Cybersecurity

Phish Happens: Preparing your Business and Employees for Phishing Scams

January 25, 2023
Rueben Medina

Phishing is the number one attack vector for malware, ransomware, and data exfiltration.

The Cisco Cybersecurity Threat Trends Report estimated that phishing accounted for 90% of all attacks in 2021. Targeted phishing attacks (known as spear phishing) and attacks via text message (smishing) increase effectiveness by using social engineering to prey on victims' concerns and fears. Despite how effective phishing is, the cybersecurity community often treats it as a shameful trick that only the non-technical and uninformed fall for.

Falling for phishing doesn't make you stupid.

Everyone is susceptible to phishing. A judgmental view of those who fall for phishing scams does nothing to improve security posture — in fact, it makes you less secure. If being phished is treated as an embarrassing event, employees will be hesitant to ask for help when they receive suspicious messages.

So, how do we create a culture that can fight against phishing scams?

Encourage an environment where people aren't afraid to ask questions. Let coworkers know that security professionals are there as a resource to help navigate suspicious emails and messages. There are no stupid questions.

Reconsider that internal phishing campaign. Recent studies show that ethical phishing campaigns may not be as effective as previously thought and may also make employees more susceptible to phishing. If you do run an internal phishing campaign, make sure it is paired with positive and open communication about cyber threats. Educating your employees is more effective than tricking them.

Build a culture of security. Don't just educate employees about best security practices — give them a sense of ownership over security. Instead of telling employees what they must do to follow security policies, help them understand why they should follow security policies. Share security articles and discuss the latest security breaches in the news with your team.

No matter how many tools or technical steps you take to prevent phishing attacks, people are always at risk of falling for simple social engineering. If you're not creating an open, communicative, and non-judgmental environment, you are increasing your security risks. When you create a culture where security is everyone's job and employees take ownership of it, you decrease indifference and reduce morale hazard. Above all, when you stop approaching security from a punitive viewpoint, you create not only more secure employees, but a more secure company.

No matter how cautious you are or how strong your security posture is, you may still get hit by a phishing attack. When that happens, Elpha Secure's unique combination of cyber insurance and endpoint software has you covered.

> Back Button An arrow to close the mobile menu