Germany Breaking News | Top Stories | Political | Business | Entertainment | Sport Exit Reader Mode

Unfortunately, awareness alone won’t do it: Successful phishing defense requires a layered approach

Phishing: The most popular brands used to target your data
Just got an email warning that you are locked out of an important account? It might be cyber criminals trying to trick you.

Forrester thought leader Chase Cunningham discusses in a complimentary webinar how to implement and maintain Zero Trust with the Zero Trust eXtended Framework.

Despite being one of the oldest tricks in the book, phishing remains one of the primary methods attackers use to target end-users and infiltrate enterprises. Security and risk programs, however, don’t always prioritize phishing prevention enough. Phishing exploits still work in 2019 because hackers are studying their targets and employing new techniques to get past email content security filters.

Once a malicious email lands in front of an employee, even your most security-conscious employees can be tricked by clever social engineering. Phishers often use psychological tricks to get users to take action that they might not usually take, preying on an employee’s desire to be helpful or their instinct to do what an authority figure tells them to do.

Training alone can’t protect you from phishing. Phishing prevention requires a layered approach that combines technical controls and user education. Each layer in this strategy acts as a safety net in case the layer on top of it fails. These layers are:

This post was written by VP, Research Director Joseph Blankenship, and originally appeared here.


Article source: https://www.zdnet.com/article/unfortunately-awareness-alone-wont-do-it-successful-phishing-defense-requires-a-layered-approach/#ftag=RSSbaffb68