Human hubris is difficult to shake — even in risky situations that could result in a cyberattack.
In fact, more than two-thirds (68%) of non-IT employees are troublingly over-confident in their ability to detect a phishing email that could lead to a ransomware attack, according to a new report out today from Veritas Technologies.
However, report findings show that confidence ranges based on age (with, surprisingly, younger workers more iffy on their abilities to identify phishing) — and, whether they think an email is trustworthy or not, employees are most likely going to open it anyway.
“No one likes to think of themselves as an easy ‘mark,’” Matt Waxman, Veritas’ SVP and GM of data protection, told SDxCentral. “But the reality is that cybercriminals are exceptionally good at what they do. And with the help of advancements in technology, almost all of which can be used for both good and bad, including AI, they’re only going to get better.”
Ransomware is common, devastating and the way in It’s estimated that 59% of organizations were hit by a ransomware attack in 2023. And victims continue to pay out: Last year, in fact, ransomware payments set an all-time record, exceeding $1 billion.
Respondents to the Veritas survey affirmed this trend, too, with the majority (73%) reporting an increase in ransomware attacks against their organizations over the past six months.
“The reality is that ransomware attacks are extremely common, they often are absolutely devastating, and phishing is still the foremost way hackers infiltrate organizations,” said Waxman.
While many respondents to the Veritas survey were confident in their ability to spot phishing, they were still likely to open suspicious emails if they seemed to be coming from a friend (63%) or colleague, or appeared to be related to employer benefits (60%), online orders (56%) or financial institution.
Interestingly, though, the youngest respondents (those aged 18 to 24) were not as confident in their ability to spot suspicious emails as those in older age groups (25 to 44). Presumably, Waxman pointed out, they would be more tech savvy and confident.
But that isn’t necessarily a bad thing. “In fact, recognizing that they could be duped probably helps in increasing their skepticism and thereby actually improves their ability to spot and avoid a phishing attack,” he said.
Two factors may be behind that lower confidence level, Waxman noted: First, younger workers have less experience that naturally makes them a little unsure of themselves. Second, because they are “tech-savvy digital natives,” they may have an “almost inherent understanding” of the impact cutting-edge technologies like AI have for both good and bad applications.
Looking beyond telltale signs Employees continue to look for telltale signs of phishing, such as misspelled words (81%) or poor grammar (82%), according to Veritas.
This means that training has sunk in, and “that’s a great thing,” said Waxman. However, hackers are getting better and better at eliminating those once telltale giveaways.
“At its core, phishing is all about using social engineering to psychologically manipulate people — that’s a very hard thing to train someone against,” he said.
So, organizations have relied heavily on teaching people how to spot traditional warning signs. But they need to go beyond that to instill a “greater sense of overall skepticism” and more of a zero-trust mentality in their employees, said Waxman.
Because what happens when those warning signs aren’t there, he posited? For instance, today’s hackers are using multi-stage spear-phishing tactics (that is, aimed at a specific person or group) coupled with generative AI that are incredibly convincing, even for those well-trained and inherently skeptical.
Waxman laid out the scenario: “Think about it — with five minutes on your company’s website, five minutes on LinkedIn and five minutes in a generative AI tool, even a novice cybercriminal could have your work email address, your job function, your colleagues’ names and a pretty convincing, well-written email asking you to click on a link to review something.”
Ransomware concern is low Surprisingly despite it being everyday news, employees aren’t that concerned about ransomware. Not even half (49%) of survey respondents were worried about kicking off an attack through their work email.
“General non-IT employees are likely not as concerned about ransomware as they should be because it’s out of sight, out of mind,” said Waxman. “They may have heard about it on a nightly news broadcast and glanced at an email from their company’s security department, but is that enough to really convey how rampant the problem is?”
At the same time, perception of hackers continues to center around the faceless, hoodie-wearing, basement-dwelling outcast stereotype (with more than half of respondents affirming this). Still, workers are beginning to understand that hackers are increasingly operating as larger syndicates, and IT professionals in particular (81% per the survey) understand that hackers are using AI to further professionalize their work.
The good news:
- 73% of IT professionals report that they have updated their employee security training;
- More than 80% say their organizations have invested in technologies including AI to counter attacks;
- 66% report that their organizations are implementing more frequent security audits and 62% say they are incorporating stricter data access controls.
Waxman noted: “It’s critical to start approaching this challenge with as much of a recovery mindset as any other: When it happens, what data needs to be recovered first? When it happens, what systems need to be back online fastest? When it happens, how do we get back to business quickly?”
Comments