Employees can help prevent phishing attacks, say BlackBerry

BlackBerry’s Vice President - UKI, Middle East & Africa, Keiron Holyome, says that the whole organisation needs to unite against the phishing threat

To preview our feature in Cyber Magazine, which will be a special feature titled ‘The dark side of remote working,’ Blackberry, the mobile pioneer-turned cybersecurity specialists, have got in touch to discuss remote security and how phishing targets remote workers specifically.

Keiron Holyome, BlackBerry’s VP - UKI, Middle East & Africa, shares his thoughts…

Kieron Holyome

How is phishing an issue for remote workers?

“Phishing criminals are constantly looking for methods to increase their profits. They haven’t missed a beat since opportunities surfaced from increased remote working. Spear phishing was a major problem before the pandemic, but it continues to account for most breaches today. There was an US$1.07M increase in breach costs (from US$3.89M to US$4.96M) specifically when remote work was a factor. Not only did these attacks result in huge costs, but it also took 58 days longer to identify and contain a breach when 50% or more of employees work remotely. With many employees still working from home indefinitely, a long term solution to securing home workers must be found.”   

What examples has BlackBerry seen of a phishing attack?

“Phishing criminals are aware that one way to achieve increased profits is by better personalising the email bait to appeal to the target receiver. For example, BlackBerry discovered that the Chinese cyber espionage group, APT41 had been preying on victims in India with a purportedly state-sponsored operation that capitalised on people's expectations for a quick end to the pandemic by the end of 2021. The user's servers, business emails, and other accounts would have all been compromised if these hackers were able to do so. 

Even though phishing is outdated, it still poses a serious danger to organisations in the light of remote working. Campaigns, often known as the "spray-and-pray" strategy, can be profitable for hackers even if only a tiny fraction of the many messages sent are successful in reaching their recipient. On the other hand, spear phishing, which refers to tailoring and customising an attack to a particular person, group, or organisation, is a more specialised variation of this strategy.”

What can businesses do to counter the cyber threat?

“It's getting harder and harder for regular users to recognise targeted phishing emails and spear phishing attacks. This means that when employees are working from home or outside the office, they must be extra vigilant, working with their employer to defend effectively against phishing. Employees are essential in preventing phishing attacks by adhering to security policies, making ensuring all of their devices are secured by security software, and immediately installing automatic updates. Employers may increase employee knowledge of phishing by providing regular staff training as well as endpoint security measures for both company-owned and employee-owned devices that can be used both online and offline.” 


Featured Articles

Zurich selects AWS to help accelerate digital transformation

As its preferred cloud provider, global insurance leader Zurich will use AWS capabilities to speed innovation and meet regulatory and security requirements

Technology can overcome public sector data privacy concerns

A new report finds that collaborative data ecosystems help governments to craft a response to systemic challenges, but widespread adoption is yet to come

US-EU partnership to drive global advancements in AI

The US and EU have announced an agreement to speed up the development of AI to improve agriculture, healthcare and climate forecasting

Survey into future of cloud security in the Middle East

Cloud & Cybersecurity

Infosys serves up digital innovations at the Australian Open

Digital Transformation

Top 10 best metaverse platforms to look out for in 2023

Digital Transformation