The Phishing Breakthrough Point
Effectiveness of Phishing, Training & Understanding the Human Response
Executive Summary
Utilising security awareness training and phishing security tests can be a useful and effective tool to reduce unintentional insider threats. However, if robust metrics are not put in place to effectively gauge the click rate patterns from a human landscape perspective, phishing tests can create organisational social engineering blind spots. Meaningful phishing assessment metrics should go beyond the click rate, and understand human patterns relative to their job and work environment.
Key Takeaways
- Awareness training makes a dierence in the short and long term. IT and business decision makers should consider how effective training is in the long term when assessing the value of training services
- “Low hanging fruit” phishing emails still work. It is important to understand the employee level of awareness in terms of levels of phishing email sophistication
- IT and business decision makers need to be aware of how some types of jobs, and working hours of their employees can react responses to phishing emails
- Data-driven phishing evaluations on who is clicking what, and when, can more effectively indicate patterns of phishing vulnerabilities within an organization than the blanket click rate of the overall organization
- Clear communication with employees regarding IT updates or HR processes can play a vital role in preventing misunderstandings and blocking phishing attempts based on generic company email themes.
About This Whitepaper
This whitepaper reports the results of a 6-month experimental study testing the effectiveness duration of the 40-minute KnowBe4 “Kevin Mitnick Security Awareness Training”. The scope of the experiment was on common workplace phishing emails tested among small to medium size companies. This whitepaper was sponsored by KnowBe4.
State of Affairs in Phishing
The estimated annual cost of cybercrime to the world economy in 2015 was $450 billion dollars.1 That is a staggering amount in losses. The most concerning aspect is that 90-95% of all successful cyber-attacks begin with a phishing email.2 It’s been estimated that around 156 million emails are sent each day, 16 million make it through the filters, and 800,000 of them are not only opened, but the phishing links are clicked, and out of those who clicked it is estimated that around 80,000 share compromising information.3 On top of this, each quarter some 250,000 new phishing URLs are identified.4 Even though phishing can be automated in mass campaigns, the most successful campaigns are those which are tailored to an organization or person – spear phishing. However, a significant amount are successful with mass emails that appear to come from a fake or spoofed email. Getting through the mass phishing email hurdle is a breakthrough point in an individual’s or organization’s phishing awareness level. Like in the learning of a new language, a breakthrough point5 is a turning point when the structure of a language starts to make sense and everything from that point on becomes easier to learn. Similarly, in phishing, a breakthrough point is where one becomes clearly aware of the tell-tale signs, and can more easily learn and pick up on new phishing techniques. In the case of a phishing breakthrough point, once achieved, a user would consistently and systematically not click on phishing links over an extended period of time.