Nearly Two-Thirds of IT Leaders Have Fallen For Phishing Attacks
Sixty-four percent of IT leaders have clicked on phishing links, a new survey by Arctic Wolf has found.
Despite this, 80% of these same professionals are confident their organization won’t fall victim to a phishing attack.
The survey found that 34% of organizations send simulated phishing emails to their employees at least once every two weeks, but only 15% of end users are aware of them.
Likewise, the IT and security leaders surveyed said 83% of their employees fall for the phishing simulations.
The report also found that organizations usually increase employee training programs after they’ve sustained a breach, and the frequency of this training has a noticeable effect on security.
“The data suggests that organizations who have suffered a breach are more likely to increase the regularity of training,” the report says. “40% of IT and cybersecurity leaders whose security awareness training happens quarterly have not experienced a breach in the past year, as opposed to 14% of leaders whose training is weekly.”
The researchers add, “We see a direct correlation between those who receive frequent training, and those displaying the most robust attitudes to security.”
The report observed poor password security practices at many organizations, with 68% of IT leaders and end users admitting to reusing passwords.
“Regular password updates, the practice of reusing passwords and relying on memory indicates significant vulnerability within organizations,” the researchers write. “Password reuse and poor tracking increase the risk of credential theft and compromise, especially for sensitive accounts.
Implement a robust password management system and encourage the use of unique, strong passwords for different accounts. Consider adopting multi-factor authentication (MFA) to add an extra layer of security and enable end-users to accept MFA notification if only they initiated.”
KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.
Arctic Wolf has the story.
Free Phishing Security Test
Would your users fall for convincing phishing attacks? Take the first step now and find out before bad actors do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.
Here’s how it works:
- Immediately start your test for up to 100 users (no need to talk to anyone)
- Select from 20+ languages and customize the phishing test template based on your environment
- Choose the landing page your users see after they click
- Show users which red flags they missed, or a 404 page
- Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
- See how your organization compares to others in your industry
PS: Don’t like to click on redirected buttons? Cut & Paste this link in your browser: https://info.knowbe4.com/phishing-security-test-partner?partnerid=001a000001lWEoJAAW