Nearly Two-Thirds of IT Leaders Have Fallen For Phishing Attacks

Stu Sjouwerman | Oct 22, 2024

Phishing StudentSixty-four percent of IT leaders have clicked on phishing links, a new survey by Arctic Wolf has found.

Despite this, 80% of these same professionals are confident their organization won’t fall victim to a phishing attack. 

The survey found that 34% of organizations send simulated phishing emails to their employees at least once every two weeks, but only 15% of end users are aware of them.

Likewise, the IT and security leaders surveyed said 83% of their employees fall for the phishing simulations.

The report also found that organizations usually increase employee training programs after they’ve sustained a breach, and the frequency of this training has a noticeable effect on security.

“The data suggests that organizations who have suffered a breach are more likely to increase the regularity of training,” the report says. “40% of IT and cybersecurity leaders whose security awareness training happens quarterly have not experienced a breach in the past year, as opposed to 14% of leaders whose training is weekly.”

The researchers add, “We see a direct correlation between those who receive frequent training, and those displaying the most robust attitudes to security.”

The report observed poor password security practices at many organizations, with 68% of IT leaders and end users admitting to reusing passwords.

“Regular password updates, the practice of reusing passwords and relying on memory indicates significant vulnerability within organizations,” the researchers write. “Password reuse and poor tracking increase the risk of credential theft and compromise, especially for sensitive accounts.

Implement a robust password management system and encourage the use of unique, strong passwords for different accounts. Consider adopting multi-factor authentication (MFA) to add an extra layer of security and enable end-users to accept MFA notification if only they initiated.”

KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.

Arctic Wolf has the story.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.