


As the pandemic started, the phishing attempts rose by 90 percent. Among those impacted by the attacks were the financial services sector, the healthcare sector, and the insurance sector. During the pandemic, attacks are more likely to target C-level and executive secretaries rather than employees. Although the world is currently experiencing an endemic, phishing attacks never seem to abate. Instead, it began focusing on particularprofessions or employees of the government.
In 2020, phishing attacks caused 36 percent of data breaches, espionage, and fraud. Despite the company’s best efforts to reduce financial loss, increase awareness, and address rational internal gaps, their staff still fall prey to phishing attacks. Despite awareness being done by the company governance team, there are situations where staff still fall victim to phishing attacks, fraud, espionage, data breaches and so on.
Ensure Awareness And Effectiveness
Governance needs to look into the potential gap and improve its processes. As regulators have begun penalising businesses heavily for failing to protect consumer and employee personal information from cyberattacks (inthis case, specifically phishing attacks), they have started to impose higher fines and stricter controls to ensure assurance. Regulators started to ask the industries for assurances of conformity and compliance.
To ensure that this event causes the minimum damage and is not penalised by the regulatory, the governance team, which in this case will be the IT risk management team and IT security governance, will need to collaborate for good strategic decision making through planning, developing, creating, and assessing the effectiveness of awareness in a company. To kick-start the plan is to educate which can be painful as it requires education across the company.
using as many platforms available within the company can make it easier.
With this, we started by blasting email awareness, physical posters, face-to-face training with all levels of position in the company, e-learning systems, and videos.
The second is to have buyouts from all the stakeholders in a bank. This could be the second pain point. Negotiation and a streamlined process are the methods we adopt for this, and our strategy is to focus on “supporting each other”. This approach can ease the process.
The next step will be approaching the senior management team and providing them recommendations by using a top-to-bottom approach theme, wherebyeveryone in the company bears responsibility for protecting the company’s data and the ROI’s are based on regulatory fines or based on real case studies.
Fun Facts: - In some countries, regulators impose higher fines on companies that encounter data breaches due to cyber attacks (e.g., data leakage, hacking, or mismanagement). They face fines of up to $500,000 per line of customer and staff PII if breached.
“Despite awareness being done by the company governance team, there are situations where staff still fall victim to phishing attacks, fraud, espionage, data breaches and so on”
Create and spread a slogan about security and risk culture on orientation or induction days and during monthly security and risk awareness events. The proposed slogan is, “If we can safeguard our own sensitive information, we can certainly protect our customer’s sensitive information.” In order to win over the hearts of management and personnel, use the phrase as a platform. Involving everyone (company employees and senior management) in the organisation’s broad awareness improves the effectiveness of the awareness.
Things To Be Considered Before A Phishing Drill
1. Identify departments, staff, branches, vendors, senior management or secretaries that are at high risk to the phishing attack.
2. Identify point of entry for phishing attacks to start. Is it via email, telephones, mobile phone or social media?
3. Identify scenarios for the phishing attacks? Did it come together with an email attachment; email posing as a senior management/chiefs/board members requiring urgent information from secretaries or staff; emails posing as friends/family/colleagues, shared holiday photos, requests for emergency loans of money, requests for bank accounts to purchase some items online; imposter of law enforcement/legal company for tax evasion/summons/false claim of crime/false claim of illegal purchase etc.
4. Choose the apt timing in releasing the phishing attack - either during receiving bonus, during salary week or during festivals holidays or during the school holidays.
5. Communications and data collections with the respective stakeholders were made. This is provided with a timeline on data collected based on complaints from senior management, staff at the office, branches, vendors and secretaries.
6. Schedule weekly updates with the stakeholders to ensure that there are no hiccups during the drill activity. This is to ensure a smooth process during the drill activity.
7. Improvement of process in preventing data leakage, encryptions enhancement, and IPS enhancement based on the gaps identified during the implementation of phishing drill and after the phishing drill activity.
As for the post mortem, discuss together with the involved stakeholders to have further understanding and agreement on the lesson learned and findings. Have a few rounds of discussion and commitments in remediating the findings from the identified stakeholders.
There will be the stubborn ones and the senior management normally will ask the “curveball” questions. The expected questions will be in addressing the repeating offenders such as – “Are there any impose of penalties”, etc?
Here are a few options that can be chosen. In these situations, there are two options that can be picked – non-extreme option or the extreme option.
Option Of Non- Extreme:
1. Provide three strike rules. First strike training, second strikes training together with simple quiz, and if passed will receive a small gift (e.g. voucher, gift card, etc). And if they pass the third strikes training, they win similar gift and certifications.
2. Repeating offenders will be facing penalties for each failure in the phishing drill. The penalty money will be part of donations to the company CSR or charity.
3. If the repeating owner still fails in the next round of phishing drill, then the extreme penalties will be imposed.
Option Of Extreme:
1. Put as a part of KPI, who failed with the phishing drill, it will affect their annual performance review. KPI of choice is normally 5 to 10 percent.
2. Shame them throughout the company bulletin.
3. Receive warning letter from HR.
After picking the consequence options, share the outcomes, remediation, lessons learned and step-forward plans, and selected penalty by tabulating it to the senior management and seek their advice, approval and notifications on the phishing drill results. Then take the outcome to improve and to see the growth suggest doing it annually with the phishing drill activity