Journalists Need Phishing Awareness, Too

Stu Sjouwerman | Nov 30, 2020

Journalists Need Phishing AwarenessAll types of journalists need to be wary of phishing and other social engineering attacks, according to Jacob Granger, writing at Journalism.co.uk. Granger quotes digital security expert and former New York Times reporter Runa Sandvik as saying that all journalists need to be educated about security, even those who don’t report on sensitive topics or work in dangerous environments.

“Early on, my sense was that digital security was something that only certain reporters needed,” Sandvik said.

Sandvik explained that security is relevant to every employee in the newsroom, since an attacker only needs to compromise one device in order to gain a foothold.

"In some cases, it has been helpful to illustrate how targeting one individual could impact the whole newsroom and the entire business,” Sandvik continued. “Those examples are not typically found in the world of mercenaries and spies, but in ransomware. It only takes one individual to click a link, run a piece of software or open a document before the entire newsroom and company are affected by it.’

Sandvik added that organizations should ensure that their employees receive adequate education before an attack happens.

“Especially if you work for an established media organisation, those shouldn't be things you have to ad hoc figure out along the way, it should be an established process within the media organisation,” Sandvik said.

Granger notes that journalists can find themselves targeted by nation-states, criminal actors, or mercenary hack-for-hire groups.

“[R]eporters may need separate workflows and devices for sensitive work or specific communications,” Granger concludes. “But crucially, newsrooms need a united front on cybersecurity, as the entire team is only as strong as its weakest link.”

New-school security awareness training can provide your organization with an essential layer of defense by teaching your employees to recognize social engineering attacks and follow security best practices.

Journalism.co.uk has the story.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.