THE LUXEMBOURG JOB
**The Situation**
The organization was seeking to evaluate both physical security measures and local procedures at its remote offices in Europe. This included examining site security, identifying physical vulnerabilities, assessing untested environments, and pinpointing security blind spots.
**The Task**
A cybersecurity expert (let's refer to him as Doug) was sent to the client's office in Luxembourg to conduct an assessment of physical security and social engineering tactics. Rather than using the slow entrance from an underground parking garage, Doug easily accessed the reception area by following a delivery driver inside. He chose a quiet, empty room to set up his laptop, which was equipped with a 'dropbox' designed to infiltrate the company’s domain in order to secure administrative privileges. As he executed his scripts, Doug remained undisturbed at his station for nearly three hours. However, things did not unfold entirely as expected. Doug opted to roam the office and ensured his phone was prepared for remote updates. After enjoying some coffee and chatting with employees, the Managing Director (MD) arrived. Noticing there was no record of Doug signing in at reception, the MD grew suspicious. Although Doug managed to withstand some intense questioning in a locked room, he realized the situation had become serious when he spotted two police officers entering the building. To diffuse the escalating tension, he presented his authorization letter, signed by the company’s Chief Technology Officer, which confirmed his presence. This served as his "get out of jail free" card. The MD felt satisfied to have caught Doug before he could cause any harm, only to be taken aback when Doug revealed his phone, still linked to the dropbox, which displayed the message ‘Domain Admin Obtained.’