HomeSecurityTackling phishing attacks requires a multi-layered approach - Education is not enough

Tackling phishing attacks requires a multi-layered approach - Education is not enough

Phishing is one of the oldest techniques used by hackers . However, it is still a very popular option. Phishing emails are used either as a basic attack or in combination with other malware . Hackers send emails and target both small and large businesses.phishing

However, despite the great risk, businesses are not paying enough attention to this threat . Phishing exploits continue to be a major threat in 2019 because hackers are researching their targets well before they attack. They find vulnerabilities in each business , such as vulnerabilities in systems, and use new techniques that will help them bypass security programs and penetrate systems.

Even the most informed and trained employees can fall victim to hackers. Social engineering is very effective in deceiving staff. Phishers use psychological tricks and convince users to do things they would not otherwise do.

Tackling phishing attacks requires a multi-layered approach - Education is not enough

Staff awareness and training alone are not enough to prevent phishing attacks. To stay safe, businesses should adopt a multi-layered approachthat combines technical controls with employee training. Each layer acts as a safety net in case the other layers fail.

The protection levels are as follows:

Implement technical controls to protect systems: The first step is to implement security solutions that will prevent malicious emails from reaching employees’ inboxes. These security solutions include content filtering, authentication, threat detection programs, and more.

Staff training: Training employees to recognize phishing emails is essential. In case something slips through technical checks, employees should be able to spot it. Training and awareness of new threats should be an ongoing process. It is important to conduct frequent tests to evaluate employee performance. However, if something goes wrong, employers should not be overly strict with trainees. If employees are afraid, they are likely to not report anything that seems suspicious because they are afraid of being embarrassed.

Have a plan in place in case technical and human controls fail: As mentioned above, training is not enough. If all controls fail and phishing emails succeed, businesses should have a contingency plan in place. isolation Browser and multi-factor authentication can help mitigate the impact of a successful phishing attack. Having a plan in place helps businesses recover quickly.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS