Organizations are working to limit the effectiveness of phishing attacks using both internal and external collateral and programs. According to ISACA, the important thing is to have something in place.
Making employees aware of phishing scams, the latest tactics, and how social engineering can be used is a burden put on IT on top of everything else they’re responsible for. According to the ISACA’s Phishing Defense and Governance report, it’s a task organizations take seriously:
But phishing simulations aren’t getting the same focus. According to the report, only 57% of organizations utilize phishing simulations to test whether users are paying attention to both the training provided and the emails they interact with. With cybercriminal’s social engineering tactics constantly improving, it’s critical for organizations to have this feedback loop in place to understand where their employee risk exists.
Phishing simulations present users with real-world (but harmless) phishing attacks, where their engagement with such emails is tracked, allowing organizations to report on which employees have not “learned their lesson.” It’s a vital part of the security strategy designed to allow users to act as part of the organization’s defense.
In this report ISACA recommends the following to reduce the risk of successful phishing attacks: