Employees can help prevent phishing attacks, say BlackBerry

BlackBerry’s Vice President - UKI, Middle East & Africa, Keiron Holyome, says that the whole organisation needs to unite against the phishing threat

To preview our feature in Cyber Magazine, which will be a special feature titled ‘The dark side of remote working,’ Blackberry, the mobile pioneer-turned cybersecurity specialists, have got in touch to discuss remote security and how phishing targets remote workers specifically.

Keiron Holyome, BlackBerry’s VP - UKI, Middle East & Africa, shares his thoughts…

Kieron Holyome

How is phishing an issue for remote workers?

“Phishing criminals are constantly looking for methods to increase their profits. They haven’t missed a beat since opportunities surfaced from increased remote working. Spear phishing was a major problem before the pandemic, but it continues to account for most breaches today. There was an US$1.07M increase in breach costs (from US$3.89M to US$4.96M) specifically when remote work was a factor. Not only did these attacks result in huge costs, but it also took 58 days longer to identify and contain a breach when 50% or more of employees work remotely. With many employees still working from home indefinitely, a long term solution to securing home workers must be found.”   

What examples has BlackBerry seen of a phishing attack?

“Phishing criminals are aware that one way to achieve increased profits is by better personalising the email bait to appeal to the target receiver. For example, BlackBerry discovered that the Chinese cyber espionage group, APT41 had been preying on victims in India with a purportedly state-sponsored operation that capitalised on people's expectations for a quick end to the pandemic by the end of 2021. The user's servers, business emails, and other accounts would have all been compromised if these hackers were able to do so. 

Even though phishing is outdated, it still poses a serious danger to organisations in the light of remote working. Campaigns, often known as the "spray-and-pray" strategy, can be profitable for hackers even if only a tiny fraction of the many messages sent are successful in reaching their recipient. On the other hand, spear phishing, which refers to tailoring and customising an attack to a particular person, group, or organisation, is a more specialised variation of this strategy.”

What can businesses do to counter the cyber threat?

“It's getting harder and harder for regular users to recognise targeted phishing emails and spear phishing attacks. This means that when employees are working from home or outside the office, they must be extra vigilant, working with their employer to defend effectively against phishing. Employees are essential in preventing phishing attacks by adhering to security policies, making ensuring all of their devices are secured by security software, and immediately installing automatic updates. Employers may increase employee knowledge of phishing by providing regular staff training as well as endpoint security measures for both company-owned and employee-owned devices that can be used both online and offline.” 


Featured Articles

Confronting Enterprise AI Skills Gaps with Bridgenext

As companies struggle to marry AI investments and workforce skills, Bridgenext’s Rajesh Khanna shares how businesses can unlock greater strategic value

AWS-Workday Partnership: AI Transforming HR and Finance

Expanding their partnership, AWS & Workday are revolutionising enterprise management through AI-driven solutions, promising enhanced productivity

AMD Bags Silo AI in a Bid to Power Ahead in the AI Race

AMD acquires Finnish startup Silo AI for US$665m to step forward in the AI race, powering ahead in its mission to enhance its chips to compete with Nvidia

Microsoft Settles $22m Cloud Licensing Antitrust Complaint

Cloud & Cybersecurity

IBM's Commitment to Data Governance for Positive AI Impact

Data & Data Analytics

Gen AI Success: Need For Governance, Infrastructure & Talent

AI & Machine Learning