Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Cyber-awareness Training And Spoofing Protection Mandatory
Articles

Cyber-awareness Training And Spoofing Protection Mandatory

Rob.PocockBy Rob.PocockDecember 6, 2022Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Cyber-awareness Training
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Cyber-awareness Training And Spoofing Protection Mandatory Depending upon your line of work, there are numerous mandatory training courses which form an essential and everyday part of the job. If your role is physical, for example, then health and safety training is the norm. Food hygiene training is required for anyone working with consumables, as is DSE training for those working in front of a computer screen.

No matter the course, they are all designed to educate and safeguard employees on the hazards they may face during the working day. To minimize the risks to themselves, others and the wider company. However, one of the biggest risks facing almost every business today is not always afforded the same dedicated and essential training.

Ever-growing digitalisation and reliance on technology is a cybercriminal’s playground. New tactics are being developed every day to dupe unsuspecting employees into giving away confidential information or clicking on something they shouldn’t, putting both themselves and the business at increased risk. As a result, phishing attacks and domain spoofing have now become one of the biggest, if not the biggest, risks to UK organisations and their employees – with phishing alone accounting for 83% of attack vectors in a recent 2022 Cyber Security Breaches Survey.

Much like understanding how lifting a heavy box correctly can prevent injury, an increased awareness of the threat landscape and how to spot phishing attacks. Example, can prevent employees giving away sensitive information or clicking on a seemingly legitimate link in an email which could have devastating consequences for the business.

With 95% of all cybersecurity issues traced to human error, according to the World Economic Forum’s Global Risks Report 2022, it begs the question – why isn’t cyber-awareness training mandatory for all businesses?

The risk of phishing attacks and spoofing

Social engineering attacks, including phishing and domain spoofing, can cause untold damage to both an organisation and individual. Recent cases affecting Dropbox, American Airlines and Interserve show not only the severe consequences of these types of attacks – both financial and reputational – but that no organisation is immune to human error.

With cybercriminals becoming more thorough in their attention to detail it can be hard to identify a real email from a rogue email. A quick glance at a domain address on an email before responding might not be enough, with spoofing tactics becoming a growing concern.

The email domain status of every company is publicly available so it’s not hard to duplicate and catch out unsuspecting victims. Indeed, a recent report from the Office for National Statistics (ONS) found that in a two-week period alone, more than 1,500 reports were made to the suspicious emails reporting service (SERS), run by the National Cyber Security Centre, about scam emails pretending to be legitimate energy rebates from Ofgem, the energy regulator.

With cybercriminals exploiting key world events and situations for their own gain, including the energy crisis. Football World Cup and the imminent Black Friday and Cyber Monday weekend, the human element can often undo the protection afforded.

Taking responsibility

Businesses have a responsibility to their staff, clients, and the supply chain to ensure vulnerabilities in their attack surface are addressed. When infiltrated, it’s not just a company’s data and IP that are targeted. Cybercriminals will often use passwords and usernames gleaned through phishing to steal client data to sell on or use an attack to further infiltrate the supply chain and access more lucrative targets.

Some of the key first steps to ensuring a robust approach to cybersecurity and to mitigate the risks caused by human error are to apply cyber-awareness training. Across the workforce and reduce the chance of your company being spoofed.

No matter what your industry or size of business, ensuring all employees from every department undergo regular training will provide the skills . There is no substitute for staying up to date with the latest risks.

Understanding the role played by strong passwords, how to identify phishing emails, and verify the legitimacy of a link or web address is just the start of the process. When combined with sophisticated security tools like enterprise firewalls, your business will reduce its attack surface.

Whilst the type of phishing threats and tactics deployed are numerous. There are some underlying tips which all employees should always follow to safeguard themselves and the wider business from attack:

  • Think before you click. If something seems suspicious or too good to be true, then it probably is.
  • Always check website security. Look for the ‘https’ in the URL and if a security warning message appears then go no further.
  • Remain vigilant when it comes to pop-ups. Most browsers will allow you to block pop-ups but they can slip through the net and be a phishing attempt.
  • Check for spelling mistakes in sender details or company domains in emails. A quick scan won’t always pick up the errors and are designed to catch you out.

Much like the cyberthreat landscape is always evolving, training is not just a one-hit-wonder. It needs to form part of employees working life, to regularly refresh their knowledge and have the insights needed to keep up to date with the latest threats. They can sift through emails with confidence and know the right approach to take if anything looks suspicious.

As phishing attacks become more sophisticated, cyber-awareness training needs to be prioritised, in order to strengthen the human firewall. Not only will this mitigate risks to businesses, it will also reduce the risk of supply chain attacks, as well as prevent any emotional damage to those that have been targeted.

By making cyber-awareness training mandatory, we can increase security across all organisations in the UK and continue to improve our response to national cyberthreats.

Rob.Pocock

Technical Director at Red Helix

    The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

    Share. Facebook Twitter LinkedIn Email Copy Link

    Related Posts

    New Phishing Kit Starkiller Defeats Multi-Factor Authentication

    February 23, 20264 Mins Read

    ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

    January 22, 20266 Mins Read

    What Happens after a Phishing Email Lands in Your Inbox?

    January 5, 20266 Mins Read
    ISB-Bora-Side-Bar

     
    ISB-Bora-Side-Bar
    Black ISB Logo

    Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

    X (Twitter) LinkedIn Facebook RSS

    Working With Us

    • About Us
    • Advertise With Us
    • Contact Us

    Write For Us

    • How To Contribute

    The Pages

    • Privacy Policy
    • Cookie Policy
    • AI Policy
    • Terms & Conditions
    • Copyright Notice

    Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}