mnemonic security podcast
Hosted by Robby Peralta from mnemonic, one of Europe’s leading cybersecurity companies, the show features conversations with researchers, founders, operators, and security leaders working across the cybersecurity landscape.
Each episode explores a specific topic within cybersecurity: from incident response, threat intelligence, AI, and geopolitics, to leadership, resilience, and the changing role of security leaders.
The podcast is tailored to cybersecurity practitioners and decision-makers who want grounded conversations about where cybersecurity is going, what organisations should prepare for, and what experienced people are seeing.
mnemonic security podcast
Social Engineering TTPs
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
“Human behavior is not going to change significantly year after year.”
In our latest podcast episode, Robby is joined by Rob Shapland, ethical hacker and Director at Cyonic Cyber, to explore how social engineering works in practice today.
Despite advances in technology, social engineering remains an effective attack method. Whether it is a convincing email, a friendly conversation, or a well-timed request to the support desk, attackers continue to exploit human trust.
In this episode, we discuss how social engineering tactics have evolved and what still stays the same, how new tools are making attackers more effective, and real-world stories, including how many buildings Rob has gained access to during his career so far.
Rob will also be speaking at mnemonic’s annual conference, C2 Summit, this May. Check out the program and see if you should join us as well: mnemonic.io/c2-summit-2026
From our headquarters in Oslo, Norway, and on behalf of our host, Robby Peralta, welcome to the mnemonic security podcast.
Robby PeraltaSocial engineering is the oldest trick in the criminals playbook. A friendly conversation, a convincing email, a helpful request to the support desk. Nobody's gonna watch your fishing training videos, but show employees a pen tester who sweet talked their way into the office while filming everything, and now everyone is paying attention. Suddenly those annoying processes we're supposed to adhere to make a little more sense. So today's guest is here to help us understand how social engineering works today. And what organizations should actually be doing about it. Rob Shapland, welcome to the podcast. Thanks so much. Great to be back. It's been a while, isn't it? Way too long.
Rob ShaplandWhat have you been up to these days? Um last year, I've got my own business now, which has been fun. I honestly don't think I could go back to having a boss anymore. It's been great. And I just I really enjoyed all this stuff at the start, like setting up a logo and you know, using AI to help design all that stuff. And then uh the website and coming up with the services and all those documents and stuff. I loved it all. It's great, great fun. And then when some actual people actually start buying, you're like, oh yes, great. How many buildings have you broken into so far in your career? With career in total, about 150 to 200, something like that. But since I set a business up, probably about 20 or so. So okay. The 20 is probably above average for the amount I've done per year because I've been doing this for so long now. But it's been it's been good. That's actually, I thought when I set the business up, I thought training would be the most part of my business. But actually, so far it's been more social engineering than training in terms of like size of projects and things as well.
Robby PeraltaYeah. You still have your own, I don't want to say clothing company, but last time we talked, you had something that you can make your own clothes and your own logos just to be able to copy like brands that you're gonna break into.
Rob ShaplandYeah, it's um so it's not me, it's like someone I know that can create stuff for me. So, so yeah, sort of if I need a particular outfit, because the problem you can have is if you go to a reputable company and say, I want an outfit for this particular, you know, large brand, they might question you a little bit and go, why little shady people that you work for this company and why do you want one badge from from this company with your face on, saying you're a IT person that's sort of dodgy, so you need to know someone that's kind of happy to do that for you. Uh so it's quite handy to have that. Yeah.
Robby PeraltaWhat does the the physical pen testing slash social engineering landscape look like these days?
Rob ShaplandYeah, yeah. So since I since I set the business, I've done done quite a lot of building break-ins. So normally how it works is I'll ask the client for what objective they want me to achieve. So some are just happy for me to go in, film some footage, walking around the office space, and then play that in the training afterwards, where the other, whereas others set more complicated objectives. So it might be can you get into our server room, which is normally quite a difficult one? Can you steal some paperwork? Can you get onto a laptop like someone's left it unlocked and unattended? And you get on and you plug in a USB stick or something like that. One one thing I've been asked to do a couple of times this year is either plug in a USB rubber ducky, that device that looks acts like a keyboard and then sends commands, or uh an OMG cable, which is like a USB-C cable, looks identical to a USB-C, but you can program it with different things that it can do. So you can plug, once it's plugged in, it can be a keylog or all sorts of stuff. And it's quite a unique bit of kit because once you plug it in, it's like there's nothing visually about it, it looks any different to a normal USB-C. So some of my clients have like docking stations. So you you know every desk is a hot desk, you just come in, you plug in via USB-C and you start working. Swap out one of these cables, and they're gonna just give you everything that they're doing. So that's quite been quite fun trying to plant those cables into networks as well. So it looks like that, I've been doing a lot of training. So whenever I do the break-ins, I always film it on hidden cameras, and then afterwards you can use it in the training because that's just a lot more engaging for the training. If you haven't got someone saying, just oh, don't let people tailgate, but instead you've got someone say, Well, don't let people tailgate, and here's what happens if you do, and you've got video footage. Normally you have to anonymize it, you know, but people don't want to embarrass whoever let the person in, but I blur it all out and stuff and then play it in the in the training, and you get such more of an engaging impact with everyone if you do that.
Robby PeraltaI thought of you when I tried on those meta sunglasses for the first time with the camera. I was like, I didn't know that Rob has these.
Rob ShaplandYeah, yeah, they're they're super cool, aren't they? I mean, they're really obvious, they're filming. The ones I use have you know, you can't actually see the camera then you don't know that you're filming, but yeah, I I quite like those things. I I mean they're expensive, aren't they? But I did try them on in the store in uh Gowick Airport. I think I thought, look, I want these, these are cool.
Robby PeraltaThe ones that you have, is that something you created yourself then?
Rob ShaplandNo, no, you can buy them, but you have to be able to prove that you're either law enforcement or in my field. So they're they're like a pair of normal glasses, so rather than uh sunglasses, and they have a camera in them, but the camera is disguised as like a decoration essentially on the glasses, like a screw, and they're quite thick, but then a lot of people wear thick glasses now anyway, don't they? So it doesn't look weird. And then you've got a memory card in the arm of the glasses and you kind of activate it with a button on the side. They're probably not the video's not as high quality as the meta ones because it's like a smaller bit of kit, but still works brilliantly.
Robby PeraltaSo, you know, in the the traditional pen testing, I've heard many times that clients do a pen test, come back a year later, and the same holes will be there.
Rob ShaplandYeah.
Robby PeraltaIs that your experience in physical pen testing as well, or do they actually implement the changes?
Rob ShaplandSo I think luckily for me, I've got clients who are doing it not just because they have to do it. You know, a lot of a lot of pen tests like you described, they're doing it because they have to get a tick box in a somewhere in a compliance spreadsheet or whatever, or for insurance to say they've had a pen test. And sometimes they don't follow that up. And you get the same thing every year. But with with physical pen testing, I think because for most clients, it's not uh like a requirement they have to do. So they just want to do it, they want to to check whether their security is good. So they do implement the changes on the back of it, which is interesting because you you find a hole, uh like a flaw in the in the defenses, whether it's they're uh uh they're susceptible to tailgating or whether it's they don't have a good visitor process, and then you exploit that and then actually they fix it, you're like, Oh god, it's just made my job much harder for the following year. And it's often not me following up the following year because everyone knows my face by then, so I use kind of a team of contractors I've got to do the work. And you know, I've got to tell them, well, you can't use this because they they know what they're doing now with that, and I've kind of discussed it with them, checked it, it's it's all good. So you're gonna have to try some other scenario. And so I do end up making my job harder. But yeah, I found with the physical pen testing, the clients do seem to implement the changes. Not if I it depends what you recommend, right? If I say to them, okay, you should replace your normal door with an airlock that you know everyone has to go in one by one, they're not gonna do that because it takes too long to go through. So you've got to be a little bit pragmatic and uh and understand what the client can afford to do and what's relevant to their kind of size of business and the risks they face. But if I recommend process changes and things, they tend to they tend to do those, yeah.
Robby PeraltaJust on in general, what do those advices look like? Where does everybody screw up?
Rob ShaplandSo um with with tailgating. So a lot of companies, um, especially outside of London, their building won't have security barriers to the doors that open and close that are quite hard to tailgate through. They often just have a door and you know someone scans through and then hold the door open for everyone else. So I always like think oh, tailgating is a really simple thing to do, and it is really, but there's you can mess it up quite easily. Yeah, a lot of people get caught when they're doing social engineering when they try to tailgate someone because they do it in a really obvious way. So we or me and my team of contrast, we have kind of two main styles that we do it. So you'll either be really friendly, so as you're going into the building, you'll start chatting with the person that you're following and go, oh, you know, rainy again, isn't it? And you know, just generally chatting and talking about your day and things like that. And because you're being nice, there's kind of this quid pro quo that they'll be nice back to you and hold the door open for you. And because you don't look or sound like a criminal, they just do it. The other option, which I use quite a lot as well, is to hang back from the person you're gonna tailgate. So they go in and then you dash the last like 10 meters as fast as you can to get to the door before it closes, and then just hold it and then wait another 10 seconds and then push through, and then they have no idea they've been tailgated, which works really, really well until you've then got another door straight afterwards, which happened to me a few weeks ago. I was doing a test um abroad, and the main entrance to this building was really, really well protected. So I had a security guard watching a single doorway. And every single person that came in had they had to queue up, they had to scan in, the scrutiny guard watched them scan in, they had to go through the door, they had to pull the door closed behind them. So there was no real opportunity to tailgate. You couldn't do that, not unless you had a badge that was working. But they had a goods in entrance at the back. So no, no valid reason why a normal employee would use this entrance. But I thought, you know, maybe deliveries come here, I can tailgate a delivery person. Sat on a wall for four hours with a very cold coffee, just watching this door. Eventually, eventually, this furniture van came in into a lay-by, pressed the buzzer, one of the staff came out about five minutes later, let the furniture people in. They were just doing uh like delivery and collecting old furniture as well. Um, and I thought on the third time they went in there, I thought, right, now's my opportunity. So I dashed across the road, did exactly what I described, you know, waited, got the door, waited, waited, waited, pushed through. There was another door right in front of me, and then the door behind me closed. Uh, oh God, I'm stuck in a room that's like three meters squared. Luckily, one of the other furniture people was obviously a rival late or something and buzzed, and they they kind of let him in. And I managed to just kind of escape out that way. But yeah, that that style can backfire sometimes. So, so yeah, so tailgating is one of the one of the big threats. And that's about teaching people to be okay with challenging, but you kind of need to get buy-in from the senior staff that it's all right for people to to challenge because you're going to end up challenging people that might have been there for 10 years if you're new to the business and it's really embarrassing. And you just need to make sure the people that are the ones that have been challenged aren't idiots about it. You know, they just go, uh, well, challenge me. Yes, I'll come down to reception. And then the other main process fail you have with social engineering is to do with visitors. So I often turn up with some story about I'm there to fix the IT kit or I'm there to do an environmental audit on behalf of the local council. And sometimes I'll make calls in advance to try and book the appointment in. But the problem that companies have is they don't verify those visits properly. So they they look at me and I'm dressed in the right way. I've got an ID badge. You know, maybe there's been a call in an advance to book me in, but they've never actually called back. They've never checked that appointment is legitimate. And I use that a lot. I actually prefer now, most of the time, trying to book in an appointment with the company and do something once I'm inside because all the risk is taken up front then. So reception, they either let me in or they don't. And then if they don't let me in, it hasn't burned me completely because only one person's seen me. And it's not that I've been revealed as a social engineer. They just don't believe whatever story I I've said, you know, I'm there to fix the IT. They just don't, they go, oh, and there's no appointment, you have to come back. It's not like I've been burned at that point, so we can come back and try something else at some other point. So that that visitor process, I often check. I prefer doing that than tailgating. Because if you tailgate and then you're inside and someone questions you, it's quite difficult from that point to explain why you're there. Whereas if you've got a visit booked in, let's say I've gone in as uh an energy auditor. So I'm there on behalf of the local council to measure temperature leakage from windows and things like that. If I can convince a receptionist that's a real appointment and they give me a visitor badge, at the point where I get a visitor badge, it doesn't matter anymore. I can be there as long as I want. The only thing I need to do is just shake off anyone that's accompanied me by making it as boring as possible for them, whatever I'm doing. And then they walk off and then I can do my whatever I need to do once I'm inside.
Robby PeraltaSo it seems like your TTPs have not really changed that much and they still work, even if companies do this for the second time.
Rob ShaplandYeah, the TTPs don't need to change that much because you're relying on human behavior, right? So human behavior is not going to change significantly year on year. The only thing I change, and if it's a client that I've done before, maybe I try year one, I try Tailgate, and year two, I try a visitor thing, and then maybe something else. And then year four, I might go back and try Tailgate again because people tend to forget, you know, they forget the processes or or you test a slightly different approach to it. So yeah, you don't need to be in incredibly complicated with the TTPs you're using. You just need to be kind of confident and know what you're doing.
Robby PeraltaOkay, TP TTPs haven't changed. Uh, what about the tool side? Are you, you know, I'm thinking of data brokers. There must be a bunch of new tools out there that make imitating, you know, a vendor or you know, along those lines. Uh is there any new cools, new tools you want to mention that have made your job easier?
Rob ShaplandYeah, I mean, I think from from an overall social engineering perspective, not just the in physical intrusion, I've been using a lot of voice cloning software to help with the attacks targeting people over the phone. So that that works really, really well. So I've been using 11 Labs as the main one because I think it's probably the best that I've that I've played around with. And the fact that you can make it sound realistic as in you can put all the ums and uhs in and emphasis in the right places and things like that. And as long as you've got a decent sample of the person's voice, like it says you can make a sample with 10 seconds of audio, but it's a pretty rubbish. But if you've got about three minute sample of someone's voice, and you know, for large companies, even medium-sized companies, you can always find an audio file of the CEO or the CFO, you know, rip it off YouTube, whatever. There's something available that you can use. And then you can do calls into staff saying, Can you do this for me? Can you do that for me? Um, so I've done, you know, I've cloned the voices of service desk operators to try and get passwords read over the phone. I've cloned CEOs, CFOs, phoned up the service desk and got passwords reset by sounding like that person. And you know, when you're phoning up as someone very senior in the business, you've got that air of authority. So that puts more pressure on the person. And when you sound like that person as well, you know, you can even like copy the kind of speech patterns they use and stuff because you've, you know, if you've watched an hour YouTube video of them, you know, roughly how they speak and things. So you can you can copy that as well. And you can even, if you want to, if you're feeling lazy, you can hook it up to Chat GPT and give it a prompt and ask it to convince someone to do something. It's quite, it's quite fun to play around with. Say you are a service desk operator, you need the person on the other end of the call to give you their password for whatever reason. You know, you need to be very, very convincing and it'll argue with the person. It will get one I did a one test with it with a client and it started shouting at them. Like so you can get it to do all sorts of random stuff. I normally use what's called text-to-speech where you type out what you want to say, just so I can control what's what's said. But if you don't know where the conversation's gonna go and you can't type fast enough, you can you can hook it up to AI to help out as well.
Robby PeraltaThat's crazy. So when it comes to Eleven Labs, I've copied my voice with the labs, but I had to like give it permission. How do you get around that?
Rob ShaplandYou just say I've got permission. Like isn't that easy? It's as easy as that. So I I mean I do have permission. Like when I'm doing it against the clients, I will seek, I will say, like, do I have permission to copy senior people's voices? And they go away, get that permission. That's fine. But obviously, in reality, if you're a criminal, you're just gonna say, Yes, I've got permission, because there's no actual checks on on whether you have actually you're just self-certifying that you have it. So yeah, yeah. And then I and it's know your customer. Yeah, yeah, exactly. Yeah, yeah. So you cloned your voice. It sounds, yeah, you give it a decent enough sample. It does sound pretty close, really. Um family members might not know, might might recognise the difference, but most people wouldn't know.
Robby PeraltaYeah. And then the criminals, like maybe if they don't use Eleven labs, there there surely are open source models out there.
Rob ShaplandYeah, yeah. There are plenty. There are plenty of plenty of models that will do it um for free if you if you don't want to play anything, um decent enough to to fool someone. Especially, you know, if you're doing it as a phone call, you can easily put you know distortion on the line, make it sound like it's a bad signal or whatever. So even if the voice isn't perfect, it'll probably close enough that you can trick someone. Um yeah, I mean leave a voice note for someone, ask them to do something, it works pretty well.
Robby PeraltaYeah. So it's it's totally possible to automate a full-on conversation without the person on the other side of the phone knowing these things. Yeah, absolutely.
Rob ShaplandYeah. So I could, if I if I didn't want to do it myself, I could literally say, This is what you've got to do. You've got to get this information from this individual, use this voice to do it, and it will go ahead and do it. Yeah, it might, it might not be as good as you could do yourself, but you if you were playing a numbers game, you know, if you were phoning up 100 people, you could automate it all to just keep phoning. Yeah, absolutely.
Robby PeraltaRight. Has there been any developments in the OSINT game to like if you're gonna you have to first of all know who these help desk people are? I guess LinkedIn is your main tool. Are there any of the ones you want to mention?
Rob ShaplandUh LinkedIn's my main tool, yeah. Um, one of my favorites is talking to chatbots as well, like AI chatbots and trying to get information out of them as well. Because sometimes you can trick them into giving you like internal service desk phone numbers and things that that you need for these attacks. So, yeah, I've been doing a lot of that. And even if you end up getting through to a real person, you can still try and convince them. You know, I'm a new employee of the business, I didn't know where to go. So I just went onto the chatbot. I need to speak to IT service desk because my password's not working. Yeah, if you prefer to do it that way rather than phoning the company up and asking, then you can do that. And so I've been playing around with it with a lot of that stuff as well, trying to get information out of AI chatbots and normal chatbots. So that's been good. And then you've got all the the sort of data breach services where you can see the passwords and things of people. So one of the first things, you know, if you were to say to me, you know, attack my company, one of the first things I'm gonna do is go on the one of those websites and go, okay, there are any passwords out there that I can try and log in through Office 365 or whatever. And if you haven't got MFA, you know, I'll be straight in using those passwords. So there are plenty of services out there that are that are free, or so you're a sample of passwords from a company, but others you have to pay. But it's yeah, it's peanuts, you're not paying a lot of money, you know, a couple of pounds a week or something to to get access to every password that's been breached and and what uh you know, you just read that password in plain text.
Robby PeraltaAnd that's info stealers, basically info stealer logs or whatever.
Rob ShaplandYeah, yeah, exactly. Yes. It's like if you go to a website like Have I Been Pwned, and it'll tell you like you've had all these breaches. It's just the other end of that. It'll show you what the password is as well.
Robby PeraltaOh, exactly. Yeah.
Rob ShaplandYeah.
Robby PeraltaWhen it comes to the chatbots, like getting the information from chatbots, that's kind of their job. What are you what is your advice to clients around or is there any advice? Is that just how it is? And if you put that out there, that's a risk you have to accept.
Rob ShaplandYeah, I think it I think it's a risk you have to accept because you know you can put guardrails and say, you know, you can't give away this information, that information, whatever. But as we've seen, you know, there's always jailbreaks or whatever. And you know, it might be quite complicated to jailbreak Chat GPT itself, but an individual chatbot that's deployed for a specific purpose is much easier generally to trick it into doing something. So yeah, I think when you as a company, when you decide to deploy a chat bot, you there is a risk that you're that you're taking that some information could be revealed through it if someone's malicious is trying to trying to trick it.
Robby PeraltaYeah. So speaking of calling up health desks, help desks, uh, Marks and Spencer's co-op, um, Jaguar. I'm not sure if that happened there, but a lot of the scattered spider playbook is to call up these help help desks. I'm not sure if you've had the opportunity to sort of research what actually happened or if they're if that uh data is available. But uh, if you have, could you walk up, walk us through exactly like what actually happened in those?
Rob ShaplandThere's quite a bit of information available, and I can kind of fill in the gaps with with how I know it would work. Uh and also I've been doing it, I've been simulating it since it's suddenly been a lot of client demand for simulating that process, of course, and recommendations on how to kind of get around it. So so yeah, so they would have they found out that Marcus Spencer's been using an outsourced service desk company, which happened to be the same as a lot of the other companies that were hit. Um they found out there's various ways you could do that. It's probably a press release, something like that at some point. And then they would have identified Marcus and Spencer's employees, most likely through LinkedIn. Uh, you know, kind of head off if people uh pretend to be someone in authority within the business. So look for a reasonably senior person, then phone up the service desk number. If you don't know the service desk number, then you just phone up the main helpline number of the company and tell a sob story you've just died the business, forgotten your password, or haven't been issued with a password. What's the service desk phone number? And somehow I'll give it to you. So you get hold of the service desk phone number, you phone up the service desk and say, hi, I'm such and such person from MS. About to go into a really important meeting with a supplier or a client or whatever. I need to do a presentation, but I can't log in. My password's not working. I haven't got time to go through a normal process. I need you to urgently give me the password now. And you know, you're relying on a combination of things to stop that. It's process. So, you know, there should be a defined process of okay, someone phones up for parts of reset. I need to get this bit of information from them. Now, that bit of information might not be very hard to get hold of. It might be who's your line manager, which you can look on LinkedIn and find that as well. What authors do you want to get? Again, probably find that on LinkedIn. You know, what's your date of birth? Maybe I can find that on Instagram or whatever. You know, it's not going to be particularly complicated. Or you might just be able to convince a person at the other end of the line to bypass that process. And that's the problem. When you've got a human at the other end of the line, you can trick them. You can use psychological tricks like being an authority, like it being really urgent. You know, you're about to go into a meeting. I haven't got time for this. You know, I'm going to talk to your boss if you don't sort this out for me. You know, putting that pressure on the individual, then maybe they bypass that process and then give the uh password over the phone, which is essentially what they did. They gave the password to the person. They, the scattered spider person, then also managed to convince them to disable their multi-factor as well. So if you've come that far, you go, okay, my, you know, I still can't log in. My MFA is not working. I've lost my phone, whatever else. Can't get access. Can you temporarily turn off my MFA? And then they turn that off as well. And now you've got a Mark Suspense, senior person's email address, password, and no MFA. So you could they should just log in and you go through Office 365, you have access to all sorts of information through their SharePoint, et cetera. And in the case of MS, they the first person they compromised didn't have like IT admin rights on the network, wasn't an IT person. So they went through the list of employees that they had access to. Now they've got access to SharePoint and everything else, and then got a second, did the same process again, just with a more senior IT person, got their password reset. As soon as you've got uh access to an IT person's account, you can log on essentially to every computer in the network with an ad as an admin and do whatever you want. So you can turn off antivirus and things like that. But what they did was they used that to deploy ransomware across Mark Spenses like ESXI virtual net machine network that allowed them to disable everything in the business, really. So a relatively simple process, to be honest, let down by a service desk that was either had poor processes or wasn't following those processes, allowed them in. Of course, there's more, you know, there's technical stuff you need to do beyond that to move around the network and and you need to know what you're doing in terms of how to disable the security systems. But you know, that's bread and butter for a lot of these these hacking groups nowadays. The service desk password reset was a relatively unique thing, primarily enabled by the fact that they spoke English as a first language. You're not talking about trying to, you know, use a translation tool or whatever and sounding really awkward. You can sound like a a real employee because you know it's your language.
Robby PeraltaYeah. And I guess it helped them, it made it easier for them since it was an outsourced help desk. So that didn't I I guess it would have been maybe a little bit harder if they were internal, but then you would just have to imitate the right voice to get around that.
Rob ShaplandYeah, it would be hard if it was internal because yeah, potentially the person would know that voice. You could voice clone, but then you know, if it's a long conversation, they might they might get a picture that sounds a bit odd in some ways. And you also might find that if you're phoning up as a senior person in that business, the way you speak and and the manner in which you you engage with people is is well known. And so it might just be the service desk person, like, this just doesn't sound like how this person speaks. They've never spoken. Why is he being so nice today? Yeah, I guess it's often that, isn't it? It's like when you see phishing attacks and it's signed off with you know many thanks or whatever, it's like the CO never says many thanks, they just end an email. So yeah, it's like those little things, but an outsource service desk wouldn't know those things. Uh and also when you're calling an outsource service desk of a size of company that was handling MS's one, when you make multiple calls, you're gonna get three to different people each time. So if the first time fails, you just call someone else two minutes later and you just keep trying until you manage to convince someone to do it for you. Whereas if you're talking to a service desk and there's a three people in that service desk, that's not gonna work, is it? Because it's gonna be very obvious that something weird's going on if I keep receiving calls from the same person. And so, yeah, the outsource service desk is definitely a vulnerability for most companies.
Robby PeraltaSo I can imagine that you've done this uh since those attacks happened. Has it gotten any harder for you or has it just stayed the same?
Rob ShaplandUm, so when I first tried against companies, generally it's been quite easy. But those that have implemented controls to stop it have made it much more difficult. So this, you know, relatively simple things, like each person has a separate like code word, like you would with your bank, any little secret word that you say when you when you phone up. And some companies have implemented like an NFA type system where a code is generated in the sent 3G mobile when you're speaking to the service desk and you have to read that code back or or vice versa. That makes it a lot more difficult. So then the only way to get around that really is to kind of social engineer your way around it, you know, rather than you've got to make them break the process. The process is solid. And when the process is solid, you've got to convince them to break that process. And if they're well trained enough and they're told never break that process, even if it's a CEO calling, then it's very, very difficult. And that's you know, that's how it should be, really.
Robby PeraltaSo the problem really isn't in the process, it's just the social engineering part that uh that Yeah.
Rob ShaplandI mean it's both. You need the process and you need the people that understand you should never bypass that process to are not susceptible to social engineering. Yeah, you want to almost like if you ever give up a password without following through that process, you'll get in trouble regardless of who it was that called you. You need to follow that process. As long as you've got the process and the training, that's the combination that you need.
Robby PeraltaRight. And I I mean, there should also be technical controls. You shouldn't be able to hop around a network like that either.
Rob ShaplandNo, exactly. So yeah, you shouldn't be able to just yeah, move to every single device, deploy around somewhere, and no one knows what you're doing. Yeah. If you've got a decent SOC or your internal team that's looking at anything strange going on, hopefully they detect that before it before it happens.
Robby PeraltaHow has that experience been for you, the more technical side? Because I I would assume that you, with your experience, you'll get in. But have you ever been stopped by technical controls?
Rob ShaplandYeah, it depends what I've been asked to do when I'm inside the network. So if I'm asked to just log in and grab some data, you can normally get away with that without triggering too much because you're normally coming in as a valid identity, effectively. You know, I've I've compromised an account of a senior person in this business. I'm logging in, I'm logging in from a UK IP address. There's nothing weird about the login itself. Um, and then I'm accessing data that person has access to. As long as I'm not extracting gigabytes out of the network, I'm just sending some random things. And I'll I might send it via a you know a known mechanism that's used by the company, a file sharing service or something that I've seen that they use. Um, in which case that's fine. You don't trigger anything. But it's if I'm you know, if I'm asked to get in and get admin rights and then disable A V and drop a test ransomware file onto the network and stuff like that, that's far more likely to get picked up, especially if they've got an active SOC. Um SOCs are they vary in how good they are, obviously. Depends on on the SOC analysts, uh, what their training is, how good they are at spotting links between things. So often you have what you're doing, you might be doing several things that might trigger low-risk alerts to the SOC. But the SOC analysts, if they can look at those, that chain of low-risk things and go, well, hang on, that's someone doing this, this, this, and this, that's actually really high risk, even though the tools I'm using are telling me it's 10 low risks. When I combine them together, I know from my experience that's someone doing something that shouldn't, it's a lateral movement or whatever. And so if you've got someone good or good team working defending you, then it is very difficult beyond that point if I've got to do something rather than just grab a little bit of data. So I do get caught going around the network by problems.
Robby PeraltaYeah. Yeah, yeah, absolutely. Yeah. How do you, as kind of like closing thoughts, what is the advice you gave to your clients around keeping the attention up and keeping it fun? Maybe I I don't think it was you. I think it was another pen tester or a physical pen tester. He said that he would, you know, once a year come out and say, Hey, there's gonna be some guy or girl trying to break into our building. If you're the one that catches him, you get a week off from the Hawaii fully paid vacation. Do you have any other that maybe that's one thing to do? Like, what do you tell your clients around kicking that attention span up and nice?
Rob ShaplandThat's good. So I want the whole today if I manage to get in and no one catches me. That's the that's the um so yeah. So I I mean, I I've always been a massive advocate that that training is the most important part, but not just e-learning, but actually getting, you know, I love going in a room with people and and teaching them and and playing the videos of breaking into the building and telling stories and anecdotes and things like I've done on this because I think that's much more memorable than than your standard, okay, you've got a module to do for 10 minutes and a quiz, which is what most companies are now saying, you know, I've done my cyber training, everyone's been issued with a with a quiz. You know, there are plenty of good tools out there that do that, but they should be in support of other training mechanisms like face-to-face rather than being the only, the only source of training that you use. Um, so yeah, so I try and make it as engaging as possible. I will always say, yes, we are going to try and break in again. So, you know, look how it won't be me, maybe someone else trying to trying to get in at some point. I've not had a client that's offered a whole day to Hawaii. That's I quite like that idea. But yeah, it's just about keeping that that awareness going. So for some clients now, I'll do like quarterly or monthly little videos or blog articles or whatever, just to try and keep that that awareness going within the business. And I try to, when I first go in and do the the awareness training, no one knows that the job I do exists, right? No one knows social engineering is a thing that you can do as a career. So you have immediately that, oh, that's a cool job, that kind of immediate like kudos associated with it. And then you can sort of establish yourself as this expert in this area, and everyone gets excited about the training next year. And then when you're doing little blog pieces, people more likely to read them than they are random blogs that appear on the internet. So you're you've got that kind of yeah, kudos and slight fame within the business, which is really really handy for getting people to listen to you when you come along next year. So so that's why I try and establish that kind of grabbing their attention and keeping it for a number of years afterwards.
Robby PeraltaYeah. That physical pen testing and the stories that come with it are definitely the things that people remember most about cybersecurity.
Rob ShaplandYeah, yeah, absolutely. Even if it's, you know, it's not the biggest threat. You know, the no company, their biggest threat is physical, right? Physical is a threat, but it's not anywhere near as big a threat as phishing or other other attacks. But it's the one that grabs their attention the most, like you said, and then they listen to you for the rest of it. You know, you've got to cover phishing in a cybersecurity training session, right? You can't ignore that topic and then all the scams that come with it. It's not as interesting as physical pen testing. You can make it quite interesting, but not as interesting. But if you grab them up front with, look, we broke into a building, here's a video, here's me going to your canteen, having lunch in your canteen surrounded by people, and then going and stealing one of your laptops and stuff, then they're like, you've got just putty in your hands for the next 50 minutes, however long you've got them for. So yeah, it works really, really good.
Robby PeraltaI guess the story is to start with that and then say, by the way, you know, I you know, I got in, I plugged in a rubber ducky, I've moved around the network, deployed ransomware. I could have done that. Or I could have just sent you an email and you have to open up this PDF for control C and control V. Yeah.
Rob ShaplandYeah, exactly. Yeah, yeah. This that's literally the segue I use to get into the phishing sections. Like, yeah, yeah.
Robby PeraltaAny other closing thoughts? Anything that you find personally interesting in your world that is kind of new and hip or things that you're gonna be using more time on moving forward?
Rob ShaplandUm, I think I think the the interesting thing that I haven't really got across yet, I suppose, is because we've got a lot of AI tools coming out, so we've got the voice cloning, but we've also got the video versions as well, you know, where you can do a real-time call over Teams or whatever and swap out your face and look like that person and you're looking and sounding like that individual. And I think as someone that doesn't work in this world, if you know, if I'm talking to a normal person at a company who has their own day job and they have no background in this kind of stuff, they don't keep up with how those tools, how how effective those tools are is very, very difficult. So when I'm talking to companies and going like, how do we defend against this in the future? Because social engineering is easy enough already, but if you can look and sound like the person you you're representing, it's obviously going to get even easier. And as the technology advances, it's gonna get better and better and better. So we have to think about with the person I'm talking to, the tread personal training, like what is the underlying goal of that criminal? At the end of the day, they're wanting to get hold of something from you, they're wanting to make you do a money transfer, they're wanting to get hold of your password, they're wanting you to click something, whatever. Those underlying principles haven't changed. There's nothing about those that's different, it's just a lot more convincing layer put on top of it. So I always boil it down to okay, so your CEO's called you, they're asking you to do this. Is this a usual thing for them to do? You know, have they ever done this before? Is there anything about your gut? Is your gut instinct telling you there's something a little bit off about this? Because you speak to people after they've clicked on a on a link or answered a phone call, whatever, and they've done something that's led to a hack. And then afterwards you speak to them and they always say, Oh yeah, that felt a bit off. I knew it, but it's always a butt afterwards, right? There's always a but I was really busy, or you know, it was it was five o'clock and I wanted to go home, or but it was the CFO, and you know, I know he needs stuff done urgently. Uh, and there's always that reason. So it's trying to educate people that the more pressure you feel into doing something, the more you should back off. Trust your gut instinct. And and actually, most people, most senior people in businesses aren't that scary. If you phone them up and say, I was just verifying with you, did you send this email asking me to do his money transfer? They're not gonna shout at you for doing that. They're gonna be pretty happy that you checked. So it's just kind of teaching people that as well. Um so I think that's the thing that that although the technology is getting more and more advanced, it's gonna get more and more difficult to spot whether something is fake or not. Those underlying things they're asking you to do will remain the same. So it's just recognizing those and then doing the right checks afterwards.
Robby PeraltaTrust your gut in 2026.
Rob ShaplandYeah, it's trust your gut.
Robby PeraltaWell, Mr. Shapland looking forward to seeing you here in May. Thank you for your time today and uh good luck with all your engineering here in the meantime.
Rob ShaplandLooking forward to it. Thanks, Robby. See you see. Thanks, Rob. Cheers.
Robby PeraltaWell, that's all for today, folks. Thank you for tuning in to the mnemonic security podcast. If you have any concepts or ideas that you'd like us to discuss on future episodes, please feel free to hit me up on LinkedIn or to send us a mail to podcast at mnemonic.no. Thank you for listening, and we'll see you next time.