Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
Cybersecurity News

Where Cyber Meets Skinware: An Enterprise Security Problem

By Mark McCourt
October 1, 2014

As your enterprise virtualizes and leverages cyber technology to speed productivity, the incidence of cybercrime will, of course, increase. Similarly, as your employees’ behavior, as consumers, drives the technology they use (BYOD), the cybercrime cat will continue to be let out of the bag. What can any enterprise, security leader or technology truly do to eliminate or prevent cyber terror, espionage, theft, network intrusions and major fraud when the humans involved are making it so easy?

In the connected world, there are only three components that can cause failure: hardware, software, and skinware. For example, with hardware, your hard drive can crash. Or with software, an operating system may have a continuous loop in which you start your computer and an error message indicates it has encountered a problem and has to restart and that repeats until you cry. Or a skinware issue, which is, well.... you. You don’t know what you are doing, and you are the problem.

While the Home Depot, Target and (oh, just fill in your favorite retailer here) hacks are real network breached cybercrimes, there are too many schemes – scams and human error – due to poor or no training that are leading to real crimes. That’s right – skinware!

A perfect example is the African Cyber Crime School Impersonation Scheme. No, really. I didn’t make this up. It’s on the FBI’s cybercrime alert site if you want to check it out. So how do you successfully impersonate an entire school? I couldn’t even get away with forging a lousy hall pass!

If you have not read about the African School Impersonation Scheme or are not familiar with the FBI’s Internet Cyber Crime Complaint Center (IC3), it all sounds so technical and scary. Somehow, it would appear, Africans will steal our schools blind through the Internet while we sit in the cafeteria, helplessly trying to guess what we are eating.

But that is not it at all. Whether or not Cyber is in your job description, I assure you that stopping this scheme is right in every security leader’s sweet spot.

First, no encrypted passwords are broken or firewalls hacked. Your CIO, CISO or network security administrators have nothing to breach, protect or stop in this matter. No computer needs to be turned on or connected to the Internet. So, it is not about the Internet or cyber. The only technology the criminals use is the “good ole telephone.” Imagine that.

Second, it is not about schools, although they were initially used as the golden ticket to steal millions in products. This scheme is very successful and, as a result, it has quickly spread to businesses and other institutions. The FBI shares that the scheme is resulting in $200,000 per incident thefts. (Laptops, medical supplies, industrial equipment, etc., are all at play).

This scheme is all about you and physical security insider threats. But no, that nice customer service representative is not a nefarious criminal mind; just a poorly trained employee without policies in place to prevent them from being human engineered. Indeed, they are so helpful that they are helping a criminal perpetrate a crime.

 Here are the 1-2-3’s of the School Impersonation Scheme. The criminal contacts a business’s customer service center, poses as a school official and, using human engineering techniques, gathers additional information about the purchasing account. Most customer service training ends the call by asking, “I have answered all your questions and is there anything else I can help you with today?” And in this case the agent most certainly has.

Next, the criminal calls the targeted vendor again with account information in hand and places an order billing to the school’s line of credit. This is bold; they give the actual school address for the shipment and then call the school pretending to be the business they just ripped off. Stating they shipped an order in error, they ask them to return it. They then ship labels to the school, and the school unwittingly forwards the shipment to the criminal’s address.

As noted, it started with schools, but has spread quickly to other sectors. And why not? Without policies, training and a way for employees to “see something, say something,” your company doesn’t stand a chance. And having a CIO buy more hardware and software with more passwords is not the answer in this and in many other criminal cases.

Cyber or not, naming it is less important than stopping it. This is where physical security’s expertise, leadership and experience are perfectly suited to identify and mitigate known risks. Otherwise, your customer service representatives will not even recognize a well-crafted fake hall pass.   

KEYWORDS: cyber espionage cyber security data breach insider threats skinware

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Mark McCourt was once the publisher of Security magazine.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

The Lourve

The Lourve Heist: What Was the State of the Museum’s Security?

The 2025 Security Benchmark Report

The 2025 Security Benchmark Report

Office supplies

Security Leaders Share Why 77% Organizations Lose Data Due to Insider Risks

American Airlines

Security Leaders Discuss Cyberattack on American Airlines Subsidiary

Going Down with the Ship

Going Down with the Ship

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

November 13, 2025

Inside the 2025 Security Benchmark Report

The 2025 Security Benchmark Report unveils the top trends CSOs and enterprise security executives are facing in today’s current climate and how each of these trends could potentially impact the enterprise’s global reputation with the public, governments, and business partners. 

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • two-way-radios-1170.jpg

    Evolution of two-way radios meets changing enterprise security needs

    See More
  • Studying the 'Wicked Problem' of Cyber Security

    See More
  • cyber security freepik

    The big problem with bad cyber analogies

    See More

Related Products

See More Products
  • physical security.webp

    Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

  • 9780367339456.jpg.jpg.jpg

    Cyber Strategy: Risk-Driven Security and Resiliency

  • 150952519X.jpg

    Intelligence in An Insecure World, 3rd Edition

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing