It’s just a quick take on the CrowdStrike situation, but worth reading because wider training modules, that go beyond your IT department, may well head off some of these types of attack before they do too much damage.
Niall McConachie, regional director (UK & Ireland) atYubico comments on how bad actors take advantage of events like this, and explains how organisations and individuals can ensure they’re protected against subsequent phishing attacks:
“Cyber criminals often capitalise on events when a lot of confusion and panic is prevalent, such as Friday’s global IT outage. In the hours and days following the incident, bad actors have been tweaking their existing attack methods to take advantage of the situation. For instance, hackers have already adjusted their phishing campaigns to offer information about the outage, promising to help those impacted – providing cyber criminals with a way of hacking individuals and organisations.
“The spike in phishing activity associated with the incident highlights the urgent need for better cybersecurity training for employees and customers alike so that both know how to spot and report phishing attacks to keep both themselves and the business secure. Most employees do not receive frequent cyber security training, which leaves them and their organisations vulnerable.
To establish an effective cybersecurity awareness training programme, organisations must ensure this is properly resourced – as opposed to treating it like a collateral duty – in addition to frequently updating the training with the latest information on methodologies being used by hackers. This will reduce the vulnerability of employees facing increasingly sophisticated phishing attacks and, in turn, make services safer for customers to use – keeping the sensitive data of the business and customers secure.
“In conjunction with regular and up-to-date security training, organisations should consider implementing phishing-resistant authentication solutions. Basic username and password and weak multi-factor authentication (MFA) methods alone are far too easy for attackers to circumvent, allowing unauthorised access to online accounts and personal data.
Instead, phishing-resistant MFA, such as passkeys like physical security keys, is more secure, user-friendly and can be used for both personal and professional data security. This is because it requires something you know (a PIN), something you have (the security key), and something you are (a physical touch of the key when prompted to gain access). These tools are especially important as cyber attacks relating to the global IT outage are unlikely to be limited to companies, but will also directly target customers and employees too.”
20 years experience as a journalist and magazine editor. I'm your contact for press releases, events, news and commercial opportunities at Insurance-Edge.Net
Latest Consumer Intelligence data shows that car insurance is rising at the same rate as the price of Heinz beans, council run car parking for diesel cars in Bath, or many other consumer goods. The […]
With employers looking to develop and improve the soft skills of their employees, nearly 300 of the 2020 Fortune 500 companies now offer in-house Toastmasters clubs to help build their employees’ communication, leadership, and public […]
MAPFRE has updated the calculation of its Solvency II position as on March 31, 2020, following a request from the General Directorate for Insurance and Pension Funds, and within the framework of the Recommendations on […]
Be the first to comment