Did you know that 74% of security breaches involve human factors, not technological issues? Did you imagine that people are the primary attack vector for cybercriminals? Why is this?
In this talk, we'll delve into "Social Engineering," which has become the main weapon of attack for cybercriminals. First, I'll analyze the current context regarding people's intensive use of the internet and smart devices, and how this new environment has created a favorable scenario for Social Engineering. We'll review what social engineering is, the most common cases, the phases of the attack cycle, and focus on the main techniques (Quid Pro Quo, Baiting, Pretexting, Diversion Theft, Tailgaiting, Phishing, and Vishing), explaining each one with videos. All of this will be combined with real-world case examples, proofs of concept, and personal anecdotes, concluding with recommendations to avoid falling for these scams.
About Gabriel Bergel: Master's degree in Cybersecurity from IMF Business School and Camilo José Cela University (Spain). 22 years of experience in various cybersecurity roles. He is a regular speaker at cybersecurity courses, talks, workshops, and forums at various national and international institutions, universities, and events. His presentations at PHDays7 in Moscow, Campus Party and Roadsec in São Paulo, the Biohacking Village at Defcon26 in Las Vegas, and the (ISC)² Secure Summit LATAM 2019 in Mexico City are particularly noteworthy. During 2020 and 2021, he delivered over 100 virtual talks both nationally and internationally. He is currently CEO of Vulnscope (the first bug bounty platform in Spanish, developed in Chile) and CEO and Co-founder of the 8.8 Computer Security Conference, Coordinator of the Industrial Cybersecurity Center (CCI), Co-Chairperson of the Latin American Advisory Council (LAAC) at (ISC)2, Director of Public Policy at Whilolab, and Director at Fundación Nativos Digitales.
→ Certified CISSP by (ISC)2 since 2006.
→ Certified Lead Auditor ISO 27001 by BSI since 2007.
→ Certified CBCP by DRI since 2009.
→ Certified C|CISO by EC-Council since February 2013.