Preventing Phishing Scams
Preventing phishing scams from becoming incidents is largely a question of minutes, and minutes depend on culture.
Someone who realises they have entered a password on a fake page has a short window in which resetting it and revoking sessions solves the problem cheaply. Whether they use that window depends entirely on what they expect to happen when they own up.
Organisations that publish click rates by team, or single people out after simulations, teach staff that reporting costs them something. Those organisations find out later, usually from somebody else.
The alternative is stated plainly and repeatedly. Tell us immediately, nothing happens to you, and it is the delay we care about rather than the click.
Measure reporting speed rather than click rate.
The Australian Cyber Security Centre publishes incident guidance. This is general information rather than legal advice, and obligations vary by state and territory.
See Sentrient’s incident reporting software and cyber security training course.
Understanding And Preventing Phishing Scams
Phishing scams are a type of cyber-attack where a cybercriminal attempts to trick a victim into providing sensitive information, such as login credentials or financial information, by posing as a reputable entity. These scams can take many forms, including email, text messages, and social media, and they are becoming increasingly sophisticated and challenging to detect. […]
