Phishing awareness educates candidates and employees on how to identify and report suspected phishing attempts to protect themselves and the company from cyberattacks, hacking, and others who want to steal data from your organization. Technically, it is impossible to prevent phishing, so phishing awareness comes into play. Awareness can take different forms. We all need to work on how we can educate employees to reduce the risk.
The most common types of phishing include generalized, spear, voice, and in-person phishing. Generalized phishing often involves email or text asking for confidential details, posing as some popular companies. Spear phishing is advanced and dangerous. It involves personal information that is readily/publicly available. Hackers use this data for phishing purposes. As the name indicates, voice phishing uses a professional voice as an asset when trying phishing. They use authentic-sounding voices of real people. In-person phishing typically includes the way of talking, where the hacker/lousy actor tries to retrieve confidential data from the person by making an excellent start to communication. We all should always be alerted by strangers when sharing confidential details, including passwords, PINs, identity numbers, etc.
We must all be aware of and alert to these kinds of phishing attacks and protect ourselves!
Employees should be trained for these phishing attacks before they happen and we lose data.
- Employees should be given training programs and education sessions. Platforms exist that give us a real-time phishing experience and help companies understand how employees react to phishing emails. Our company, too, has a phishing tool that is typically designed for phishing awareness.
- Continuous training is yet another approach. The company must maintain phishing awareness training programs over time, and employees should co-operate for the same.
- Identifying high-risk employees is quite important. Every company has 2 types of high-risk employees – Employees who fail to recognise a risk/threat and employees who are prone to have attractive deals
Four common ways to avoid phishing attacks include:
- Protect your system by using the latest security software
- Update your mobile by setting software to update automatically
- Protect your accounts by using MFAs
- Backup your data
If you come across an email or text which is weird:
- Don’t open
- Delete it immediately to prevent yourself from accidentally opening the message in the future.
- Do not download attachments which are attached to the message.
- Never click suspicious links
Five ways to detect phishing emails:
- · Urgent action demand requests from strangers
- · Poor grammar and spelling errors in the attachment
- · An unfamiliar greeting which is weird
- · If a person requests login credentials, payment information or sensitive data.
- · Offers that are too good to be true.
- · Suspicious or unsolicited files/attachments
- · Inconsistent email address
Some red flags of Phishing attacks:
- Urgent/threatening language
- Sensitive information request
- Any offer which is too good and not possible
- Unexpected emails
- Unprofessional design
- Suspicious attachment
- Incorrect but similar email address

