As part of the final project for the Cyber Security Seminars, students Martin Oliver Gába and Tadeáš Ježek conducted cybersecurity testing at two educational institutions. The goal of the CSS project, supported by Google.org, is to convey practical knowledge in the field of digital security in an accessible way. Through a series of simulated attacks, a final reflection session, and a follow-up lecture, they provided insight into which attacker methods were effective and how staff members reacted in the moment.
Why did you choose the form of direct intervention?
The traditional approach of theoretical lectures, full of difficult-to-understand terminology, seemed to us to be insufficiently connected to the real-world practice that staff encounter daily. We were concerned that such an approach would not ensure the desired retention of security principles and measures. The motivation for improving cybersecurity was the nature of the work at both institutions, which handle sensitive data on children and parents daily, with one having 15 staff members and the other 50. The average age at both is around 45.
What three types of simulated attacks did you choose, and how did the implementation go?
The first wave of simulated attacks involved placing USB sticks on the premises of the institutions. We deliberately positioned them to give the impression that one of the students had lost them. We tested whether these devices would be reported to management, ignored, or, in the worst case, plugged into a device, where we monitored the opening of a “virus” file.
In the second wave, we sent out a phishing email via the headteacher’s email address. It contained deliberate grammatical errors and non-standard formatting designed to trick the reader into entering sensitive data. In both waves, we monitored the conversion rate, that is how many staff members actually clicked on the link and thereby compromised the institution’s security.
The third wave focused on social engineering techniques. One team member posed as a computer science student on work placement who, under the pretext of reporting to head office, requested access to the server room. For this test, we worked exclusively with publicly available information to which a real attacker would also have access. The aim was to verify whether employees would check the validity of the new “IT technician”, for example by phoning management or asking additional verification questions.
How did employees react when the attack was underway?
In the case of phishing and planted USB drives, most employees showed a healthy dose of scepticism. Both types of “attacks” were reported relatively quickly to management and other colleagues. Nevertheless, we recorded several clicks on risky links in the first few minutes after the intervention began, i.e. before the warning had had time to spread across all departments.
In the case of social engineering, on the other hand, we encountered a high degree of trust and a willingness to help. In one of the institutions, doubts about our identity arose shortly after we left, suggesting that despite their initial trust, employees would have been able to react in time and eliminate the threat in the event of a real problem.
In what way did the approach of the two institutions differ most?
The quantitative results were comparable in both institutions, but a fundamental difference emerged in the speed of internal communication. In the smaller institution, a single message in the communication app was enough for all staff to be immediately in the loop. It was precisely this efficiency that enabled them to quickly detect our planted USB drives and eliminate the risk. In the larger organisation, information spread noticeably more slowly. Representatives from both institutions take cybersecurity seriously and appreciated our tests as a useful basis for identifying and subsequently rectifying weaknesses in their security.
Which of the three attacks had the highest ‘success rate’?
Social engineering proved to be the most effective method. In both cases, we gained access to sensitive infrastructure without difficulty, the compromise of which would have posed a serious threat in the event of a real attack. In one of the institutions, no one noticed anything until our final presentation, when we ourselves drew attention to the simulation that had taken place.
Did the participants react with defensiveness and irritation after the revelation, or did curiosity and a desire to learn prevail?
In both cases, we encountered a great deal of interest in how to defend against cyber threats. In the smaller team, the discussion was very open and informal. Staff actively asked questions and shared their feelings about the tests. At the second organisation, the atmosphere was somewhat more serious. Some staff members took their “mistakes” in the tests as a personal failure. Despite these initial reservations, however, the desire to learn and do their utmost to avoid being tricked in the future prevailed.
What did you focus on most in the subsequent presentation?
Our presentation of the results wasn’t just about numbers. We analysed the individual simulated attacks in detail and showed employees specific warning signs to look out for in the future. When communicating the results, we placed great emphasis on respect. Our aim was not to embarrass anyone, but to constructively highlight weaknesses in the system and equip colleagues with the skills to help them recognise threats in good time.
The main lesson from the whole exercise is that constant vigilance is key. A moment’s inattention or fatigue, for example on a Friday afternoon, is enough for an employee to unintentionally open a phishing email, which could cause weeks of complications for the entire organisation. The same caution applies in the physical world. Verifying the identity of any unknown person moving around the institution’s premises should be a matter of course.
This project was a brilliant combination of theory and practice and an opportunity to test our skills in the field. We would like to thank the faculty for the opportunity to take part in this unique experience.