Social Engineering Risk and Its Effect on Nigeria’s Electronic Banking Security

Isah Rambo Saidu, MN Musa, AS Abdulkadir

Abstract


Social engineering refers to techniques that exploit human weaknesses and manipulate people into breaking normal security procedures. Therefore organizations are still at risk because the people entrusted to safeguard their information are highly vulnerable to social engineering attacks. In this regard the study offered guidelines on how stakeholders can manage the social engineering threat within the electronic banking risk appetite. The general objective of the study focused on social engineering as a security threat in electronic banking and how human behaviour contributes to its success. The specific objectives explored social engineering techniques, highlighted motives and factors that influence the success of social engineering attacks, determined risk areas that needed to be improved and modelled a risk of probability of compromise/breach involving stakeholders and finally recommended guidelines on how the threat level of social engineering may be reduced in electronic banking. This study adopted a hybrid of quantitative and qualitative methodologies and targeted the UBA branches in Kaduna. The study being descriptive made use of questionnaires. The collected data was coded and entered into the Statistical Package for Social Sciences (SPSS) for analysis. The qualitative method made use of interview coded using thematic content analysis. The output presented by these techniques indicate that social engineering being a ‘non-technical’ way of infiltration should be taken seriously as any other technical threat. It is therefore important for continuous research to be carried out in this field as the field of social engineering is dynamically changing with the advancement of technology. Further recommendations on how the social engineering threat level could be reduced were also provided.

Full Text:

PDF

References


Bailey, K. D. (1987). Methods of Social Research. 3 ed. Michigan: Free Press. Breda, F., Barbosa, H., & Morais, T. (2017, March). Social engineering and cyber security. In International Technology, Education and Development Conference, 3(3), 106-108. Huber, M., Kowalski, S., Nohlberg, M., & Tjoa, S. (2009, August). Towards automating social engineering using social networking sites. In 2009 International Conference on Computational Science and Engineering, 2(3), 117-124. IEEE.

Kenney, M. (2015). Cyber-terrorism in a post-stuxnet world. Orbis, 59(1), 111-128. Kigen, P. M., Kisutsa, C., Muchai, C., Kimani, K., Shiyayo, B., & Mwangi, M. (2014). Kenya Cyber Security Report 2014. Tespok. Mitnick, K. D., & Simon, W. L. (2009). The art of intrusion: the real stories behind the exploits of hackers, intruders and deceivers. John Wiley & Sons.

Mugenda, O. M. & Mugenda, A. G. (2003). Research Methods Quantitative and qualitative approaches. Nairobi: Acts Press. Nebeker, C. (2016). Basic research concepts. San Diego State University Research Foundation. Retrieved: September, 1.

Peltier, T. R. (2006). Social engineering: Concepts and solutions. Information Security Journal, 15(5), 13. Simon, W. L., Wozniak, S., & Mitnick, K. D. (2002). The Art of Deception: Controlling the Human Element of Security, 304.

Vidalis, S., & Kazmi, Z. (2007). Security through deception. Information Systems Security, 16(1), 34–41.

Wang, Z., Zhu, H., & Sun, L. (2021). Social engineering in cybersecurity: Effect mechanisms, human vulnerabilities and attack methods. IEEE Access, 9, 11895-11910.

Weider, D. Y., Nargundkar, S., & Tiruthani, N. (2008). A phishing vulnerability analysis of web based systems. 2008 IEEE Symposium on Computers and Communications, 326.


Refbacks

  • There are currently no refbacks.