overlooked, yet every official document contains confidential information such as home addresses, bank account numbers, tax codes and more. 

With this kind of information, it is not difficult to steal the identity of the unfortunate person it was taken from. What if it happened to your company? What could happen if banking details, security codes or other valuable confidential information fell into the wrong hands? 

You would rather not find out.

Sicurezza fisica dumpster diving

This scenario is also covered by our add-on services for Vulnerability Assessment and Penetration Testing.

Contact us for more information

We are here to answer your questions and work with you to assess your situation, so we can offer you the services that best fit your needs.

Customers