[SPECIAL] The Hard Evidence That Phishing Training and Testing Really Works Great
We are publishing a special edition this week.
Now and then in the press you get people who ask if security awareness training which includes phishing training and testing is really necessary. We decided to answer that question once and for all, so that this is available as your budget ammo year-round.
Security awareness training (SAT) and simulated phishing works to significantly reduce cybersecurity risk. We have the data, customer testimonials and government recommendations to prove it.
Social engineering, especially as enabled by email, text messages, the web and phone calls, is involved in the vast majority of cybersecurity attacks. No other root initial access hacking method comes close.
Cybersecurity experts state that social engineering is involved in 60% to over 90% of all successful data breaches.
For example, Barracuda Networks reported that spear phishing accounted for 66% of all successful compromises. Seventy-nine percent of all successful credential thefts came through phishing . Avast recently stated that 90% of all cyber attacks involve social engineering . Reports may differ over the exact percentage, but they all agree that social engineering is the number one threat.
And if you do not aggressively try to mitigate social engineering using your best defense-in-depth combination of policies, technical defenses and education, you or your organization are more likely to become a part of those statistics.
It is important to note that social engineering is the number one threat only after it has already gotten past every existing policy and technical defense. Some estimates state that as many as one in every seven malicious emails make it past content filters.
Until the — unlikely — event where we get proven technical defenses that work to prevent all social engineering, we will need continuous education to help users to spot and report social engineering attacks. Note this U.S. Government FedRAMP recommendation : "Users are the last line of defense and should be tested."
We recommend frequent training (at least monthly) and frequent simulated phishing campaigns (weekly if possible, because you can gamify it and get great results that way.)
Security Awareness Training Analysis Whitepaper
KnowBe4 has the data from over 60,000 customer organizations worldwide who use our platform as recommended. They were able significantly reduce the likelihood that a user will click on a phishing attack and the more frequently the training and simulated phishing occurs, the better .
The numbers tell the story
We analyzed over 10 years of records from those 60k+ customers, comprising 32,604,108 separate individual users, who took a total of 493,871,295 Phishing Security Tests (PSTs) and participated in awareness training at least once a year. We believe this is the largest analysis, in terms of both customers and test numbers, of any study of this kind.
We found these five main points:
Customer Testimonials
This is not just us saying training works. Our customers see the improvement in their own environments and support the effectiveness of SAT.
Creating Your Security Awareness Training Policy
Doing cybersecurity training once a year to meet a compliance requirement does not work. We recommend a longer SAT training session when employees are hired (say 15-30 minutes), and a similar longer session once a year thereafter. Then, SAT training should be at least monthly, although shorter in duration (say three to five minutes).
Simulated phishing campaigns should be conducted at least once a month. However we found that organizations that conduct phishing tests weekly had been able to drive down their social engineering risk score the lowest.?Recipients "failing" a simulated phishing test should be given more training.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) Advisory recommends "continuous training ." The recent introduction of an integrated Phish Alert Button in Microsoft Outlook makes things easier and leads to better threat detection and prevention.
Fantastic ROI
And it goes without saying that deploying KnowBe4 has fantastic ROI. The combination of SAT with PhishER Plus , combined with Compliance Training , all using the same platform has incredible returns. Forrester showed a three-year ROI of 276% with payback in less than 3 months. Get your copy of the study here.
You, of course, should not do SAT and simulated phishing in a way that makes your co-workers upset or disgruntled. If you are creating unhappy campers because of SAT and simulated phishing tests, you are doing it wrong. Use your SAT program to reduce cybersecurity risk and to create a culture of healthy skepticism when your users get sent a suspicious-looking messages.
If you are interested in creating a professional corporate SAT policy, we have a guide for that . It discusses the sections that a corporate SAT program policy document should contain followed by an example of a corporate program SAT policy.
To reiterate, security awareness training works! We have the data, the customer testimonials, and government cybersecurity organizations on our side. Let's create a stronger security culture and keep our networks safe!
Blog post with a TON of links: https://blog.knowbe4.com/the-hard-evidence-that-phishing-training-and-testing-really-works
领英推荐
[New Features] Ridiculously Easy Security Awareness Training and Phishing
Old-school awareness training does not hack it anymore. Your email filters have an average 7-10% failure rate; you need a strong human firewall as your last line of defense.
Join us TOMORROW, Wednesday, June 5, @ 2:00 PM (ET), for a live demonstration of how KnowBe4 introduces a new-school approach to security awareness training and simulated phishing.
Get a look at THREE NEW FEATURES and see how easy it is to train and phish your users.
Find out how 65,000+ organizations have mobilized their end users as their human firewall.
Date/Time: TOMORROW, Wednesday, June 5, @ 2:00 PM (ET)
Let's stay safe out there.
Warm Regards,
Stu Sjouwerman, SACP
Founder and CEO
KnowBe4, Inc.
SUBSCRIBE to your weekly CyberheistNews here: https://www.knowbe4.com/cyberheistnews
PS: Your KnowBe4 Fresh Content Updates from May 2024: https://blog.knowbe4.com/knowbe4-content-updates-may-2024
PPS: KnowBe4's Original "2024 Social Engineering Red Flags" Training Series Wins Silver Telly Award: https://finance.yahoo.com/news/knowbe4s-original-2024-social-engineering-120000478.html?
"It is a capital mistake to theorize before one has data. Insensibly one begins to twist facts to suit theories instead of theories to suit facts." - Arthur Conan Doyle: Author of Sherlock Holmes (1859 - 1930)
"Only the strongest people have the pluck to change their minds and say so if they see they have been wrong in their ideas." - Enid Blyton Author (1897 - 1968)
Thanks for reading CyberheistNews
You can read CyberheistNews online at our Blog https://blog.knowbe4.com/cyberheistnews-vol-14-23-special-the-hard-evidence-that-phishing-training-and-testing-really-works-great
This Week's Links We Like, Tips, Hints and Fun Stuff