According to a recent study by security training firm ThreatSim, an average of 18 percent of messages in a phishing campaign succeed in tricking recipients into clicking on a malicious link. One extremely successful campaign, according to ThreatSim, induced a staggering 72 percent of users to click on a link.
The fact that the phishing attacks have met such a high success rate is hardly a surprising one. Indeed, an unrelated penetration test campaign managed to fool even security experts at a government agency after some preparatory work to create a fake social media profile. If even highly trained personnel working on the forefront of security can fall prey, how much more will normal users be tricked?
It’s obvious companies should sign up for security training, though ThreatSim says it is not a full solution for protection from phishing. As reported by eWeek, “Companies that trained their employees at least monthly cut their click-through rate to 2 percent, far lower than the 19 percent for companies that trained quarterly.”
While some security professionals have advocated training users to defeat social engineering, others have spoken strongly against it. At least one CTO of a security outfit has dismissed the idea of regular security training for employees, saying that organizations would be better served by installing proper technical measures.
What is your opinion on this matter? Do you consider it a better idea to spend your limited security budget on training or on more specialized defenses? You can download the report directly from ThreatSim here (free registration required).
For more:
– check out this article at eWeek
Related Articles:
How a fake social profile fooled security experts at government agency
Tech giants team up to combat phishing with new email specification
IMF hack blamed on state-sponsored phishing
