Security
22 Aug 2022

Attack simulation training


In the world of technology, security threats change over time. Currently, one of the most critical risks revolves around phishing emails. Phishing is where criminals use scams sent via email, SMS or phone calls to try and steal personal information or trick people into installing malicious software.

Over the last few years, it’s been on the rise. It’s been estimated that about 90% of all cyber-attacks start with a phishing email. Attacks are becoming increasingly sophisticated, with highly targeted attacks (known as ‘Spear Phishing’) that can be personalise more of the email content and design.

"We’ve seen a sharp decrease in the number of people giving away their details."

Security training and education are two of the traditional ways of raising awareness and caution regarding phishing. There is also another, increasingly popular, tool that organisations can use – attack simulation training.

This involves setting up a fake phishing attack to send to the staff of an organisation or company. The fake phishing email replicates exactly what users will see from a real phishing email, so the clues people need to spot are the same. Most attack simulation training platforms will then capture the success rate of the training, to give an idea on how many people were tricked by the simulation, often alongside inbuilt training and guidance.

I’ve been using this approach to improving security with clients, using the attack simulation tools provided to administrators in the Microsoft 365 cloud platform.  The toolkit is impressive, with a wide range of preconfigured simulated attacks, estimated success rates and the ability to create bespoke simulations. There are inbuilt training options as well, and the system tracks how well the organisation is progressing.

From the phishing attacks I’ve simulated so far, we’ve seen a sharp decrease in the number of people giving away their details. The feedback has been positive, and more users are flagging up suspicious emails. These simulations are working really well.

There have been some concerns amongst unions that this type of training is used properly. This approach should only be used to help target additional training and educate, it should not be used to punish or name and shame workers who may fall for the simulation.

Good communications as to why the simulations are being used is vital.  However, given the increased risks from phishing, it’s never been more important to raise awareness of the security risks.