Skip to Content

CSEPS

CSEPS (the Certified Social Engineering Prevention Specialist program) is a corporate security-awareness training and certification course developed in 2003 by Kevin Mitnick and Alex Kasper through their consultancy, Defensive Thinking.1 It is their belief it is the first professional certification built specifically around defending against social engineering, rather than technical intrusion.2

Course Structure

CSEPS was delivered as a two-day, in-person “boot camp” costing roughly $1,500 per attendee, combining lecture, case studies, live attack demonstrations, and pretexting exercises. Clients included corporations, government agencies, and military organizations, among them the U.S. Air Force and Marine Corps. The certification exam itself combined multiple-choice and written-response questions on social-engineering defense and mitigation.2

The curriculum was organized into a series of print training-workbook modules. The first covered the fundamentals of social engineering: what it is, why it works, who social engineers target, and the research/develop-trust/exploit-trust attack cycle.3 The second turned to planning an attack: intelligence gathering, researching a company and its personnel, dumpster diving, and elicitation techniques for drawing out information indirectly.4 The third covered pretexting and execution: building a false identity, establishing rapport and credibility, and the psychological principles of influence, persuasion, and compliance that make those pretexts work.5 Later modules addressed building resistance to manipulation and turning an organization’s employees into what the course called a “human firewall.”

History

Mitnick and Kasper partnered with Intense School Inc., a Florida-based IT training company, in 2003 to deliver CSEPS classes in the United States 2 and later worldwide. Coverage of the program and its instructors followed over the next two years, including a 2005 Wired profile of Kasper and Mitnick’s shared history6 and a 2005 ZDNet report on a CSEPS-style workshop in Sydney describing the goal of building a “human firewall” against social engineers.7

In 2012, Mitnick partnered with the security-awareness training company KnowBe4 as its Chief Hacking Officer,8 a role he held for the rest of his career. By the time of a 2020 Fast Company profile, hiring a reformed hacker to test and train employees against social engineering, the approach CSEPS had pioneered nearly two decades earlier, had become mainstream corporate practice.9

References


  1. ^Press Information”. Defensive Thinking, Inc. January 1, 2004.
  2. a b cEx-Hacker Kevin Mitnick Teaches From Experience”. The Wall Street Journal. October 15, 2003.
  3. ^ CSEPS Training Workbook – Module 1: Understanding Social Engineering. Defensive Thinking, LLC. 2003.
  4. ^ CSEPS Training Workbook – Module 2: Planning the Attack. Defensive Thinking, LLC. 2003.
  5. ^ CSEPS Training Workbook – Module 3: Pretexting and Execution. Defensive Thinking, LLC. 2003.
  6. ^ Gray, Patrick (June 6, 2005). “A Tale of Two Hackers”. Wired.
  7. ^ Kotadia, Munir (April 13, 2005). “'Human firewall' a crucial defence: Mitnick”. ZDNet.
  8. ^Kevin Mitnick Partners With KnowBe4”. PR Newswire. June 12, 2012.
  9. ^ Sjouwerman, Stu (July 16, 2020). “I hired an infamous hacker—and it was the best decision I ever made”. Fast Company.
Join the Mailing List

Related Projects