Intelligent CISO Issue 72 | Page 64

BUSINESS surveillance

Phishing attacks are increasingly sophisticated , and although they ’ re not necessarily more prevalent , these advanced threats are getting through traditional defenses .
intervening when the risk appears with clear explanations which ultimately increase the individual ’ s understanding .
Traditional email security solutions tend to offer quarantine for admins to sift through and static prompts to prevent incidents . But if users are alerted to treat all external emails with caution , their heuristics will apply to all . ‘ Availability ’ will come into play if the individual is rarely targeted with phishing attacks , as they ’ ll be more likely to assume the email is legitimate like it seemingly always is . Or a business email compromise attack , which imitates a legitimate request extremely well , could see the recipient put it in the same category automatically , as that ’ s what they do with all requests of that nature .
Outbound isn ’ t safe either . Generic pop-ups lead to click-fatigue and continuing past a prompt easily sinks into routine . As these tend to be unspecified messages , the user won ’ t be informed whether the prompt occurred because of lack of knowledge , incorrect rules , or lapses of memory . In fact , they won ’ t normally recognise a mistake has been made !
Nudges are essential , but they must be informative , relevant , timely and distinctive to have an impact .
64 WWW . INTELLIGENTCISO . COM