Youâve set up your organizationâs cybersecurityâconsidering firewall, anti-virus, DNS and web filtering, your wireless network⌠and on and on. Youâve made all the difficult IT security decisions to protect your business, but just one well-meaning employee that clicks one malicious link in one little email can open the door for a hacker to defeat all your defenses.
As a small business, youâre not likely to get targeted. Right?
Nope.Â
Hackers look for the easiest targets, and small organizations with limited IT budgets are more likely to fall prey to a cyber attack than a big enterprise. According to the Verizon Data Breach Investigations Report, more than three-quarters of the companies targeted by malicious hackers are small.
Donât worry. That doesnât mean you need to double your IT budget.
Protecting your users by teaching them how to avoid email attacks will make a difference right away.
Email is a hackerâs favorite weapon. Symantec reports that more than 400 businesses are targeted by spear-phishing emails every day. And those emails often look very real to an untrained reader.
What is security awareness training? How does it work?
Security Awareness Training is a program designed for non-technical computer users that trains them to spot the signs of a malicious emailâso they donât click a link that could ruin everyoneâs day.
Security Awareness training can also cover topics like password security, safe web browsing, and mobile device security so your employees stay up-to-date and vigilant about protecting their organization. And because cybersecurity threats change all the time, the training modules are updated regularly by expert cybersecurity teams. The program is automatedâregularly testing employees through simulated phishing campaigns and reminders to take new training as itâs released.
When an organization adds Security Awareness Training to its IT services, the very first step is a simulated phishing attack to get a baseline score of the companyâs âphish proneâ percentage. Most of our clients are surprised at how many of their users click phishy links. Then the training begins.
How do we know it works?
I spoke with one of our clients in Charlotte whose phish-prone percentage started at 34% and dropped to just 6% after beginning Security Awareness Training. He shared that his end-users now forward him suspicious emails from vendors or customers that donât seem legitimate. And in many cases when they have followed-up, the email was the result of a hacker. He says the frequency of the training test emails keeps his users ready and alert all year.
One of our Raleigh-based clients, saw their phish-prone percentage fall from 51% to 2% after beginning the training. As a recruiting firm, their end-users send and receive a LOT of email. When Personify started the program, none of their users wanted to end up as the one person to fall for a phishing email. The whole organization really got into it, and their results show it. Personify users still forward suspicious emails to get checked out, staying constantly vigilant.
Security awareness training may be the missing piece to your cybersecurity preparation.
Reach out to your WorkSmart Account Manager or contact our sales team at [email protected] for more information.