You may think your company can stop an intruder from walking through your door – but chances are at least one of your employees is more likely to invite hackers for coffee.
Indeed, despite years of scare tactics, most companies still have no idea how to handle a “scary incident” in cyberspace, according to a penetration tester who claims his team has never failed to get passwords from various companies.
In fact, Michael Connory, CEO of Security In Depth (SID), says that the easiest way to get an employee to share their username and password is to simply “send them an email and ask for their username and password . ”

Most companies don't implement any protection beyond usernames and passwords – so once credentials are shared, the door is wide open for cybercriminals to gain access to internal email systems, document repositories, confidential documents, and the rest of the network.
Users' innate trust in email, combined with busy work lives that mean they don't always question unusual requests , have made social-engineering tactics devastatingly effective.
“People simply don’t have the understanding, knowledge or training to be able to recognize when someone is trying to mislead them,” Connory says.
A recent survey of 300 Australian small and medium-sized businesses, conducted by Gartner subsidiary Capterra, highlighted the extent of the problem.
More than 13% of respondents said they have been victims of phishing,while over 9% were not sure.
However, only 39% of respondents knew who to contact at their company about data security, privacy or compliance issues – and 37% of staff said they had not received any training on how to keep data secure.
