39 Percent of Organizations Were Victims of a Mobile Attack Despite Improved Security

Stu Sjouwerman | Feb 26, 2020

Hand holding smartphone with hand drawn media icons and symbols conceptBrand new data from Verizon shows businesses sacrificed when it comes to mobile security; a decision that caused compromises with impacts well-beyond just a simple breach.

With so many possible attack vectors for IT to protect against, often times IT needs to cut corners in the name of simply “getting the job done.” According to Verizon’s newly released 2020 Mobile Security Index, 43 percent of organizations felt they sacrificed mobile security for reasons of speed, convenience, profitability, budget constraints, and lack of expertise. Despite this segment of organizations being lower than last year (48% in 2019), the percentage of organizations suffering a security compromise from their mobile and IoT devices increased 18 percent year-over-year (from 33 percent of organizations in 2019 to 39 percent in 2020).

These attacks weren’t minimally impactful either; according to Verizon, of those organizations suffering an attack, nearly two-thirds (66%) considered the compromise to have major impacts:

  • 59% suffered downtime
  • 56% suffered a loss of data
  • 46% saw the compromise of additional devices
  • 37% suffered reputation damage
  • 29% incurred regulatory penalties
  • 19% experienced a loss of business

So, where’s this all coming from? How are these bad guys getting in?

Easy. Mobile phishing.

The user’s oh-so-trusted mobile device increases their sense of security and lowers their sense of vigilance. And it’s not just email – in fact, it’s mostly not email that is the source of mobile phishing.

2-25-20 Image

According to Verizon, 85% of mobile phishing comes from messaging, social networks, gaming, and other apps – with only 15% of attacks coming from email.

Your users need to be taught that anytime a device with access to any corporate resources is being used, they need to be security-minded. This can be achieved using continual Security Awareness Training, which teaches employees about the kinds of attacks, social engineering scams, and methods of trickery that are used to con them into engaging with malicious links and attachments.

Mobile looks to be a growing security concern – and the reason is your users.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.