mnemonic security podcast

Ethical Social Engineering

mnemonic

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 35:00

Ethical social engineering

Even the best pentesters out there can be fooled by a social engineering attempt under the right circumstances. But how do we treat the ones that have been tested and failed?

Ragnhild «Bridget» Sageng, Senior Security Advisor at Norwegian Customs, has several years of experience from the IT and cybersecurity industry, and hands-on experience working as an ethical hacker specialising in social engineering.

In her conversation with Robby, she shares what goes through her head during social engineering  assignments, and discusses the importance of company culture and management expectations when doing these kinds of assessments.

Ragnhild is particularity interested in the other side social engineering and how we should meet the humans that are involved in these assignments. During this episode she explores what ethical responsibilities we have, what a pentester should demand from a company before accepting an assignment, and what a company should demand back from a pentester.

Send us Fan Mail

SPEAKER_00

From our headquarters in Oslo, Norway, and on behalf of our host, Robby Peralta, welcome to the mnemonic security podcast.

SPEAKER_02

Now I don't know about you, but I've never used the word ethical in the same sentence as social engineering. Which to me makes sense, as there isn't much ethical about tricking someone into doing something you want them to do. That being said, I didn't really think about the fact that some professionals, also known as pen testers, do exactly that for a living. Breaking into stuff in the name of good, hopefully preventing any evil from doing the same thing at a later point. But as you'll soon learn, pen testers actually bear a lot of ethical responsibility in their engagements. They need to protect their clients from the bad guys, but they can't necessarily use the same tactics themselves. Why not, you may ask yourself? Sounds lame. But today's guest has a pretty solid answer and a great point to make for both the pen testers and whoever else is ordering them. Hey dog, niters hogging! Welcome to the podcast. Thank you. Also also popularly known as uh Bridget. Yes. Bridget doesn't strike me as like uh like a hacker name.

SPEAKER_01

No. It's uh it's just Bridget. It is basically because my second first name is Birgitta, and Bridget is the closest English name. Yeah.

SPEAKER_02

Well, we like it. Welcome, Bridget.

SPEAKER_01

Thank you.

SPEAKER_02

Tell us about yourself.

SPEAKER_01

Well, I am um I work for Norwegian Customs as a senior security advisor. Uh, and prior to that I worked as an ethical hacker specializing in social engineering.

SPEAKER_02

Cool.

SPEAKER_01

And uh I've been doing that for a couple of years, and I love to talk about social engineering and how humans respond to that.

SPEAKER_02

So why don't you unpack that for us? Because uh somebody reached out to me the other day and was like inviting me to a social engineering course. And I'm like, I'm the farthest thing from a hacker, or what I would define as a hacker. But he was like, no, but you're a sales guy, like you should be you should definitely know how to social engineer people. And I was like, okay, so there's a connection there. What do you think about that?

SPEAKER_01

It is.

SPEAKER_02

Yeah?

SPEAKER_01

Oh, it definitely is, yeah. I oftentimes when I meet uh salespersons, I oftentimes tick off boxes mentally in my head, oh yeah, they're using that technique now and this technique, and just no, and it's just like I I I usually don't fall for it because I'm just analyzing it as part of having some fun. But yeah, it is so it is the same. Basically, uh when humans are uh thinking of social engineering and cybersecurity, we think of, oh yeah, that's those phishing emails, etc. But social engineering in itself is a technique that every human uses each day to get what we want. And I oftentimes say that that is basically what the kids are doing to their parents every single day to get what they want. So, yeah, salespersons definitely use social engineering techniques, and that is because the social engineering techniques it's what makes people do what we want them to do or give the information we want them to give us.

SPEAKER_02

I guess another word for social engineering is kind of manipulating. That's a winner word, I guess.

SPEAKER_01

It is the same equivalent.

SPEAKER_02

So uh you were many years as a pen tester, right? Um yeah, yeah. Well it's it's a few years. Um I was thinking just like how much of your time spent as a pen tester was on social engineering compared to like the bits and bytes, sort of because you have to have you kind of have to have both, right?

SPEAKER_01

Yeah, the I was doing some basic uh bath pen testing and aiding in different things, but my main task was to be an analyst of sorts, like in bigger red team operations. My job would be to analyze the open source in intelligence that was out there, look into social media profiles of companies, etc., to see what angle can we take to get into the human elements. So mostly uh that's what I did. I didn't do well, I did some of the techie stuff, but not as intense as a lot of the really, really good ethical hackers I know out there. A lot of the pen testers I know are technical geniuses. Uh I usually tend to the human element of it. So it was nice. It was nice working together and helped them to get the entry point in bigger operations. And I also did a lot of pure social engineering tests where it was sending out the SMS smishing and some phishing, etc., creating those based on the techniques used against humans. And I also did some physical pen testing where the main goal was to see if you can access uh restricted areas or get information or see if people have left things on their printer, for instance, which is not according to policy and so on, and then I report on it to see okay, what procedures do you need to change to make the company more secure as a whole when it comes to the human threat?

SPEAKER_02

In 2024, do you think it's easier to do social uh engineering through digital means now than it was a couple years ago?

SPEAKER_01

Oh wow, that's a really, really hard question because I would say it is about the same. Uh we might be more aware in a sense. I I like to think that we're more aware, but you never know. Uh because there's a lot of things in media about phishing and uh how people are being scammed, etc. Love scams and so on, and phones, wishing calls, and one can only hope that people are getting more skeptical, but in the heat of the moment, everyone can be fooled. Even I, who also has tried to educate myself on the topic, can be fooled. And I would like to think that yes, maybe we are a bit harder to fool, but I don't think so. And now with the rise of AI and how that is being utilized to create different pretexts and to uh fake voices, etc., I think it will be harder for us for a little while before it gets better.

SPEAKER_02

Right. I forgot who it was, I think it was um somebody from Zscaler on LinkedIn today said if you're if you're reachable, you're breachable. Exactly. Right.

SPEAKER_01

And I I agree with that. If you're reachable, you are breachable, basically. Because everyone can be fooled, and we learn new stuff every day, but so does the adversaries. They learn new angles. When's when one angle doesn't work, they make up a new one.

SPEAKER_02

Yeah. And yeah, so it's then there's lots of angles to take, right?

SPEAKER_01

Exactly.

SPEAKER_02

Right. As somebody that does this for an ethical manner, ethical social engineering. Um on the other side of all these attacks that you just mentioned, there is uh there's a person that uh yeah, explain the feelings that that's gonna most likely go on in that person's head uh as a target of social engineering once they figured out that they've been tricked or manipulated.

SPEAKER_01

Yeah, definitely. When I used to work with social engineering pen testing, I started to think a lot about, well, here I am doing all these tests, and there are people involved that I have to report back on. And what happens to those people afterwards? I mean, we can all think about it, how much we laugh about people who have been fooled by someone, and what will happen to those you tests and how will they respond uh emotionally to it all? Like if they had opened the door for me, for instance, or given me access to a restricted area. Uh will their bosses be, hey, let's look at the procedures here now and see what we need to improve on? Or would it be like, well, you're gonna go to a mandatory security awareness training course and you're not getting paid for it while you're doing it, or even worse, in a lot of foreign countries outside of Norway, because we have a lot of good unions, uh, some people even get fired. Uh and it's not unheard of uh that, for instance, third-party vendors such as uh cleaning companies uh get uh loses their contract after holding the door for someone that wasn't supposed to enter the building. And the only problem is that we are placing the blame on a single individual instead of the whole system itself because it is not an individual's failure, it's a systemic failure. When one person can fail, everyone else can fail fail as well. So it is all about oh, do we focus on the single individual who sort of failed the test, or do we try to look at the reason why and how to secure that element so it doesn't happen again, to put around controls to strengthen that particular area, to for instance have granulated control of the door, etc. In the case where someone is holding the door? Maybe you should have like um uh vents to get people in one by one, etc. So it is that made me think that maybe we should look into that. Maybe we should think what about all these cool social engineering pen test stories you're listening into, people are listening to the war stories, and usually when I tell a war story, um I can always hear you know the laugh when someone is get giving me access and you you're like telling it to the crowd, and you know, they're like laughing a bit because uh they're thinking I would never fall for that, you know. They maybe they think that, maybe they they're like are more shocked and like, oh yeah, that was awful, or uh but it is in our we think like that because we really want to believe that we would not fall fall for it. And I wanted to explore the other side of that, the other side of the cool war stories where people are being duped, but to look at how do people actually respond to being duped and how should we actually treat them? What should a pen tester demand from a company? Uh, and what should a company demand from the pen tester when humans are involved in the test.

SPEAKER_02

In my eight years of being involved in penetration testing and sort of stuff, I've never uh I've never actually came across this uh topic, not once.

SPEAKER_01

It's important to think about the human element itself. Because when we do, even if we are doing not only pen tests, if you are doing internal phishing simulations, for instance, there are tons of uh well, Twitter now X content out there where you see people are, yeah, exactly, where you see people are nagging about the fact that well they were fooled in a phishing test and now they have to take secured awareness training, or now I can't trust my boss anymore because they fooled me thinking they were my boss, and now they're like yelling at me because I was stupid. And there are so many people out there you clearly see that even when people are doing internal testing, they're handling it wrong. They're either doing the content of their fishing simulation in such a manner that people are feeling like they have been scammed of something, like getting a Christmas bonus, for instance, and then they're told like, oh yeah, there was no Christmas bonus, you have been duped, and now you need to do training. It's like it's like dangling candy in front of a baby and taking it away and then punish them because they wanted the candy. It's just not right, and we never think about it because all we're thinking about is the end goal. We need to make this user safe, and it's just not about that, it's about strengthening the human element itself. And to do that, we need to make people not fall into distress, we need to make them feel like, okay, so I failed, but that means now I have an opportunity to learn and evolve. And to do that, it's all about how we're handling it. If you would have gone to, for instance, a kid and they would have done something wrong and you start yelling at them, what are the odds that if they do something wrong again, they will tell you about it? They will not tell you yeah, exactly, zero. They will not tell you if they have done something wrong the next time. They will try to hide it. So if a if a user pushes a link and they get yelled at because, oh you're so stupid, you pushed a link, you shouldn't have done that. Well, they will not tell you when they get a phishing email and push the link. So if they have pushed a phishing simulation and they've been punished, well why should they even tell you that they've done it again? They are afraid of getting punished and they will hide it, and if they hide it, well maybe the attacker had gotten access to the system, maybe no alerts have been triggered, and all of a sudden you have a ransomware attack on your hands, which could have been prevented if the user felt psychologically safe enough to actually hey say, Hey, I think I've done something I shouldn't be doing.

SPEAKER_02

Right. Yeah, I really liked your example there with the uh the gift card. Yeah. And you had some other ones in your black cat chat, the um the dream job thing. Can you would you mind sharing a few of those? Because I think those are things that people definitely should not do, you know.

SPEAKER_01

Yeah, definitely. So the one with a gift card, first of all, that actually happened to GoDaddy a couple of years ago. They actually sent out a gift card, uh a Christmas bonus, I think it was. They wanted to give a Christmas bonus to their employees, and I think this was during COVID times, and people were, you know, really far off. A lot of people needed the money, and people were so happy, you know, they were thinking that oh, it's finally gonna solve itself. I might have enough food to put food on the table for Christmas, and I might even have enough for presents for family. And then all of a sudden they were told that it was all a scam. And they actually, I think I also heard that they got this on a Friday afternoon and they went home and didn't hear about it being a scam before after the weekend.

SPEAKER_02

So the minus better.

SPEAKER_01

Yeah, like maybe they used their master card and say, Yeah, I can pay it back, you know. Yeah, exactly. Uh yeah, maybe, but it I mean they still went in with this sense of relief. Like, if you would have been told that you would get some money and it would actually solve your problem, and then it was taken away from you, uh I wouldn't be happy. And it has happened in a lot of cases also with pen testing, where people have been uh fooled, for instance, to uh well one of the stories that I oftentimes tell is about a pen tester in the US who had to check uh around on social media and he found a guy who had posted uh this picture of himself, you know, with the card on and everything, his access card, and it was like finally got a job of my dreams, it said. And well, he had to uh use that in the report because he used that picture to make himself a fake access card and got into the building, using that fake access card as a roost, seemingly like you belong there. And this guy he had just lost his father, and he was like, Oh, this I finally got a job in my dreams, my father would be so proud of me, it said. And then he lost a job. When when the manchers read that report, they thought of him as a liability to the company, and then he lost a job he had dreamed of. Just because of that, instead of you know people saying that, okay, this might not have been a good idea, now we learned, you know, so now we're gonna put that up in the in our transcript saying that we should not post pictures of our card or maybe tell them that hey uh this happened, uh, this should not happen again. Now we were lucky that was just a pen tester doing it, you know. Uh, that person would have learned from that experience if it had been handled correctly, but he just lost his job. And it has been some grave consequences, you know. We often think of social engineering as yeah, okay, that is it. You know, you make people give away credentials or information. Uh, but it also happens uh when people are pranking others, for instance. There was this Australian radio show back in 2012 that decided to call the hospital where Kate Middleton was residing when she was pregnant and pretend to be part of the family and get information about her health status. And they sent this live on um on the radio show. And this nurse, she believed them and gave away information. And two weeks later, uh she killed herself. I mean, we do not know if that if if it was other circumstances, but that was the triggering factor to push her over the edge. She might have had a really bad time in her life otherwise, but that was the factor that triggered it to eventually at least they're assuming that was the factor if she didn't leave a notes, uh to my to my knowledge. But I mean, if I would have been the that radio host, I would feel so bad.

SPEAKER_02

Yeah. Yeah. Is this a part of the pensum for uh you know pen testers doing these sort of things?

SPEAKER_01

Well, uh what pensum? Uh well, yeah, exactly. Uh a lot of pen testers uh usually do so-the engineering as a part of their uh red team job or part of a bigger operation, and some people think about it and others do not. I mean, most uh ethical hackers or pen testers are self-made, they make their way there, they uh learn how to pen test, and some of them are also really good at getting people to give away what they want. There are courses out there that uh provide people with knowledge on how to use social engineering, and some of them will also go into that thought of, well, you should leave people uh better off for having met you. And they try to do that, but it's really hard because you never know how a person will respond on the other end. You might think that, oh well, I have I have done it correctly. I mean they should feel good about it. But maybe not. Maybe you would have felt good about it, but you do not know the mental state of that other person, meaning that you would have to take care of them or have more responsibility in how they're dealt with after they get the knowledge of that that they have been duped. Like you need to focus on uh getting the customer to have proper debriefings. You as a pen tester need to focus on how the company is willing to deal with them, and actually you have to have the courage to say, well, you know what, I don't want to take the job because I don't feel secure enough that you will deal with these humans well afterwards. Because some pen tests are all about humans and some pen tests you only well you only get initial access from a human and you can try to anonymize the report a bit and try to not disclose who it was, but usually you have to because the account has been compromised. But then it's your responsibility as a pen tester to actually ask the questions. Well, if I get a hold of someone who will give me credentials, how will you deal with them? But asking those questions is not something that you inherently learn to do, and that doesn't make the pen tester a bad person for not asking it. It just it's just about the need to know.

SPEAKER_02

Well, their goal is just to accomplish uh the means and right, and then they celebrate. Unless they've burned themselves or uh worst case burned somebody else, right? Then they wouldn't know that unless they heard this podcast, I guess.

SPEAKER_01

Yeah, well, uh I can only hope that some of them will listen into this and be like, oh yeah, maybe I should take that up, you know, in my questionnaire when doing this. And because we all think that, well, people should deal with it. And I know a lot of people out there, not just only pen testers, but a lot of people who would act like, well, if they're stupid enough to give away the credentials, they would have to deal with it, you know. Then if they're so stupid, and people will be like that, but then again, what if it happened to you? I mean, it could happen to you. Even the best pen tester out there could be fooled if the circumstances is right. And so we need to think about it that everyone can be fooled, and that makes it our responsibility to also help them deal with the aftermath of it and help them to get into that mode where they can start the learning process and learn from the experience.

SPEAKER_02

So all the pen testers out there listening to this, make sure you add those questions at the end. I think that's just a very healthy conversation to have with your client as well. They may not think about that as much as we would expect them to either, right?

SPEAKER_01

No, no, and they will actually just respond then and there. They would get report and they haven't really thought about it, and they will be like, oh, we need to do something about this, and then they will do something, and then they will end up feel guilty because they have done something that had an adverse reaction for that person. So we should always think of it as well. I oftentimes say that when you're doing bigger pen tests and humans gonna be involved, especially when you're doing something with phishing simulations or even internally phishing simulations or doing pen tests where you're gonna call someone to an extent, maybe have HR involved. In it to actually have them. I know people will say, Well, that will be a gatekeeper, you know, they will take away all the fun and all that, but is it really fun if someone is rendered feeling like shit afterwards? So you gotta you gotta take it all in and just think about it and at least have someone take care of them in the aftermath. If it is HR, for instance, having talks with people and let them vent, let them talk about their experience so that they can finally, you know, start healing and get over it. So I oftentimes try to say to the companies that you know what, if any one of the people I met, usually when I did social engineering tests and I went in physically or had to talk to someone, I oftentimes say that, well, if they need to talk with me afterwards, I'm open for it. They can call me, we can have a video chat, we can do it do that so that people can feel that they can talk through the event with me and not just feel like someone they trusted then and there fool them. I mean, if you have been scammed by someone, you would feel so ashamed and you would feel so mad at that person for scamming you. And if you have all those reactions, you will not be ready to start healing and to start thinking logically about the experience. You will just have this emotional roller coaster inside of you and where it will go through all the stages of sadness and anger and everything, and you will just not it will take time to get over it, and for some people they will never get over it. So by by resetting that relationship that happened uh while you were while you were fooling them, you will make it for them such such that they will be ready to learn. They will feel like, oh, well, okay, this happened. We talked about it. Now I can start thinking about the situation. What could I have done differently and how can I progress going on from here?

SPEAKER_02

I'm sitting here thinking that every pen test, uh, somebody's gonna get their feelings hurt, whether it's the the employee that you're fishing or the CISO that whatever didn't organize things properly, or the pen test didn't that didn't make it work, right? So yeah, I like your approach of um, yeah, because it's usually, I guess, there's usually an employee that's not to blame, but there that's the way in, right? Sitting there and just maybe having a conversation saying, or the way I would do it as a social manipulator myself, I guess, uh, or a social engineer, I should say, and just say, hey, uh, we did this test because XYZ is important to protect the company. Uh we know that like the whole goal was to trick you into doing this, and it's not because we want to, you know, uh prove that you're wrong or anything, but we really want to have this conversation with you now to hear how you are like the the circumstances and like uh how could we prevent this from happening again? Not for you, but for you know, the role that you're in, because we know that your job is to do X and Y. How would you, you know, how can we remove this risk?

SPEAKER_01

And it's not about you, and you know, try to is that something that would be like a nice way of approaching it or yeah, I think so, because you have to take it away from personal blame into to and to look at it as a systemic thing. Like you need to figure out what to do to secure the surrounding area and to help a person not fall for the same thing again. So it's not about blaming a person saying that oh you you fell for it, you're stupid. That's not how it works. So you gotta start thinking about rationally and having an approach where you uh don't focus on the human of uh human itself uh when trying to solve the problem is a good approach. Uh and if you also make room for the people who have been affected by it, having reactions, emotional reactions to it, and allow them to have an emotional reaction, then you can come quite far. And I would also say that when uh when people are testing, uh well when pencisters are testing people, uh it is also important to think of them as people, not just uh and then so it means you know, it's just not about just getting that password no matter what. You have to think about how you're doing it. Are you gonna make them feel so emotionally distressed that they're gonna give it away to you? Are you gonna lure them uh trying to give them something and not giving it to them, for instance? You have to think about the way you're doing it. I don't know people say, yeah, well, but the attackers do it. Yeah, but that's what separates us from the bad guy. I mean, in usually when we're testing uh computers, we're thinking, well, what separates us from the bad guy there? No, well it's uh you either get in or you don't. But usually when you're testing the system, you don't actually launch ransomware on there just to prove a point as a pen tester. You don't render the data useless or you steal the data and say, hey, you're not getting them back now because you were stupid. And you're not doing that. You stop at a certain point. And you gotta do that as well when you pen test humans. And well, how will they learn, people say. Uh people often ask me that well, how will they learn if you're not using the same techniques? Well, you're not, and I oftentimes um compare these two things, because I oftentimes think of pen testing humans and doing fishing simulations as something that maybe we need a bit of a change in the future. It's not something that we might have right here, right now, but when it comes to human pen testing, uh maybe it's better to have this approach that we're doing like a fire drill exercise, like saying, hey, someone named Fred is gonna come within the next three months, and he's gonna try and gain access, and the one who stops him, they get a challenge coin. Like they're gonna get something, a treat, you know? And within those three months, maybe someone will come up and they will have like this sweater on which will save Fred, and they will try to to fool a person. And then they will see, wait a minute, this says Fred, like the subconscious will be starting to work, and they'll be wait a minute, you're not allowed to be here. And that in itself, yes, of course he didn't get to breach them, but they will have the courage to actually stop someone when it counts later on. They will start learning from that process. Because when we are doing CPR training, for instance, we're not actually having a person having a heart attack in front of the people learning CPR and say, hey, you gotta save him now, you know. We're doing it on dolls, and it doesn't make us worse at doing CPR when it counts. So yeah, that's my thoughts on it at least, because I think that yes, as it is now, we have this way of testing people doing phishing simulation on a regular basis internally. A lot of companies do that at least, especially in the US, and a lot of Norwegian companies do as well. And then some people have pen tests purely on human element, and some it's only a part of the whole thing. Uh it's just about when it's just about the people, we might need to rethink how we do it.

SPEAKER_02

Right.

SPEAKER_01

One thing is checking a lock or checking a system, another thing is actually, well, the humans Well, you gotta train them to be able to stop someone. And you're not training them by saying, Hell, you failed. You're training them by by teaching them how to speak up, by t teaching them how to stop it in the act and gain that confidence. You need to gain the confidence.

SPEAKER_02

Alright. Have you ever been a part of uh a test where the HR was a part of it and actually had like good um like good things to say about exactly this part?

SPEAKER_01

I have never actually had HR in itself, but I had uh companies where uh the management has been very much on board with it and been also said that well we will contact HR if needed and having debrief if needed as well. And I had full access to seeing how they wanted to do it and how they were gonna approach the talks afterwards. Cool. Uh and then they had like my phone number, you know, so that the ones who were fooled could talk to me later on. And now that I think about it, there was actually one time where I experienced that HR was partly involved. I did not speak with them, but I know they spoke with them in the back, and I actually sent pretexts up hand, and they were well discarded or approved uh based on several people in the back. And I think HR was involved in that as well, because I told them that it was an important factor. Yeah, uh, but I cannot confirm if it was the HR person or just someone, uh someone in management uh personnel responsible or something like that. But yeah, it is some people who do it.

SPEAKER_02

I can understand the skepticism from like a CISO or some somebody ordering a pen test to not want to involve HR. But I think it would be number one good at anchoring the support you have in the organization, just making sure you get the full effect out of it. Even though HR can be very stiff sometimes, and also maybe uh maybe I think that security people may be a little nicer than uh HR people sometimes. I don't know.

SPEAKER_01

Yeah, and when it comes to humans, I mean if you're doing it wrong, you're gonna have a really bad time afterwards. I know it's a hassle to plan something when you feel like people are stopping you at every turn when it comes to humans, like, oh yeah, I want to test these people, and they'll be like, no, you shouldn't do it like that, etc. But if you're doing it wrong and then you're gonna have this big HR case against you later on, maybe it was best to actually do the hassle and take HR into account to begin with. So there is a lot of ways to do it, and uh not everything suits every organization, but one should at least think about it, because HR might have some intel on which people are not eligible for testing, for instance. Maybe they know someone who has without being able to tell you know, someone who are have been on sick leave, maybe they've had a mental break or being burned out recently, and then you're coming there, or maybe they have a lot of stress at work. It's their job, you know, to at least protect them from well, the company themselves attacking them. One thing is the attackers around us attacking them, but if the company is doing it as well, then who can you trust in the end? Yeah, exactly.

SPEAKER_02

Exactly. Well, Bridget, do you have any closing thoughts? Any um any predictions or any cool things you're working on for the future that you'd like to share?

SPEAKER_01

Well, first of all, I would say that this is not a simple thing to fix. It's not a thing that everyone can fix in the same way. It's all about the company culture on what is okay to test and not. It is all about the expectations and the management of them. And uh me coming here saying that, well, you should be doing you should involve Asia, you should do this and this and this. Well, not uh it doesn't fit everyone. Like a tire does not fit every car. So you have to adapt and try to be as respectful as you can towards the people involved and think of them as humans and not just some targets to gain access and to finally reach that goal. And for a future, I'm hoping to personally I hope to look more into AI and how that will affect social engineering going moving forward, because that is an interesting topic in itself, to see how will it be when it will be nearly impossible to distinguish a person's voice over the phone from an AI and someone you know really well, and to see how that will progress on and to see how we can pr protect humans against that.

SPEAKER_02

Yeah. Well, in the meantime, the least we can do is make sure that we are uh taking uh our fellow colleagues and uh humans into account when we have to uh give them a potentially uh hard message to hear, right? Yeah, exactly. Well, Bridget, thank you so much for sharing. Um I'm not sure if I will ever order a pen test, but I will make sure I ask those questions if I do. And it'll be the new.

SPEAKER_01

Thank you.

SPEAKER_02

Thank you very much, Bridget. Have a good evening. Bye-bye.

SPEAKER_01

You too. Bye.

SPEAKER_02

Well, that's all for today, folks. Thank you for tuning in to the Mnemonic Security Podcast. If you have any concepts or ideas that you'd like us to discuss on future episodes, please feel free to hit me up on LinkedIn or to send us a mail to podcast at mnemonic.nl. Thank you for listening, and we'll see you next time.