Spare the rod and spoil the child is taking on new meaning in IT, at least for one IT security expert. He argues that employees who intentionally or even inadvertently put their organizations at risk through online practices should be held up as examples.
“Rather than simply retraining employees who are prone to fall for phishing attacks, KnowBe4 advocates reporting them to immediate supervisors and human resource departments that can pressure workers into becoming more careful,” Network World notes of the idea.
According to IT security firm KnowBe4’s Founder and CEO Stu Sjouwerman, the best way to stop unwanted behavior is to punish it.
“With this program, they start to understand that there truly are repercussions for clicking on phishing links. That will change the behavior,” Sjouwerman is quoted as saying.
What Sjouwerman has in mind is an online program that monitors and automatically notifies management when employees click on potentially risky links. Employees would be trained first, of course, in how to avoid risky behavior. And they would be warned of the consequences of any bad actions.
KnowBe4 tested its theory on 372 companies over a 12 month period, the article notes. Of 291,000 people who underwent the testing, approximately 16 percent were found to be prone to clicking on links in phishing emails. When the test groups were held accountable for their online actions, the research found that the percentage of those who were victims to phishing attacks dropped to approximately one percent.
As noted by Network World, phishing attacks are on the rise. They represent a threat to organizations because hackers often research intended victims beforehand, and then design emails that appear to be legitimate to those users. In the case of the test groups noted above, approximately one-third were in financial services companies.
Read more:
– see the Network World article
Related Articles:
From phishing to adult content, many CEOs benefit from analyst cover-ups
Data breaches are significantly underreported, survey of IT pros finds [FierceITSecurity]
‘Dramatic’ increase in Apple phishing attacks, warns Kaspersky Lab [FierceITSecurity]
