Why? Simply put phishing works and the more organizations and individuals are aware of it, the easier it is to defend against an attack.
Phishing is a form of social engineering in which a cyber threat actor poses as a trustworthy colleague, acquaintance, or organization to lure a victim into providing sensitive information or network access, according to the infographic published by the Cybersecurity and Infrastructure Security Agency (CISA).
In terms of phishing attacks:
- 70 percent of all attached files or links containing malware were not blocked by network border protection services.
- 15 percent of all malicious attachments or links were not blocked by endpoint protections, which are set up to reduce the amount of unwanted or malicious activity.
- Within the first 10 minutes of receiving a malicious email, 84 percent of employees took the bait by either replying with sensitive information or interacting with a spoofed link or attachment.
- 13 percent of targeted employees reported the phishing attempts. Employee failure to report phishing attempts limits the organization’s ability to respond to the intrusion and alert others to the threat.
The infographic also provides detailed actions organizations and individuals can take to prevent successful phishing operations – from blocking phishing attempts to teaching individuals how to report successful phishing operations.
Click here to view the infographic.


