Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Out of your Control: Phishing Detection and Prevention
Articles

Out of your Control: Phishing Detection and Prevention

ISBuzz TeamBy ISBuzz TeamNovember 17, 2015Updated:December 10, 20153 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Phishing Detection and Prevention
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Organizations can fall into two categories: Those who have been successfully phished, and those that will be successfully phished. Some experts may be bold to say there is nothing more certain in life than death, taxes, and phishing.

Wisegate, a peer-driven IT research company, recently held a roundtable discussion on the topic of phishing. An internal poll showed 100 percent of the participants had been previously phished, 80 percent successfully. The question, “Can increased user awareness and/or improved technology successfully detect and prevent phishing?” has since been asked in reports, surveys, and one-on-one interviews with CISOs. Unfortunately, the answers and conclusion are not promising.

User awareness training can only do so much. It can be relatively simple to train employees to be wary of emails constructed with poor grammar, typographical errors, and strange URLs, but it is more difficult, impossible even, to teach anyone to detect a personally targeted email.

This roundtable also found a dearth of effective technology to prevent phishing. As soon as anything proves effective, phishers simply adapt their techniques. Technology cannot outpace hackers.

What can be done? Not much, to be honest. The roundtable contributors offered several individual recommendations, but phishing is a global problem that requires a global solution. This form of cyber attack needs better international threat intelligence sharing, and globally harmonized legal definitions and sanctions. Many law enforcement agencies are making strides toward this, but a truly international legal treaty has yet to be seen.

One avenue that may be worth exploring is a publicly available master database of dirty URLs, but this would require altruism above the norm. The Federal Bureau of Investigation, as well as other national law agencies, would need to combine their intelligence with competing private security firms, who actually base their products on their own proprietary intelligence. It would be to serve the greater good and be extremely difficult to coordinate. But not impossible.

While CISOs know they cannot prevent phishing, they are not downhearted. They instead seek to reduce the risk to an acceptable level.

“If I can increase the detection of phishing emails from, say 10 percent to 50 or 60 percent, then I consider that a success,” one CISO explained. “It is then up to me to have enough other internal controls to catch anything that gets through.”

The CISOs questioned in the roundtable did share their own best practices, including :

  • Sandboxing: A security measure that allows code to be executed in an isolated environment. This allows users to safely test suspect malware.
  • In-Line Stripping: This automatically removes links within emails and optionally replaces them with a link to a company warning or training page.
  • Behavioral Practices: One CISO shared relative success to thwarting phishing attempts by encouraging staff to forward emails with questionable links to the security team for evaluation. The CSIO has no formal analytics for this approach, but it is rooted in the unscientific security policy known as ‘paranoia pays.’ The success depends on the staff’s own paranoia.

One thing is for certain; phishing is an issue that will not be resolved soon.

You cannot stop phishing. There is no silver bullet. But you can try to catch as many phishes as possible, and trust your other security controls to help mitigate other risks.[su_box title=”About Wisegate” style=”noise” box_color=”#336588″]Wisegate logoWisegate is a member-based IT research company that serves the industry’s most senior-level IT practitioners. Wisegate’s editorial team keeps a pulse on what matters to IT via its members, and publishes member-based advice, best practices and collaborative insights for the IT industry’s most pressing and important issues. [/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}