Name It, Frame It, Check It: A 3-Step Fix for Phishing

https://hackernoon.imgix.net/images/2jqChkrv03exBUgkLrDzIbfM99q2-x38225y.jpeg

I’m a cognitive security independent researcher which means I spend most of my time researching how corporate workers fall for phishing attacks through their emotions and how CISOs can use that insight to reduce breaches.

A few days ago, I surveyed r/CISO from April 2013 to the present to discover which problem chief security officers rated as their most challenging. For most executives, it was superficial compliance. Employees do all the obligatory workshops, games, simulations - and still fall for phishing attempts. Indeed, Cybsafe reports that only one in ten workers remembers all their cybersecurity training. When it comes to applying the security rules in practice, just 12% of employees of medium to large corporations do so. Ironically, it’s workers who are most familiar with the rules who are sometimes duped.

Why do employees pass security training—and still fall for bait?

To cite psychologists Kahneman and Tversky, employees...

Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE

Read more