No-One Is Immune From Phishing

According to a new analysis from F-Secure, even the most technically skilled employees are just as likely (if not more likely) to fail a phishing test.

 

Phishing

Phishing attacks typically involve sending emails that appear to come from a legitimate company/organization to gain an individual’s confidence. This is to target the recipient to follow a link in the email. However, clicking on a link in a phishing email means having malicious software loaded onto the recipient’s device. This can allow cybercriminals to take control of a computer, log keystrokes, gain access to your personal information and financial data. Crimes include theft, identity theft, or being directed to a phishing page/payment page where sensitive information and money is taken. Compromising one person’s computer and accounts can also provide a way into broader company systems. It should also be noted that phishing links can be inserted into malicious advertisements and even direct messages on chat apps.

The Study

A recent test by F-Secure highlighted a comparison of how people working in IT or Development Operations responded to phishing emails. The study found phishing emails mimicking HR announcements or asking for help with invoicing achieved the most clicks from recipients. Furthermore, people working in ‘technical’ roles seem equally susceptible to phishing attempts (or even more so) than the general population.

 

Why?

“The privileged access that technical staff have to an organization’s infrastructure can lead to their being actively targeted by adversaries,” Matthew Connor, F-Service Secure’s Delivery Manager, explained.

As a result, those in ‘technical’ jobs appeared to be equally or more vulnerable to phishing attacks.

 

Clicked Despite Higher Level Of Awareness

One concern raised by the study is IT personnel being more aware of previous phishing attempts and knowing more about the threat. However, evidence by post-study surveys shows they still clicked as often (or more often) on the phishing links.

 

Speed Of Reporting and Ease Of Reporting Crucial For Security

The study also found that both the IT and DevOps groups were no better at reporting phishing attempts than others. Out of 17 departments, IT came 15th in writing phishing emails. Also, the study highlighted how reporting phishing emails became more common as time went on. Different processes at different organizations played a role in the level of reporting. Forty-seven per cent who had a dedicated button to flag suspicious emails used it to instantly register phishing emails during the study compared to much lower reporting levels where there was no button.

 

Reporting phishing emails could help businesses to tighten security and raise awareness. The study highlights how important having a simple, fast, easy-to-use reporting process (a button) in place is.

 

How To Spot Phishing Emails

Many phishing emails have giveaways that you can spot if you know what you’re looking for. Examples of ways in which you can identify a phishing email include:

  • Online requests for personal and financial information, e.g., from government agencies, are unlikely to be sent via email from legitimate sources.
  • Generic greetings. Scammers are less likely to use your name to personalize the email greeting and title.
  • Mistakes in spelling and grammar can be signs of scam emails.
  • Checking the email address by hovering your mouse (without clicking!) over the link in the email. This can quickly reveal if the email is genuine.
  • Beware of heavy emotional appeals that urge you to act immediately. These are signs of scam emails that hope to bypass your critical thinking and tap into an emotional response.
What Does This Mean For Your Business?

As the study’s report pointed out, advanced or even average susceptibility to phishing is a concern. IT staff who should have a higher awareness of phishing click more often than other staff on phishing links worry. However, as highlighted by F-Secure, one explanation may be that IT staff with privileged access to systems may be targeted more. One valuable insight uncovered by the study is that providing a fast, easy reporting process for phishing emails can provide a way for security personnel and other teams to work together. They are improving an organization’s resilience against phishing. This could mean earlier detection in future, thereby really helping strengthen company security in the future. Cyber security training and awareness efforts are also crucial in keeping all staff up to date with the nature of threats, more importantly, how to respond to them to protect the organization and enable vital feedback.

Fully managed IT

IT Security

Networking

Disaster Recovery

Telephony