New York Tech Media
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
New York Tech Media
No Result
View All Result
Home Cybersecurity

People working in IT related roles equally susceptible to phishing attempts as the general population

New York Tech Editorial Team by New York Tech Editorial Team
February 3, 2022
in Cybersecurity
0
People working in IT related roles equally susceptible to phishing attempts as the general population
Share on FacebookShare on Twitter

Phishing emails that mimic HR announcements or ask for assistance with invoicing get the most clicks from recipients, according to a study from F-Secure.

phishing emails clicks

The study, which included 82,402 participants, tested how employees from four different organizations responded to emails that simulated one of four commonly used phishing tactics.

Phishing emails that mimic HR announcements most clicked

22% of recipients that received an email simulating a human resources announcement about vacation time clicked, making emails that mimic those sent by HR the most frequent source of clicks in the study.

An email asking the recipient to help with an invoice (referred to as CEO Fraud in the report) was the second most frequently engaged with email type, receiving clicks from 16% of recipients.

Document Share (notifications from a document hosting service) and Service Issue Notification (messages from an online service) emails received clicks from 7% and 6% of recipients, making them the least frequently clicked emails in the study.

However, according to Matthew Connor, F-Secure Service Delivery Manager and lead author of the report, the study’s most notable finding was that people working in ‘technical’ roles seemed equally or even more susceptible to phishing attempts than the general population.

“The privileged access that technical personnel have to an organization’s infrastructure can lead to them being actively targeted by adversaries, so advanced or even average susceptibility to phishing is a concern,” Connor explained. “Post-study surveys found that these personnel were more aware of previous phishing attempts than others, so we know this is a real threat. The fact that they click as often or more often than others, even with their level of awareness, highlights a significant challenge in the fight against phishing.”

IT or DevOps departments no better at reporting phishing attempts than others

Out of the two organizations studied with personnel working in IT or DevOps, both clicked test emails at rates that were either equal to or higher than other departments in their organizations: 26% from DevOps and 24% from IT compared to 25% for one organization, and 30% from DevOps and 21% from IT compared to 11% for the other organization.

Furthermore, the study found that these departments were no better at reporting phishing attempts than others. In one organization, IT and DevOps came third and sixth out of nine departments in terms of reporting. In the other organization, DevOps was the twelfth best at reporting out of seventeen departments, while IT was fifteenth.

The value of a fast, easy-to-use reporting process was also highlighted in the report. In the first minute after the test emails arrived in inboxes, over three times the number of people who reported it as suspicious had clicked. This number levelled out at around five minutes and stayed consistent after that.

And while reporting became more common as time went on, the different processes at different organizations played a key role. 47% of participants from an organization that provided all employees with a dedicated button to flag suspicious emails used it during the study. Only 13% and 12% of participants from two other organizations reported their test emails (the remaining organization did not provide data on reporting).

According to F-Secure Director of Consulting Riaan Naude, the patterns in report and click rates identified by the study highlights a practical opportunity for organizations to mobilize employees in a collective effort to protect themselves against phishing.

“The evidence in the study clearly points to fast, painless reporting processes as common ground where security personnel and other teams can work together to improve an organization’s resilience against phishing. Getting this right means that an attack can be detected and prevented earlier, as security teams may only have a few precious minutes to mitigate a potential compromise,” said Naude.

Credit: Source link

Previous Post

How organizations are arming themselves to combat threats

Next Post

Kenyan insurtech startup Lami enters Malawi, DRC after acquiring Bluewave, eyes rest of Africa – TechCrunch

New York Tech Editorial Team

New York Tech Editorial Team

New York Tech Media is a leading news publication that aims to provide the latest tech news, fintech, AI & robotics, cybersecurity, startups & leaders, venture capital, and much more!

Next Post
Kenyan insurtech startup Lami enters Malawi, DRC after acquiring Bluewave, eyes rest of Africa – TechCrunch

Kenyan insurtech startup Lami enters Malawi, DRC after acquiring Bluewave, eyes rest of Africa – TechCrunch

  • Trending
  • Comments
  • Latest
Meet the Top 10 K-Pop Artists Taking Over 2024

Meet the Top 10 K-Pop Artists Taking Over 2024

March 17, 2024
Panther for AWS allows security teams to monitor their AWS infrastructure in real-time

Many businesses lack a formal ransomware plan

March 29, 2022
Zach Mulcahey, 25 | Cover Story | Style Weekly

Zach Mulcahey, 25 | Cover Story | Style Weekly

March 29, 2022
How To Pitch The Investor: Ronen Menipaz, Founder of M51

How To Pitch The Investor: Ronen Menipaz, Founder of M51

March 29, 2022
Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

March 29, 2022
UK VC fund performance up on last year

VC-backed Aerium develops antibody treatment for Covid-19

March 29, 2022
Startups On Demand: renovai is the Netflix of Online Shopping

Startups On Demand: renovai is the Netflix of Online Shopping

2
Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

1
Menashe Shani Accessibility High Tech on the low

Revolutionizing Accessibility: The Story of Purple Lens

1

Netgear announces a $1,500 Wi-Fi 6E mesh router

0
These apps let you customize Windows 11 to bring the taskbar back to life

These apps let you customize Windows 11 to bring the taskbar back to life

0
This bipedal robot uses propeller arms to slackline and skateboard

This bipedal robot uses propeller arms to slackline and skateboard

0
New Funding Backs Unibeam’s SIM-Driven Fix for Broken Authentication Systems

New Funding Backs Unibeam’s SIM-Driven Fix for Broken Authentication Systems

June 9, 2025
New York City

Why Bite-Sized Learning is Booming in NYC’s Hustle Culture

June 4, 2025
Driving Innovation in Academic Technologies: Spotlight from ICTIS 2025

Driving Innovation in Academic Technologies: Spotlight from ICTIS 2025

June 4, 2025
Designer Paulina Raczkowska on UX, UI Design and the Power of Empathy in Product Design

Designer Paulina Raczkowska on UX, UI Design and the Power of Empathy in Product Design

June 2, 2025
Coffee Nova’s $COFFEE Token

Coffee Nova’s $COFFEE Token

May 29, 2025
Money TLV website

BridgerPay to Spotlight Cross-Border Payments Innovation at Money TLV 2025

May 27, 2025

Recommended

New Funding Backs Unibeam’s SIM-Driven Fix for Broken Authentication Systems

New Funding Backs Unibeam’s SIM-Driven Fix for Broken Authentication Systems

June 9, 2025
New York City

Why Bite-Sized Learning is Booming in NYC’s Hustle Culture

June 4, 2025
Driving Innovation in Academic Technologies: Spotlight from ICTIS 2025

Driving Innovation in Academic Technologies: Spotlight from ICTIS 2025

June 4, 2025
Designer Paulina Raczkowska on UX, UI Design and the Power of Empathy in Product Design

Designer Paulina Raczkowska on UX, UI Design and the Power of Empathy in Product Design

June 2, 2025

Categories

  • AI & Robotics
  • Benzinga
  • Cybersecurity
  • FinTech
  • New York Tech
  • News
  • Startups & Leaders
  • Venture Capital

Tags

3D bio-printing acoustic AI Allseated B2B marketing Business carbon footprint climate change coding Collaborations Companies To Watch consumer tech crypto cryptocurrency deforestation drones earphones Entrepreneur Fetcherr Finance Fintech food security Investing Investors investorsummit israelitech Leaders LinkedIn Leaders Metaverse news OurCrowd PR Real Estate reforestation software start- up Startups Startups On Demand startuptech Tech Tech leaders technology UAVs Unlimited Robotics VC
  • Contact Us
  • Privacy Policy
  • Terms and conditions

© 2024 All Rights Reserved - New York Tech Media

No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital

© 2024 All Rights Reserved - New York Tech Media