{"id":803089,"date":"2024-12-05T12:30:07","date_gmt":"2024-12-05T10:30:07","guid":{"rendered":"https:\/\/businesstech.co.za\/news\/?p=803089"},"modified":"2024-12-13T14:18:02","modified_gmt":"2024-12-13T12:18:02","slug":"the-phishing-phenomenon-why-your-spam-filter-isnt-enough","status":"publish","type":"post","link":"https:\/\/businesstech.co.za\/news\/industry-news\/803089\/the-phishing-phenomenon-why-your-spam-filter-isnt-enough\/","title":{"rendered":"The phishing phenomenon: Why your spam filter isn\u2019t enough"},"content":{"rendered":"\n<p>Relying solely on spam filters to protect your organisation from phishing attacks is unfortunately not enough. Today\u2019s cybercriminals are constantly innovating, and they\u2019re targeting our people as much as our technology. <\/p>\n\n\n\n<p>As phishing attacks become more sophisticated\u2014often powered by AI\u2014we need to think about security as more than just technology; it\u2019s a cultural imperative that involves every employee.&#8221; <\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong><a href=\"https:\/\/www.nclose.com\/knowbe4-partner\/\" target=\"_blank\" rel=\"noreferrer noopener\">For more information on KnowBe4\u2019s PhishER product or to sign up, click here.<\/a><\/strong><\/li>\n<\/ul>\n\n\n\n<p>Phishing remains the most widely used cyber-attack vector, with <a href=\"https:\/\/blog.knowbe4.com\/email-based-cyberattacks?utm_source=BusinessTech&amp;utm_medium=article&amp;utm_term=December+2024\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>a staggering 78%<\/strong><\/a> of phishing attacks in 2022 using sophisticated techniques to bypass email security tools. <\/p>\n\n\n\n<p>Even more alarming, <a href=\"https:\/\/blog.knowbe4.com\/email-based-cyberattacks?utm_source=BusinessTech&amp;utm_medium=article&amp;utm_term=December+2024\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>56% of these attacks<\/strong><\/a> circumvented legacy security filters entirely.<\/p>\n\n\n\n<p>Anna Collard, SVP Content Strategy and Evangelist at KnowBe4 AFRICA, emphasises the gravity of the situation: \u201cThe threat of a data breach for companies is genuine. Traditional approaches like secure email gateways alone aren\u2019t enough against well-orchestrated, human-centered attacks.\u201d<\/p>\n\n\n\n<p>Collard\u2019s own experience serves as a cautionary tale. Despite her expertise in cybersecurity, she fell victim to a cleverly disguised phishing email while in transit. <\/p>\n\n\n\n<p>\u201cI was in an Uber, checking my emails as I chatted to the driver,\u201d she recalls. \u201cI saw an email supposedly from Uber asking me to update my account details. It was an incredible coincidence that I was in an Uber at the time, so without hesitating, I clicked on it.\u201d<\/p>\n\n\n\n<p>This incident underscores a crucial point: even the most security-conscious individuals can be caught off guard when distracted or overwhelmed, a state of mind many employees regularly experience.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The human factor: Both vulnerability and strength<\/h3>\n\n\n\n<p>Recent studies reveal that at least <a href=\"https:\/\/www.ncbi.nlm.nih.gov\/pmc\/articles\/PMC7005690?utm_source=BusinessTech&amp;utm_medium=article&amp;utm_term=December+2024\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>14%<\/strong><\/a> of employees regularly click on phishing emails, with distractions accounting for <a href=\"https:\/\/www.statista.com\/statistics\/1253448\/employee-clicks-phishing-emails-by-reason\/?utm_source=BusinessTech&amp;utm_medium=article&amp;utm_term=December+2024\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>45%<\/strong><\/a> of these clicks. <\/p>\n\n\n\n<p>The human element remains a critical weak point in cybersecurity defences, but it can also be a powerful asset when adequately harnessed.<\/p>\n\n\n\n<p>Stephen Osler, co-founder and business development director at <a href=\"http:\/\/www.nclose.com\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Nclose<\/strong><\/a>, a provider of cybersecurity services, notes: \u201cTraditional email security measures often focus only on technological solutions, neglecting the crucial human aspect of cybersecurity. While spam filters and secure email gateways play a role, they\u2019re insufficient against modern cybercriminals\u2019 sophisticated social engineering tactics.\u201d<\/p>\n\n\n\n<p>Collard agrees, adding, \u201cIf you want to change human behaviour, you cannot rely on training alone. That is where phish testing plays a crucial role.\u201d <\/p>\n\n\n\n<p>However, she cautions against approaches that shame or instil fear in employees who fall for these tests. <\/p>\n\n\n\n<p>\u201cThe goal should never be to shame individuals who fail the test, as this can have negative consequences,\u201d she explains.<\/p>\n\n\n\n<p>Instead, Collard advocates for a more empathetic approach. \u201cAre staff feeling stressed and overworked? Are they going through financial difficulty? Knowing this will help organisations understand what\u2019s driving employees\u2019 risky online behaviour.\u201d<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Beyond traditional defences: The rise of AI and crowdsourcing<\/h3>\n\n\n\n<p>As cyber threats evolve, so too must our defence strategies. <\/p>\n\n\n\n<p>Innovative solutions are emerging that combine the power of artificial intelligence with the collective intelligence of human users\u2014an approach known as crowdsourcing.<\/p>\n\n\n\n<p>\u201cCrowdsourcing enables users to report phishing campaigns faster than conventional methods,\u201d Collard explains. \u201cImagine tens of thousands of organisations sharing this sort of information. Imagine a blocklist where not just your users\u2019 reported phishing emails end up, but millions from all over the world.\u201d<\/p>\n\n\n\n<p>This global approach to threat intelligence is at the heart of new, sophisticated anti-phishing tools. One such solution is <a href=\"https:\/\/www.nclose.com\/knowbe4-partner\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>PhishER Plus<\/strong><\/a>, developed by KnowBe4.<\/p>\n\n\n\n<p>This lightweight Security Orchestration, Automation and Response (SOAR) product is designed to orchestrate phishing threat response and supercharge an organisation\u2019s email security defences.<\/p>\n\n\n\n<p>PhishER Plus combines robust machine learning-powered email analysis, prioritisation, inoculation, and blocklisting capabilities with a powerful global threat feed for proactive anti-phishing protection. <\/p>\n\n\n\n<p>The system is powered by a triple-validated global threat feed that automatically blocks phishing attacks before they reach users\u2019 inboxes.<\/p>\n\n\n\n<p>\u201cPhishER Plus serves as your phishing emergency room,\u201d says Collard. \u201cIt helps your internal or external InfoSec and SOC teams to identify the most dangerous threats more quickly while automating the handling of the 90% of reported emails that are not threats.\u201d<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">A multi-layered approach to cybersecurity<\/h3>\n\n\n\n<p>While innovative tools like PhishER Plus represent a significant advancement in the fight against phishing, they are most effective as part of a comprehensive, multi-layered approach to cybersecurity.<\/p>\n\n\n\n<p>\u201cNo single solution can provide complete protection against today\u2019s sophisticated cyber threats,\u201d Osler adds. \u201cOrganisations need to implement a combination of technological defences, employee training, and proactive threat intelligence to create a robust security posture.\u201d<\/p>\n\n\n\n<p>Collard concurs, adding, \u201cThe future of phishing defence lies in the synergy between AI, human intelligence, and continuous education. By promoting a culture of cybersecurity awareness and using advanced tools, organisations can greatly decrease their risk of falling victim to phishing attacks.\u201d<\/p>\n\n\n\n<p>&#8220;As phishing tactics grow more advanced, relying on spam filters alone is no longer enough. Instead, organizations need a holistic, proactive approach to email security that combines the latest technology, human insight, and collective intelligence. When cybersecurity is embraced as a cultural value, employees feel part of something bigger, aligned with a mission to protect each other and the organization. It\u2019s only through this cultural shift that companies can stay ahead of the phishing threat.&#8221;<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/www.nclose.com\/knowbe4-partner\/\" target=\"_blank\" rel=\"noreferrer noopener\">For more information on KnowBe4\u2019s PhishER product or to sign up, click here.<\/a><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Sophisticated cyberattacks are outpacing traditional email security measures, leaving organisations vulnerable to data breaches and financial losses.<\/p>\n","protected":false},"author":57,"featured_media":803093,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10459],"tags":[8556,16758,21196,1720,375,21195,21194],"class_list":["post-803089","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industry-news","tag-ai","tag-knowbe4","tag-phisher","tag-phishing","tag-security","tag-stephen-osler","tag-svp"],"_links":{"self":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/803089","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/users\/57"}],"replies":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/comments?post=803089"}],"version-history":[{"count":6,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/803089\/revisions"}],"predecessor-version":[{"id":804429,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/803089\/revisions\/804429"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/media\/803093"}],"wp:attachment":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/media?parent=803089"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/categories?post=803089"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/tags?post=803089"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}