Social engineering “most dangerous” threat, say 75% of security professionals

Research by CS Hub has revealed that social engineering and phishing attacks are the top threat to cyber security

Add bookmark
Social engineering “most dangerous” threat, say 75% of security professionals

Cyber security practitioners consider social engineering and phishing attacks to be the number one threat to their organization, research by CS Hub has revealed.

In the CS Hub Mid-Year Market Report 2022, 75 percent of respondents cited social engineering/phishing attacks as the top threat to cyber security at their organization, followed by supply chain/third-party risks (36 percent) and lack of cyber security expertise (30 percent).

Phishing and social engineering attacks rely on human error rather than software vulnerabilities, meaning the onus is on employees within an organization to safeguard against these attacks. Additionally, it is imperative that organizations ensure their employees are equipped to identify and report these attacks when they do happen.

Commenting on the results, Jeff Campbell, technology manager and previously CISO at Horizon Power, an Australian power supplier, said: “With the increase in maturity over the years of edge security, the easiest way in is through the weakest link, which generally tends to be individuals. Getting an individual to click on a malicious link or giving away information still yields successful results.”

How to safeguard against social engineering and phishing attacks

Multinational technology conglomerate Cisco notes that social engineering attacks have grown increasingly sophisticated. The company says this is not just because fake websites and emails are becoming increasingly realistic, tricking victims into clicking on links, but also because it has become one of the most common ways for bad actors to get past an organization’s initial defenses to cause further harm and disruption.

To protect individuals and organizations from these attacks, a number of procedures can be put in place. These include:

  • Multifactor authentication;
  • Email security with anti-phishing defenses;
  • Strong password management;
  • Employee training to identify and avoid such attacks.

Learn about these techniques and more in Six ways to thwart malicious emails. 


Recommended

info@cshub.com/r/n

We hope you enjoy All Access from CS Hub!!<\/p>\r\n<p>Best Regards,<\/p>\r\n<p><a href=https://www.cshub.com/"https:////www.cshub.com///" target=\"_blank\">CS Hub Team<\/a><\/p>\r\n<p>P.S. Be sure to check out our other upcoming <a href=https://www.cshub.com/"https:////www.cshub.com//events?filter_format=ONLINE\%22 target=\"_blank\">All Access events here<\/a>.<\/p>\r\n<p>--------------------------------<\/p>\r\nConnect with us on Social Media: <a href=https://www.cshub.com/"https:////www.linkedin.com//groups//12067996///" target=\"_blank\">LinkedIn<\/a> | <a href=https://www.cshub.com/"https:////twitter.com//CSHubUSA/" target=\"_blank\">Twitter<\/a><\/p>\r\n<p>--------------------------------<\/p>\r\n<p>FAQS<\/p>\r\n<p><b>Can I invite my colleagues?<\/b><br>Yes of course! Please send them this link so they can register for free! [WebUrl]<\/p>\r\n\r\n<p><b>How do I access the sessions?<\/b><br>\r\nAll Access is run on Zoom Events. You should receive an email shortly from Zoom Events with your unique All Access link to the event lobby. Please hold on to that email ahead of the event. We\u2019ll also send you a reminder 24 hours before we go live!<\/p>\r\n\r\n<p><b>Will the agenda be updated?<\/b><br>\r\nYes, the agenda will be continuously updated on the website with the latest sessions & speakers. As we get closer to the event, also look out for our weekly updates which will also include the latest updates information and link to access the event.<\/p>\r\n<p><b>Can I access the sessions On Demand?<\/b><br>\r\nEvery session will be available after the event via the event lobby. We\u2019ll also send you a reminder about the On Demand sessions which will be sent to you after the event is over.<\/p>\r\n<p>--------------------------------<\/p>\r\n<p>RELATED RESOURCES TO READ BEFORE YOUR EVENT<\/p>\r\n<ul>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//executive-decisions//reports//cs-hub-mid-year-market-report-2022?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CS Hub Mid-Year Market Report 2022<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//ciso-strategies-for-proactive-threat-prevention?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CISO strategies for proactive threat prevention<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//how-to-strengthen-email-security-and-protection-against-advanced-ransomware-attacks?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">How to strengthen email security and protection against advanced ransomware attacks<\/a><\/li>\r\n<\/ul>","event_registration_srs_confirmation_email":null,"assets_from_cdn":true},"bant_disabled":1,"sponsorship_disclaimer":null,"sponsorship_disclaimer_text":null,"sponsorship_disclaimer_checkbox_disabled":0,"ext_treat_id":null,"recording_url":null,"file_attachment":null,"ingo_enabled":null,"ingo_activator_id":null,"ingo_autofiller_id":null,"ingo_amplifier_id":null,"ingo_authorizer_id":null,"restricted_content":0,"featured_events_embedded":[],"featured_content_embedded":[{"id":"62dfd86043ab1d779b5c3728","name":"CS Hub Mid-Year Market Report 2022","description":"The current challenges facing cyber security practitioners and where they are focusing their investment decisions in 2022 and beyond","file":"https:\/\/eco-cdn.iqpc.com\/eco\/files\/channel_content\/posts\/cs-hub-2022-mid-year-reportG7cbfZfIebM7HLei8jd729tjL3A6Z3b6wEYS4XKZ.pdf","url":"\/executive-decisions\/reports\/cs-hub-mid-year-market-report-2022"},{"id":"62e3beef6ceab07f824156af","name":"What is social engineering?","description":"A guide to social engineering and how to guard against this attack vector","file":null,"url":"\/threat-defense\/articles\/what-is-social-engineering"},{"id":"624efaad3120251d580229a8","name":"IOTW: Social engineering attack sees Mailchimp hacked","description":"Mailchimp employee account compromised by a social engineering attack","file":null,"url":"\/attacks\/news\/iotw-social-engineering-attack-sees-mailchimp-hacked"},{"id":"62cefa9eba4e7223597b6215","name":"IOTW: Marriott International suffers latest in series of data breaches","description":"Hospitality company Marriott International reports data breach result of social engineering hack","file":null,"url":"\/attacks\/news\/iotw-marriott-international-suffers-latest-in-series-of-major-data-breaches"},{"id":"5e69ce4a312025518a79ebfc","name":"Phishing Attacks Work Because\u2026 Humans","description":"Layered Approach Poised To Overcome Enterprise Productivity Impact","file":null,"url":"\/attacks\/articles\/phishing-attacks-work-because-humans"}],"featured_content_portal_embedded":null}" >