Anti-phishing training: is it enough?

Cybercriminals have always exploited human weakness to successfully execute cyber attacks. Ask any vendor what the weakest link in the chain was 15 years ago and they’d offer the human up for sacrifice. Fast forward to 2022 and the answer is likely to be the same. So why, when cybercrime techniques continue to become more sophisticated, is the industry still relying on education as the key to organizational defence?

Many organizations rely on cybersecurity training

Most companies hold cybersecurity training (and even primary schools are teaching four and five-year-olds how to stay safe online) as an essential part of the HR induction. This has been the case for over a decade, with 95% of information security professionals stating they train end users to identify and avoid phishing attacks.

In fact, of the organisations who evaluate the risk that individual end users pose to overall security postures, 3 out of 4 rely on security training awareness performance to gauge that risk.

To teach or not to teach

So, for many businesses today, it’s about teaching to be aware of potential threats and therefore not fall victim to a phishing attack. But can anti-phishing be taught, and if so, should it be?

Education and awareness do have a role to play in any cybersecurity strategy. But with the inherent vulnerabilities in the human element of security, education should be considered as a measure that fortifies, rather than replaces, technology-powered cybersecurity solutions. Employees should form a supportive line of defence within a strategy that positions technology at the helm.

Too cool for school

Companies who rely on education and awareness alone put themselves and their employees at greater risk of attack and under greater time and resource strain.

An education-based approach is complex to maintain. It needs to be a part of the onboarding process, but it also needs to be repeated at regular intervals, while taking into account employee turnover, leave, and competing business priorities. More often than not, it applies a one-size-fits-all approach to education, rather than accounting for those employees who may be more receptive to classroom-based learning versus those who respond to participatory learning such as online courses or attack simulation.

Education-based approaches often lean towards blaming rather than empowering employees, by putting the responsibility of spotting clever phishing emails onto staff when it could be more effectively and efficiently shouldered by an automated technology solution – don’t make employees your human firewall.

That’ll teach you

In contrast, an anti-phishing solution underpinned by technology doesn’t rely on regular reinforcement, excessive resources, or accountability for accountability’s sake. Of course, it does require some technical understanding and resources to implement correctly. But its main benefits are its reliability, automation, and efficiency.

A technology-based solution is built to spot vulnerabilities quickly and accurately, analyze and report efficiently, and can even be leveraged to educate and build awareness with employees as it protects. A good solution should be data-driven, adaptable, and available to all organizations.

The key to building an effective cybersecurity defense among employees is to arm users with the tools necessary to effectively defend against attacks.

With an endpoint threat protection solution, greater visibility over the network’s threat landscape, and a strong employee education program, businesses can best mitigate against the threat of phishing, the vector used to launch 91% of today’s cyber attacks.

How can Red Sift help?

The Red Sift data analysis platform is purpose-built for the challenges of cybersecurity. Products on the Red Sift platform include OnDMARC, OnINBOX, and OnDOMAIN, SaaS applications that work together to close the net on the phishing problem by blocking outbound phishing attacks, analyzing the security of inbound communications, and providing domain impersonation defense.

To find out how our technology-based approach can help your organization mitigate the threat of phishing, book your Red Sift platform demo today.

PUBLISHED BY

Clare Holmes

18 Jun. 2019

SHARE ARTICLE:

Categories

Recent Posts

VIEW ALL
News

Introducing DNS Guardian: Stop impersonation and spam caused by domain takeovers 

Rahul Powar

tl;dr: We’re thrilled to announce DNS Guardian — a new feature in Red Sift OnDMARC that can swiftly identify and stop domain takeovers that lead to malicious mail. Back in February, we shared updates with the community about SubdoMailing – an attack discovered by Guardio Labs. The attack was a form of subdomain takeover,…

Read more
Email

“What’s Next for DMARC”: Red Sift & Inbox Monster Webinar Recap

Red Sift

The recent webinar hosted by Inbox Monster, “What’s Next for DMARC: Data & Predictions for a New Era in Email Authentication,” featured insights from Red Sift and examined the significant changes brought by Yahoo and Google’s bulk sender requirements earlier this year.  It also offered a forward-looking perspective on the future of email authentication.…

Read more
Security

Navigating the Information Security Landscape: ISO 27001 vs. SOC 2

Red Sift

As cyber threats evolve, so do the standards and frameworks designed to combat them. Two of the most recognized standards in information security are ISO 27001 and SOC 2. What sets them apart, and which one is right for your organization? Let’s delve into the key differences. Purpose and Scope: Global Framework vs. Client-Centric…

Read more
News

G2 Summer 2024 Report: Red Sift OnDMARC’s Winning Streak Continues

Francesca Rünger-Field

We’re delighted to announce that Red Sift OnDMARC has again been named a Leader in G2’s DMARC category for Summer 2024. This recognition is based on our high Customer Satisfaction scores and strong market presence. Red Sift appeared in 11 reports – 5 new ones since Spring 2024! – earning 5 badges: A few…

Read more
News

Google will no longer trust Entrust certificates from October 2024

Red Sift

Tl;dr: Google has announced that as of October 31, 2024, Chrome will no longer trust certificates signed by Entrust root certificates. While there is no immediate impact on existing certificates or those issued before 31st October 2024, organizations should start reviewing their estate now. On Thursday 27th June 2024, Google announced that it had…

Read more