Phishing By Industry Benchmarking Report by KnowBe4

Reduce your susceptibility to phishing

More Whitepapers

Introduction

Cybercriminals never take a vacation. In fact, 2020 gave them reason and renewed motivation to ramp up their nefarious efforts. Phishing incidents nearly doubled in frequency from 2019 to 2020, from 114,702 incidents in 2019, to 241,324 incidents in 2020, according to the U.S. Federal Bureau of Investigation (FBI). Overall, phishing reigned as the most common type of cyber crime last year, according to the FBI.

The idea that technology can prevent all cyber-related incidents has never been further from the truth because cybercriminals know the easiest way in is through your humans. Security leaders must understand that there is no such thing as a perfect, fool-proof, impenetrable secure environment. Many organizations fall into the trap of trying to use technology as the only means of defending their networks and forget that the power of human awareness and intervention is paramount in arriving at a highly secured state.

Every security leader faces the same conundrum: even as they increase their investment in sophisticated security orchestration, cyber crime continues to rise. Security is often presented as a race between effective technologies and clever attack methodologies. Yet there’s an overlooked best practice that can radically reduce an organization’s vulnerability: security awareness training and frequent simulated social engineering testing.

As the COVID-19 pandemic continues to monopolize our lives, cybercriminals have not stopped their onslaught of manipulation campaigns. The COVID-19 pandemic proved lucrative for these criminals as the public remained continuously curious and distracted by changing news broadcasts, misinformation spread on social media, and fragmented “factual” debates in the political forum. KnowBe4 saw a 6,000% increase in COVID-19 related phishing attacks in March 2020 alone.

These criminals successfully evade an organization’s security controls by using clever phishing and social engineering tactics that often rely on employee naivete. Emails, phone calls and other outreach methods are designed to persuade staff to take steps that provide criminals with access to company data and funds. Each organization’s employee susceptibility to these phishing attacks is known as their Phish-Prone™ percentage (PPP). By translating phishing risk into measurable terms, leaders can quantify their breach likelihood and adopt training that reduces their human attack surface.

Understanding Risk by Industry An organization’s PPP indicates how many of their employees are likely to fall for social engineering or phishing scams. These are the employees who might be tricked into opening a file infected with malware or transferring company funds to a cybercriminal’s bank account. A high PPP indicates greater risk, as it points to a higher number of employees who typically fall for these scams. A low PPP is optimal, as it indicates the staff is security-savvy and understands how to recognize and shut down such attempts.

In short, a low PPP means that an organization’s human security layer is providing security strength rather than weakness. The overall Phish-Prone percentage offers even more value when placed in context. After seeing their PPP, many leaders ask questions such as “How does my organization compare to others?” and “What can we do to reduce our Phish-Prone percentage?”

KnowBe4, the provider of the world’s largest security awareness training and simulated phishing platform, has helped tens of thousands of organizations reduce their vulnerability by training their staff to recognize and respond appropriately to common scams. To help organizations evaluate their PPP and understand the implications of their ranking, KnowBe4 conducts an annual study to provide definitive Phish-Prone benchmarking across industries. Categorized by industry vertical and organization size, the study reveals patterns that can light the way to a stronger and safer future.

Whitepaper

Every organization struggles to answer an essential question— “How do I compare with other organizations that look like me?”