Phishing Resistance for Charities

Stu Sjouwerman | Nov 11, 2019
UKFUNDRAISING81% of charities say they’ve been targeted by a phishing attack this year, according to Ed Macnair, writing for UK Fundraising. Meanwhile, only 37% of charities think their IT and cybersecurity employees are capable of fending off cyberattacks. Charities face the same types of threats as other organizations, but often have less money to spend on security.
 
Macnair notes that phishing attacks have grown much harder to detect as attackers have improved their methods. CEO fraud and business email compromise are examples of highly targeted attacks that have proven extremely lucrative.
 
“Phishing is a good example of cyber attack that has become increasingly sophisticated,” Macnair writes. “The crude mass-email with a compromised link or attachment has fallen out of vogue, and now criminals are opting to send extremely specific, customized emails to catch employees or volunteers out. These attacks target individuals who have access to high-value information, often use email addresses that are almost identical to a colleague or family member, and contain content that, on the surface, is not suspicious at all.”

Macnair adds that only one employee has to fall for a phishing email for the entire organization to be placed at risk. Once the attackers have gained access to one email account, they can use it to launch more convincing attacks against other employees.

Macnair recommends a combination of training and technology to thwart these attacks. He says employee education needs to include the new techniques that attackers are using. New-school security awareness training can provide your employees with the knowledge they need to avoid falling for these attacks.

UK Fundraising has the story: https://fundraising.co.uk/2019/11/01/how-charities-can-protect-themselves-against-phishing-scams/

 

Ready to Build a Security Culture That Lasts?

Stop treating training like a checkbox exercise. Using 15+ years of behavioral data, our AI-powered platform personalizes training for every user to significantly reduce human risk and stop attacks before they start.

Get a Quote

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.