For those who care to know and read, Ran a phishing simulation for a client last month. Simple email. Nothing fancy. ‘Your account will be suspended in 24 hours. Click here to verify.’ 40% of staff clicked it. When I sat down with the team after, one person said something that stuck with me: He said, ‘It looked exactly like the real ones we get every week.’ That's the actual problem. Not that people are careless. It's that attackers have gotten good at looking legitimate, and most security awareness training still teaches people to spot the obvious fakes. We redesigned the training around that. Fewer ‘spot the bad grammar’ exercises. Now more of, ‘here's what a genuinely convincing attempt looks like, and here's the one thing that still gives it away.’ Second simulation, done four weeks later: 12%. That's the number that matters. Not whether people fell for it once. Whether the training actually changed behavior. Phishing simulations shouldn’t be boring because attackers ain’t, trust me
Cyber_RachealShare
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.