The Human Factor in Cybersecurity: Protecting Against Social Engineering Tactics
INTRUST Bank
Unchanging values are more relevant than ever. That's Tradition for Today. That's INTRUST Bank.
Cybersecurity isn’t just about securing systems It’s also about protecting people from falling victim to social engineering — when a cybercriminal uses deception to manipulate someone into revealing confidential information. Cybercriminals often exploit our human factor, or our tendency to want to be helpful, trusting, and non-confrontational, as well as our tendency to skim through messages and skip over details. One of the best ways to protect your business is to educate your employees about social engineering and how to spot it.
Emphasize the importance of cybersecurity
Some business owners and employees might ask, “Does our business need a cybersecurity plan? We only have eight employees, and our business doesn’t have anything to do with digital technology. We sell vacuum cleaners.”
When it comes to cybersecurity, any business owner and employee can benefit from education and a plan. By training your employees, you can empower them to make better decisions and recognize potential threats. It’s an effective way to provide a sense of security and peace of mind for both you and your business.
The impact of a cyberattack can come in the form of loss of revenue, damaged reputation, and regulatory consequences that could result in losing your business license. No matter the size of your business, it’s important that everyone at every level of your business understands how cyberattacks begin.
Make a plan and start early
Despite employing state-of-the-art technology and teams of dedicated IT professionals, businesses remain vulnerable to cyberattacks. But it’s not because their equipment or technical skills are lacking. At the end of the day, every employee plays a crucial part in safeguarding their organization.
All the cybersecurity technology still can’t stop an employee from giving cybercriminals a safe passage into their internal networks. Employees typically aren't intentionally giving safe passage into the internal networks, but it’s human nature to want to be helpful when receiving a request from someone we believe to be legitimate. So a good first step is to educate your employees the first day they begin work.
Consider discussing the basics at employee orientation, such as how to recognize?various social engineering attempts including business email compromise ?and?phishing emails. If you already have an employee onboarding program, consider adding social engineering education to the curriculum.
These are the first of many discussions you may want to have around cybersecurity. Regular meetings, conversations, and reminders about the latest security awareness tips can be helpful.
Learn to recognize social engineering attempts
A social engineering email can look like this:
We’re reaching out to you regarding a suspicious charge that has been placed on your PayPal account. Please click the link below to approve or dispute this charge. Your account has been frozen until you complete this process.
It could also look like an email from your boss:
领英推荐
Hey, Bill, are you in the office today? I need you to make a payment for me. We’re late sending it out, and the client is really upset, so it needs to get processed right away this morning.
But you don’t have a PayPal account. And you just walked past your boss in the hallway. Those are two red flags telling you NOT to click on that link or take the action your “boss” wants you to. These are social engineering attempts — fake communications that may look legitimate that ask you to send money or reveal information.
When in doubt, watch for these signs:
Know the various types of social engineering
There are several popular social engineering methods:
Keep in mind that cybercriminals can create incredibly believable emails with help from an artificial intelligence platform and a well-crafted prompt.
Implement ongoing training
We get busy. We’re in a hurry to finish a project. A co-worker diverts our attention with a question. We’re hungry and we want to get to lunch. There are all sorts of circumstances to distract us. And what looks like a valid email at first glance can quickly turn into a major data breach when a preoccupied employee clicks on a link in a social engineering communication.
Education and routine exercises ?are key. Consider running exercises to test employee preparedness. A common drill involves sending an email that mimics a phishing email. Additionally, keep these tips in mind and pass them along to your employees:
Treating emails and requests with caution and knowing what to look for can help reduce your risk of falling victim to social engineering. It’s one of the most effective ways to help keep your business safe.