None of Google's 85,000 employees have been successfully phished in over a year — and it's because of a simple $20 product anyone can use
- Google told Business Insider that none of its employees had been successfully phished since it started requiring them to use security keys to log in.
- Phishing, or using misleading emails to steal passwords, is one of the most common ways people get hacked.
- Google attributes its success to products called security keys, or USB devices that you need in addition to a password to log in to a protected account.
One of the most common ways that people get hacked is called phishing or spearphishing.
Basically, attackers craft an email that looks just like something you'd normally click on, like a bill or an email telling you to change your password. Unsuspecting people click on the link in the phishing email, leading them to a site designed to look legitimate. The victim plugs in their username and password, unwittingly giving it to the attacker. Now there's a good chance that account will be hacked.
Spearphishing was one of the main ways Russian spies were able to break into the Democratic National Committee's network before the 2016 US election, the Justice Department says.
It's a big problem for businesses. You can make sure your computers are as secure as possible, but all it takes is one employee with access to sensitive data who gets fooled by an email to cause a bad breach.
One company, however, seems to have solved the phishing problem: Google. And it's all because of a $20 gadget called a security key, which Google requires its employees to use.
None of Google's 85,000 employees have been successfully phished on their work accounts since it started requiring security keys to log in, the company said.
"We have had no reported or confirmed account takeovers since implementing security keys at Google," Google told Business Insider.
Google started requiring employees to use physical security keys in early 2017, according to Brian Krebs, the security journalist who first reported Google's success against phishing attempts.
Your company may already require you to have two-factor authentication turned on, meaning that when you log in with a username and password, you have to enter a second code, usually texted to you or delivered through an app.
Google took this one step further and required all employees to start using security keys, according to Krebs. Instead of getting a text after entering your password, you merely plug the security key into a USB port on your computer and press a button.
That's a pretty big success for such a large company. Google has a lot of sensitive user data, so it's very encouraging to know its employees aren't getting phished.
You can use a security key with your own Gmail account. YubiKey models compatible with USB, USB-C, and mobile devices are available from Yubico.
In October, Google launched an advanced-protection program involving security keys for people at the highest risk of being phished, including journalists, business leaders, and activists. Google has also worked with various industry groups, such as the FIDO Alliance, to develop security-key technology called U2F.
A 2016 Google study found that text-message or app-based two-factor authentication, sometimes called "one-time password," had an average failure rate of 3%, while the U2F or security-key approach had a 0% failure rate.
There are more details about how Google's approach to authentication and login security is starting to pay off at Krebs on Security.
Source: uk.businessinsider
Latest Jobs
-
- Business Development | Healthcare | Warm accounts | UK
- England
- N/A
-
Business Development | Healthcare | Warm accounts | UK Healthcare Cyber Security UK Based An experienced Business Development Manager is required to drive new cyber security revenue across a warm healthcare account base. This role is focused on new business and account growth, engaging healthcare organisations to understand risk, priorities, and operational challenges, and positioning appropriate cyber security solutions and services. Key Responsibilities Drive new business sales into a warm healthcare account base Develop and close new opportunities across healthcare organisations Build senior level relationships with IT, security, and procurement stakeholders Own the full sales lifecycle from first conversation through to close Work closely with technical pre sales and delivery teams Experience Required Proven B2B new business sales experience within cyber security or technology Healthcare sector experience desirable Strong consultative sales and closing capability Ability to achieve UK Security Clearance is required UK based with flexibility to travel What’s on Offer Warm accounts with new business focus Clear revenue ownership Competitive base salary with uncapped commission
-
- Technical Pre Sales Cybersecurity Consultant. Healthcare
- England
- N/A
-
Technical Pre Sales Cybersecurity Consultant UK Remote | Healthcare Focus Overview We are seeking an experienced Technical Pre Sales Cybersecurity Consultant to support healthcare organisations by delivering advisory, solution design, and security uplift services. This role focuses on improving security outcomes, addressing operational challenges, and enabling informed technology decisions across complex and regulated environments. The position blends technical pre sales expertise with a consultative approach, working closely with clinical, technical, and commercial stakeholders to shape effective cybersecurity solutions. The individual must be able to achieve UK Security Clearance. Key Responsibilities Provide technical pre sales support across cybersecurity solutions and services for healthcare organisations Engage stakeholders to understand security challenges, risks, and operational pain points Deliver advisory guidance and recommendations to strengthen security posture and resilience Translate customer requirements into clear, outcome focused technical and commercial solution designs Act as a trusted technical advisor throughout the sales and early delivery lifecycle Produce clear technical documentation, recommendations, and customer facing materials suitable for regulated environments Collaborate closely with sales, delivery, and technical teams to align solutions with customer needs Experience and Skills Proven experience in technical pre sales or cybersecurity consultancy Experience working within healthcare or other highly regulated sectors Broad knowledge of cybersecurity technologies, managed services, and risk based approaches Strong communication skills with the ability to engage both technical and non technical stakeholders Confident operating in a client facing, consultative role UK based role with remote working Occasional travel for customer engagement as required
-
- Contract Technical Pre Sales Cyber Security Healthcare. SC clearance needed
- England
- Outside IR35
-
Contract Technical Pre Sales Cyber Security Healthcare Outside IR35 Contract | UK Remote | Healthcare Focus Existing SC clearance is required. Overview Seeking an experienced Technical Pre Sales Cybersecurity Consultant is required to deliver advisory and uplift services across complex healthcare organisations. This Outside IR35 contract operates on a consultancy basis, focused on improving security outcomes, addressing operational pain points, and supporting informed Cyber Security decisions. The role combines deep technical pre sales capability with consultative advisory delivery, working across clinical, technical, and commercial stakeholders to shape effective and proportionate cybersecurity solutions. Responsibilities Provide technical pre sales consultancy across cybersecurity solutions and services within healthcare environments Engage senior stakeholders to understand security challenges, risks, and operational pain points Deliver advisory guidance and uplift recommendations to improve security posture, resilience, and maturity Translate healthcare requirements into clear, outcome focused technical and commercial propositions Act as a trusted technical advisor throughout the pre sales and early engagement lifecycle Produce concise technical documentation, recommendations, and advisory outputs suitable for regulated healthcare settings Experience Strong background in technical pre sales or cybersecurity consultancy Experience working with healthcare or other highly regulated environments Broad understanding of cybersecurity technologies, managed services, and risk based security approaches Ability to communicate complex technical concepts to both technical and non technical audiences Comfortable operating independently in a client facing advisory role
-
- London Sales Manager, Key Clients. Security. Immediate
- London
- N/A
-
London Sales Manager, Key Clients A senior sales leadership role within the cyber security services and technology market, focused on account development and revenue growth across key clients. You will lead a sales team with responsibility for customer retention, increasing share of wallet and maintaining a strong commercial pipeline. The role works closely with technical, delivery and marketing teams, as well as technology partners. Key focus Lead and coach a field based sales team Own forecasting, pipeline quality and revenue delivery Drive renewals and account development Expand customer investment across services and solutions Build relationships with vendors and partners Background Proven experience managing enterprise sales teams Consistent performance against revenue targets Cyber or IT security sales leadership experience Exposure to Palo Alto, Check Point, Microsoft, etc Commercially focused with a structured sales approach A role for a sales leader focused on long term client value and sustainable growth.