Only 7% of UK Firms Regularly Train Employees to Spot Phishing Emails
As many as 54 percent of organisations in the UK have reported an increase in email-based phishing attacks launched by cyber-criminals, with such attacks being launched across the entire organisational hierarchy from the C-suite, the finance department, HR staff members, to even trusted third-party vendors.
Email has, over the years, become an important vector for cyber-criminals, allowing them to carry out a number of malicious activities from distributing computer viruses, targeting organisations with malware and ransomware, and carrying out phishing attacks either to obtain credentials or to lure employees into transferring money or divulging enterprise secrets.
The use of email by cyber-criminals has, in fact, become so rampant and audacious that in the past twelve months, 92 percent of ransomware attacks globally were delivered by email, resulting in long email downtime in affected organisations across the world.
According to security firm Mimecast who carried out a survey of 800 global IT decision-makers to gauge the effectiveness of email-based attacks, the success of such attacks is largely due to the fact that less than one in ten organisations in the UK and beyond continuously train employees on how to spot cyber-attacks.
"Email-based attacks are constantly evolving and this research demonstrates the need for organisations to adopt a cyber-resilience strategy that goes beyond a defence-only approach. This is more than just an ‘IT problem,’ said Peter Bauer, chief executive officer of Mimecast.
"It requires an organisation-wide effort that brings together many stakeholders, puts the right security solutions in place and empowers employees – from the C-suite to the reception desk -- to be the last line of defence," he added.
Nearly 40 percent of IT decision-makers interviewed by Mimecast told the firm that their CEO undervalued the role of email security as a key element of their security programme, despite the fact that cyber-criminals have made effective use of emails to lure employees into divulging sensitive data.
C-Suite staff are also believed to be among the most vulnerable to email-based attacks. According to the IT decision-makers, 31 percent of C-level employees are likely to have accidentally sent sensitive data to the wrong person in the last year compared to just 22 percent of general employees.
This could be a direct result of the lack of training imparted to employees on how to spot cyber-attacks. In the UK alone, only 7 percent of organisations continuously train employees, with 61 percent performing training just once a year. Globally, 11 percent of organisations continuously train employees on how to spot cyber-attacks, 24 percent offer monthly training, and 52 percent perform training only quarterly or once a year.
According to Mimecast, the lack of continuous training is because 33 percent of decision-makers want to focus on increased investment in technology and 29 percent want to see improved business processes. Instead, enterprises must ensure that upper management staff are trained first to set the tone of a company's security culture, that cyber-security is placed into the function that manages overall risk mitigation for the organisation, and that security controls and risk management programmes are benchmarked against peer organisations on a regular basis.
The effectiveness of email-based attacks is also boosted by the fact that in 61 percent of organisations worldwide, infected users spread infections to devices used by other employees via infected email attachments or malicious URLs. Therefore, imparting continuous cyber-security training to employees will go a long way in ensuring that infections are limited to affected systems and not allowed to spread across all devices.
While email is one of the most preferred vectors for hackers to target organisations with ransomware, it is also used frequently to launch phishing attacks either to obtain credentials or to lure employees into transferring money or divulging enterprise secrets.
In the past twelve months, 40 percent of organisations worldwide have seen an increase in the volume of impersonation fraud requesting a wire transaction, while 39 percent have seen the volume of requests for confidential data increase. This, coupled with human error, ensures that organisations' secrets are easily obtained by third parties without having to steal such details physically.
For example, 31 percent of IT decision-makers said their C-Suite staff sent sensitive data via email to third parties by accident, 22 percent said such mistakes were committed by low-level employees, 20 percent said sensitive data was shared via email in response to a phishing email by employees, and a similar number said C-Suite staff also fell for phishing emails and shared sensitive data with criminals.
In order to achieve such a high rate of success, cyber criminals often impersonate trusted third-party vendors, company employees, as well as CEOs. Such impersonation has resulted in 32 percent of organisations suffering data loss, 25 percent experiencing reputational damage, and 20 percent suffering direct financial loss.
"We all know that minimising cyber-risk is about much more than just having the right technology in place. It’s also about services, people and processes. With cyber-attacks increasing, all organisations need to do more to put all employees in the best possible position to help reduce cyber risk," said Kirill Kasavchenko, principle security technologist, NETSCOUT Arbor, to SC Magazine UK.
"There are instances where deploying more technology isn’t the answer. Sometimes you need to start with your workforce and help them play a more active role in spotting and addressing cyber-threats. This research really hammers home the reality that many employees remain unprepared. Dealing with cyber-threats is a continuous process, so performing cyber security training just once a year simply isn’t enough to adequately reduce business risk.
"Improving training is essential, and getting this right can help nurture a good cyber-security culture across the whole organisation. One of the key elements of that is being attentive to the technologies that we use every day. For example, email is something we access throughout the day – sending hundreds of emails across the week – so it can be easy to become complacent to the security risks at hand. Shifting to a more cautious mindset can help employees act as an extra barrier to stop hackers in their tracks," he added.
- Director of Sales Engineering
- Up to €110,000 plus bonus and benefits
Location: Paris Salary Upto €110,000 plus bonus and benefits Reference: RA 7382 Director of Sales Engineering This rapidly expanding Cloud Service company are looking for an experience Director of Sale Engineering (Pre sales), to help them expand both their customer base and also their sales engineering team, You will be responsible for managing a team spread across Europe, (France, Germany and UK currently 6) Your responsibilities will include : Organising and monitoring your pre-sales team activity in coordination with your management. Building and managing a pan European team. Making sure your team members are on track with company or individual KPIs. Managing your own set of customer/proposal Coordinating closely with Sales – you will work alongside Account Managers, serving as a technical lead for more standard solutions development. Assigning required resources to the Complex Solution team when required by your management. Working closely with the engineering and product teams to provide customer and market feedback Participating in the planning and execution of various partners facing activities. The role may include actively driving presentations creation or delivery, and general networking activities. As well as previous experience in leading a sales engineering/ presales team you will require both Telecommunications (MPLS, Ethernet,) and Cloud platforms (Azure, Aws, Oracle etc) knowledge.
- Product Manager - Access Controls
- £50,000 - £90,000
An Identity and Access Controls vendor are currently looking to bring on board an exceptional Product Manager with recent exposure around Access Controls and Identity Management. The particular portfolio this person would be responsible for is their Events and transportation Access controls solutions. Managing and overseeing Configuration and implementations of these solutions. The Product Manager would need previous experience within a similar product suite, particularly around Access Controls/ Identity & Access Management delivery programmes. Project size will vary from £200,000 to larger multi-million pounds, so someone with experience managing these sizes of projects is key. This will be a client facing position, so someone with strong customer engagement skills, and the willingness to travel will be essential. If you have any project management certifications, for example Prince2 Practitioner, This will be hugely advantageous. Due to some of the Engineering team being based in Italy, Someone with strong Italian speaking and listening skills will be a front runner, but this is not an essential skill. Unfortunately sponsorship can't be provided to non-eu candidates TC7774 Salary: £50,000 - £90,000 Location: London with travel Cyber Security Jobs | Information Security Jobs | Access Controls Jobs | IDAM Jobs | IAM Jobs | Identity And Access Management Jobs
- CyberArk Specialist
- Up to £90,000
We are currently working with an International Outsourcing business who are looking for a CyberArk Specialist to assist with a large scale Identity and Access Management rollout across large Financial institutions. This business is at the forefront of the financial services market, working alongside some of the largest banks globally, so this will be a great chance to be a key figure in large digital transformation projects. The CyberArk Specialist responsibilities for this role will to be the lead in the Configuration and Design of a Large Privileged Access Management rollout of the CyberArk suite. Solutions Design Client Engagement Liaison between the business and Technical teams If you have strong hands on CyberArk exposure and are looking to move into more of a Business led programme, this is a great opportunity to make that transition. The CyberArk Specialist will be mostly spent on client site, which is based in London. So the right individual will be commutable into Central London. Candidates must be based in the UK. Sponsorship can't be provided to non-eu applicants Salary: £Up to 90,000 Location: London REF: TC7773 CyberArk Jobs | Information Security Jobs | Cyber Security Jobs | IDAM Jobs | IAM Joba | Identity and Access Management Jobs
- Internal Cyber Security Consultant - Technology and Information Security
- Up to £60,000
CH7770 Internal Cyber Security Consultant - Technology and Information security Reading £60,000 Internal Cyber Security Consultant needed in Reading. If you have a blend of hands on experience between security technology solutions and information security and want to be the go to person within an organisation to drive, shape and maintain the security landscape then apply today. MUST be commutable to Reading The Internal Cyber Security Consultant role requires a blend of hands security technology and information security experience- advisory / implementing. Specifically Technology - Support, maintaining, configuring, analysing logs of internal Security technology. As well as identifying new technologies to implement into the business. Information Security - Ensuring policies are relevant to the internal security technology, ensuring ISMS is up to date, aiding in new policy definition. Security user awareness - training. Internal Cyber Security Consultants role will be diverse covering the breadth of the Security landscape. All details kept in the strictest of confidence. Chris.Holt@dclsearch.com 07884666351