【24h】

Analysing Simulated Phishing Campaigns for Staff

机译:分析模拟员工网络钓鱼运动

获取原文

摘要

In an attempt to stop phishing attacks, an increasing number of organisations run Simulated Phishing Campaigns to train their staff not to click on suspicious links. Organisations can buy toolkits to craft and run their own campaigns, or hire a specialist company to provide such campaigns as a service. To what extent this activity reduces the vulnerability of an organisation to such attacks is debated in both the research and practitioner communities, but an increasing number of organisations do it because it seems common practice, and are convinced by vendors' claims about the reduction in clickrates that can be achieved. But most are not aware that effective security is not just about reducing clickrates for simulated phishing messages, that there are many different ways of running such campaigns, and that there are security, legal, and trust issues associated with those choices. The goal of this paper is to equip organisational decision makers with tools for making those decisions. A closer examination of costs and benefits of the choice reveals that it may be possible to run a legally compliant campaign, but that it is costly and time-consuming. Additionally, the impact of Simulated Phishing Campaigns on employees' self-efficacy and trust in the organisation may negatively affect other organisational goals. We conclude that for many organisations, a joined-up approach of (1) improving technical security measures, (2) introducing and establishing adequate security incident reporting, and (3) increasing staff awareness through other means may deliver better protection at lower cost.
机译:为了试图停止网络钓鱼攻击,越来越多的组织运行模拟网络钓鱼活动,以培训他们的员工不要点击可疑链接。组织可以购买工具包来制作并运行自己的竞选活动,或聘请专业公司作为服务提供此类活动。此活动在多大程度上减少了组织对这些攻击的脆弱性,这些攻击在研究和从业者社区中辩论,但越来越多的组织所做的,因为它似乎普遍做法,并被供应商的索赔令人信服的责任令人信服这可以实现。但大多数情况都不知道,有效的安全性不仅仅是减少模拟网络钓鱼邮件的点击,即运行此类广告系列的许多不同方式,并且存在与这些选择相关的安全性,合法和信任问题。本文的目标是为组织决策者提供制定这些决定的工具。仔细审查所选择的成本和福利揭示了可以运行法律兼容的运动,但它是昂贵且耗时的。此外,模拟网络钓鱼运动对员工自我效力和信任组织的影响可能会对其他组织目标产生负面影响。我们得出结论,对于许多组织,(1)提高技术安全措施,(2)介绍和建立充足的安全事件报告,(3)通过其他手段提高员工意识的介绍和建立适当的安全措施可能会以较低的成本提供更好的保护。

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号