Phishing attacks aimed at stealing legitimate user credentials have been used in the last 24 months to undermine 45% of British organizations, according to research by security firm Sophos.
More than half (54%) of IT managers surveyed (of over 900 in total) in Western Europe said they have identified instances of employees responding to spam emails or clicking on links contained within them, according to a survey conducted by Sapio Research.
The study revealed that larger businesses are more likely to have suffered damage from phishing attacks, despite being more likely to provide training and awareness about threats posed by phishing attacks.
Organisations in the UK are falling victim to phishing attacks at the same rate as businesses in France (49%) and the Netherlands (44%). However, this does not appear to be the case in Ireland. Just 25% of respondents in Ireland said they had been the victim of a phishing attack in the last two years.
56% of companies employing 500 to 750 people were identified as victims of phishing attacks in the last two years, while two-thirds (65%) had responded to such emails.
In contrast, only 25% of businesses with fewer than 250 employees and 36% of organizations with 250 to 499 employees experienced something similar during the same period.
Half of businesses with fewer than 250 people offered training to help employees spot such attacks, compared with 78% of companies with 500 to 1,000 people. In fact, 79% of UK companies already conduct regular training on cyber threats, while 18% said they plan to offer training in the future.
Adam Bradley, CEO of Sophos in the UK, said that criminals are quite experienced, so even well-trained employees are an excellent deterrent but it is not impossible to be fooled.
"Organizations need to ensure that employees remain vigilant and properly follow the guidelines they have been given.".
According to Bradley, phishing is one of the most common methods for cybercriminals to gain access. “As organizations grow, the risk of becoming victims increases as they become more profitable targets.”.
"Given the frequency of phishing attacks, organizations that lack the basic infrastructure to identify people associated with potentially harmful emails and that don't have sufficiently secure systems are likely to face some really serious problems," he said.
According to Bradley, organizations should block malicious links, attachments and other elements before they reach users' inboxes. It is also essential to use the latest security tools to block various threats even if a user clicks on a malicious link or opens a corresponding attachment.
