• Latest
  • Trending
  • All
  • Market Updates
  • Cryptocurrency
  • Blockchain
  • Investing
  • Commodities
  • Personal Finance
  • Technology
  • Business
  • Real Estate
  • Finance
Employees learn nothing from phishing security training, and this is why

Employees learn nothing from phishing security training, and this is why

September 25, 2025
BABA, LAC, FCX, QURE and more

Stocks making the biggest moves midday: MIR, FCX, KMX

September 25, 2025
HSBC Claims Quantum Breakthrough, Should Crypto Holders Be Alarmed?

HSBC Claims Quantum Breakthrough, Should Crypto Holders Be Alarmed?

September 25, 2025
Soft Manager – Trading Ideas – 5 August 2025

Why 90% of ‘AI EAs’ Are Fake (And How to Detect Them) – My Trading – 25 September 2025

September 25, 2025
Mexican central bank cuts rates by 25 bps, as expected

Mexican central bank cuts rates by 25 bps, as expected

September 25, 2025
Hormel Foods Corporation (HRL) Stock Forecasts

Daily Spotlight: Fed's Favorite Inflation Indicator

September 25, 2025
France’s Total cuts buybacks in fresh sign of oil price pressures

France’s Total cuts buybacks in fresh sign of oil price pressures

September 25, 2025
US Dollar Surges as US Jobs Data Pressures Crypto

US Dollar Surges as US Jobs Data Pressures Crypto

September 25, 2025
EURUSD Technicals: EURUSD falls to new lows and looks toward the midpoint target

EURUSD Technicals: EURUSD falls to new lows and looks toward the midpoint target

September 25, 2025
Bitcoin Analyst Warns BTC Short Squeeze in Mid-Week Reversal; $120K Next?

Bitcoin Analyst Warns BTC Short Squeeze in Mid-Week Reversal; $120K Next?

September 25, 2025
Oracle is replacing CEO Safra Catz with two co-CEOs

Oracle is replacing CEO Safra Catz with two co-CEOs

September 25, 2025
Stocks making the biggest premarket moves: INTC, ORCL, LAC, OPEN

Stocks making the biggest premarket moves: INTC, ORCL, LAC, OPEN

September 25, 2025
Is your Roku TV spying on you? It’s possible, but here’s how you can easily stop it

Is your Roku TV spying on you? It’s possible, but here’s how you can easily stop it

September 25, 2025
Friday, September 26, 2025
No Result
View All Result
InvestorNewsToday.com
  • Home
  • Market
  • Business
  • Finance
  • Investing
  • Real Estate
  • Commodities
  • Crypto
  • Blockchain
  • Personal Finance
  • Tech
InvestorNewsToday.com
No Result
View All Result
Home Technology

Employees learn nothing from phishing security training, and this is why

by Investor News Today
September 25, 2025
in Technology
0
Employees learn nothing from phishing security training, and this is why
492
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter


fishing hooks holding arrows

MicroStockHub/iStock/Getty Photos Plus

Comply with ZDNET: Add us as a most well-liked supply on Google.


ZDNET’s key takeaways

  • Phishing is a serious and rising menace to companies.
  • However phishing consciousness coaching has a minimal success fee.
  • Researchers urge organizations to spend money on countermeasures.

A brand new examine has confirmed what many people suspected — worker phishing coaching is just not well worth the effort. 

The examine, performed by UC San Diego Well being and Censys researchers, discovered that phishing-related cybersecurity coaching packages had no impact on whether or not or not staff have been duped by phishing emails. 

After analyzing the outcomes of 10 completely different phishing e mail campaigns despatched to over 19,500 staff at UC San Diego Well being over eight months, the researchers discovered “no vital relationship between whether or not customers had just lately accomplished an annual, mandated cybersecurity coaching and the chance of falling for phishing emails.”

Additionally: Battered by cyberattacks, Salesforce faces a belief drawback – and a possible class motion lawsuit

The staff additionally investigated whether or not embedded phishing coaching — when organizations ship simulated phishing emails to see if their staff will fall for them — was efficient. Merely put, it wasn’t, and there was nearly no distinction in failure charges for individuals who accomplished the coaching versus those that didn’t. The teams have been separated by a decreased chance of falling for a phishing e mail of solely 2%. 

That is particularly regarding, on condition that phishing was discovered to be the main reason behind ransomware this 12 months, fueled by infostealers and the abuse of AI instruments, based on a brand new SpyCloud Id menace report. Phishing was additionally essentially the most reported assault vector by companies taking part within the analysis and was cited by 35% of affected organizations — up from 25% in 2024.

What’s phishing? 

Phishing is a continuing scourge and is a menace that impacts people, SMBs, and enterprises alike. Phishing campaigns usually take the type of spray-and-pray fraudulent emails or focused messages designed to elicit curiosity, panic, or worry of their recipients. 

By crafting messages that encourage worry or urgency, cybercriminals hope that their victims won’t take a step again and assume rationally, however will, somewhat, panic-click a button or hand over delicate info that can be utilized in id theft, to conduct fraudulent transactions, or to be used in broader cybercrime. 

Additionally: Scammers are actually faking the FBI’s personal web site – this is the right way to keep secure

When the menace is so critical, and a phishing-related breach can result in extreme penalties for a corporation — together with information theft, destruction, monetary penalties, ransomware deployment, and reputational hurt — corporations, naturally, will search for options. 

Phishing coaching packages are a preferred tactic geared toward decreasing the danger of a profitable phishing assault. They might be carried out yearly or over time, and sometimes, staff can be requested to look at and be taught from tutorial supplies. They might additionally obtain pretend phishing emails despatched by a coaching companion over time, and in the event that they click on on suspicious hyperlinks inside them, these failures to identify a phishing e mail are recorded. 

Why phishing coaching does not work

UC San Diego Well being and Censys researchers mentioned material was vital to the success of a phishing e mail of their examine. For instance, barely anybody clicked a hyperlink to replace their Outlook password, whereas over 30% of contributors clicked on a hyperlink in an e mail pretending to be an employer replace to trip insurance policies. 

The longer a phishing scheme continued, the extra doubtless an worker was to click on a fraudulent hyperlink, rising from 10% of contributors in month one to over 50% by the eighth month.

Additionally: This 2FA phishing rip-off pwned a developer – and endangered billions of npm downloads

“Taken collectively, our outcomes counsel that anti-phishing coaching packages, of their present and generally deployed kinds, are unlikely to supply vital sensible worth in decreasing phishing dangers,” the researchers mentioned.

In accordance with the researchers, a scarcity of engagement in trendy cybersecurity coaching packages is in charge, with engagement charges usually recorded as lower than a minute or none in any respect. When there isn’t any engagement with studying supplies, it is unsurprising that there isn’t any influence. 

Potential options

To fight this drawback, the staff means that, for a greater return on funding in phishing safety, a pivot to extra technical assist might work. For instance, imposing two or multi-factor authentication (2FA/MFA) on endpoint units, and implementing credential sharing and use on solely trusted domains. 

Additionally: How passkeys work: The whole information to your inevitable passwordless future

That is to not say that phishing packages do not have a spot within the company world. We must also return to the fundamentals of partaking learners. As a former trainer, I might counsel that tabletop discussions, in-person seminars, and even gamification might present the lacking hyperlink between coaching and constructive outcomes. 



Source link

Tags: employeesLearnphishingSecurityTraining
Share197Tweet123
Previous Post

Why 90% of ‘AI EAs’ Are Fake (And How to Detect Them) – My Trading – 25 September 2025

Next Post

HSBC Claims Quantum Breakthrough, Should Crypto Holders Be Alarmed?

Investor News Today

Investor News Today

Next Post
HSBC Claims Quantum Breakthrough, Should Crypto Holders Be Alarmed?

HSBC Claims Quantum Breakthrough, Should Crypto Holders Be Alarmed?

  • Trending
  • Comments
  • Latest
The human harbor: Navigating identity and meaning in the AI age

The human harbor: Navigating identity and meaning in the AI age

July 14, 2025
Private equity groups prepare to offload Ensemble Health for up to $12bn

Private equity groups prepare to offload Ensemble Health for up to $12bn

May 16, 2025
Equinor scales back renewables push 7 years after ditching ‘oil’ from its name

Equinor scales back renewables push 7 years after ditching ‘oil’ from its name

February 5, 2025
Niels Troost has a staggering story to tell about how he got sanctioned

Niels Troost has a staggering story to tell about how he got sanctioned

December 14, 2024
Why America’s economy is soaring ahead of its rivals

Why America’s economy is soaring ahead of its rivals

0
Dollar climbs after Donald Trump’s Brics tariff threat and French political woes

Dollar climbs after Donald Trump’s Brics tariff threat and French political woes

0
Nato chief Mark Rutte’s warning to Trump

Nato chief Mark Rutte’s warning to Trump

0
Top Federal Reserve official warns progress on taming US inflation ‘may be stalling’

Top Federal Reserve official warns progress on taming US inflation ‘may be stalling’

0
BABA, LAC, FCX, QURE and more

Stocks making the biggest moves midday: MIR, FCX, KMX

September 25, 2025
HSBC Claims Quantum Breakthrough, Should Crypto Holders Be Alarmed?

HSBC Claims Quantum Breakthrough, Should Crypto Holders Be Alarmed?

September 25, 2025
Employees learn nothing from phishing security training, and this is why

Employees learn nothing from phishing security training, and this is why

September 25, 2025
Soft Manager – Trading Ideas – 5 August 2025

Why 90% of ‘AI EAs’ Are Fake (And How to Detect Them) – My Trading – 25 September 2025

September 25, 2025

Live Prices

© 2024 Investor News Today

No Result
View All Result
  • Home
  • Market
  • Business
  • Finance
  • Investing
  • Real Estate
  • Commodities
  • Crypto
  • Blockchain
  • Personal Finance
  • Tech

© 2024 Investor News Today