It’s just a quick take on the CrowdStrike situation, but worth reading because wider training modules, that go beyond your IT department, may well head off some of these types of attack before they do too much damage.
Niall McConachie, regional director (UK & Ireland) atYubico comments on how bad actors take advantage of events like this, and explains how organisations and individuals can ensure they’re protected against subsequent phishing attacks:
“Cyber criminals often capitalise on events when a lot of confusion and panic is prevalent, such as Friday’s global IT outage. In the hours and days following the incident, bad actors have been tweaking their existing attack methods to take advantage of the situation. For instance, hackers have already adjusted their phishing campaigns to offer information about the outage, promising to help those impacted – providing cyber criminals with a way of hacking individuals and organisations.
“The spike in phishing activity associated with the incident highlights the urgent need for better cybersecurity training for employees and customers alike so that both know how to spot and report phishing attacks to keep both themselves and the business secure. Most employees do not receive frequent cyber security training, which leaves them and their organisations vulnerable.
To establish an effective cybersecurity awareness training programme, organisations must ensure this is properly resourced – as opposed to treating it like a collateral duty – in addition to frequently updating the training with the latest information on methodologies being used by hackers. This will reduce the vulnerability of employees facing increasingly sophisticated phishing attacks and, in turn, make services safer for customers to use – keeping the sensitive data of the business and customers secure.
“In conjunction with regular and up-to-date security training, organisations should consider implementing phishing-resistant authentication solutions. Basic username and password and weak multi-factor authentication (MFA) methods alone are far too easy for attackers to circumvent, allowing unauthorised access to online accounts and personal data.
Instead, phishing-resistant MFA, such as passkeys like physical security keys, is more secure, user-friendly and can be used for both personal and professional data security. This is because it requires something you know (a PIN), something you have (the security key), and something you are (a physical touch of the key when prompted to gain access). These tools are especially important as cyber attacks relating to the global IT outage are unlikely to be limited to companies, but will also directly target customers and employees too.”
20 years experience as a journalist and magazine editor. I'm your contact for press releases, events, news and commercial opportunities at Insurance-Edge.Net
Select Car Leasing sent us some interesting data recently, and it seems the government of Estonia is flush with cash. In the UK you can get a £2500 bri-sorry, grant, to ditch your petrol/diesel car […]
OK, we missed this one in January, but just in case you missed it too, here’s the latest on Quick Sure Insurance Ltd, a Gibraltar-based insurance company, which was declared in default on Friday 24 […]
A British-based research project into the latest autonomous vehicle technologies has successfully completed a 230-mile self-navigated journey on UK roads. The project, HumanDrive, is jointly funded by UK government through the Centre for Connected and […]
Be the first to comment