While ransomware like WannaCry draws the headlines, phishing is the cybercrime deceiving organizations consistently. Unsurprisingly those with access to company bank accounts, accounting and finance team members, are most frequently targeted.
The reality, 41% of organizations experience phishing attacks daily or more, and 77% experience a phishing attack at least once a month, according to a phishing report from UK-based security software firm Sophos.
The study also revealed cybercriminals are adept at using social engineering to exploit human weaknesses. That is why everyone is on the front line when it comes to security. Beside the teams connected to company finances, cybercriminals also likely to target those who manage business processes and IT controls, which puts organizations at risk for ransomware and extortion. But cybercriminals do not discriminate. No role is safe from phishing. Anyone who receives emails is at risk.
John Shier, senior security expert at Sophos, said, "As the quality of phishing emails has improved it is important to remember that some recipients will get fooled. Users are the first line of defense against a successful phishing attack. While education is an important part of keeping an organization secure, so is the user's ability to report suspected phishing attempts." He added organizations should make it easy and blameless for users, even those fooled, to report attacks. "This early warning system is crucial for any organization wishing to respond quickly and decisively to a phishing attack."