Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - End-Users And The Enduring Challenge To IT Security
Articles

End-Users And The Enduring Challenge To IT Security

ISBuzz TeamBy ISBuzz TeamFebruary 25, 2014Updated:April 30, 20253 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
IT Security
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

SUNNYVALE, CA—A leading Internet security provider recently released a report revealing how attackers exploit end-users’ human flaws to undermine even the most secure cyber security systems.

You can read the newest study released by Proofpoint, Inc., entitled “The Human Factor,” here.

Among other things, the report notes how today’s APT-attacks are socially-engineered, sophisticated, and focused campaigns that prey on end-users’ curiosity.  One particularly efficient means of attack is Longline Phishing, in which attackers employ spear-phishing techniques and mass-customization to generate thousands of individualized, infected emails that largely go undetected by traditional security software.

Human behavior with respect to how end-users treat malicious emails is therefore important, for it reveals another side of cyber security other than system design.

“The Human Factor” presents a number of findings that could help shape the future of security on the web.  These include:

– 10% of users who receive an email containing a malicious link will click.  This percentage decreases to 1% in relation to “best-of-breed” companies that train their employees and create generally effective security systems.

– An overwhelming majority of people click on malicious links from their PCs and not from their mobile phones.

– Despite traditional recommendations that training repeat clickers of malicious links will diminish the number of intrusions, one-time clickers are responsible for as much as 40% of online security breaches.

– Nearly seven percent of users click on malicious links nearly a month after having received an infected email.

The report also found that emails posing as LinkedIn invitations are clicked on twice as much as any other template, including Order Confirmations and financial transactions.  This might help to explain other attacks such as last year’s campaign in which fake profiles displaying pictures of beautiful women attracted thousands of LinkedIn connections, mainly men, via the promise of jobs.

For more information on recent LinkedIn phishing scams, please click here.

In response to the findings presented above, Proofpoint recommends solutions that are similar to its Targeted Attack Protection software.  This product uses big data analysis and cloud architecture coupled with a “full lifecycle approach” to identify malicious emails, monitor their transmittal, and track how users engage with these emails.

But whether one purchases software from Proofpoint is not the point.  What is important about “The Human Factor” is that it reflects a greater reevaluation of the cyber security community:  end-users are human and make mistakes, which subsequently requires that security companies accept that breaches will occur.

That is not to undermine system security.  However, as users can and do negate secure system design by clicking on malicious links, security providers should create software that focuses on surveillance, particularly on analyzing historical email traffic and, when identified, malicious emails that may have gotten through security systems.

In today’s cybersecurity environment, training and system design must therefore be combined to account for the shortcomings of each and to respond to the increasingly diverse and sophisticated array of cyber threats facing system analysts.

David Bisson | @DMBisson

Dave BissonBio: David is currently a senior at Bard College, where he is studying Political Studies and writing his senior thesis on cyberwar and cross-domain escalation.  He also works at the Hannah Arendt Center for Politics and Humanities at Bard College as an Outreach intern.  Post-graduation, David would like to leverage his extensive journalism experience as well as his interest in computer coding and social media to pursue a career in cyber security, both its practice and policy.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}