Workplace phishing simulations
Phishing is the name given to fraudulent emails and messages designed to trick people into giving away their passwords and other credentials or to download malware. These types of attacks have been increasingly deployed by criminals over the last few years. The number of phishing attacks are estimated to have risen by 150%, year on year, since 2019.
Unions are at particular risk, as they hold the personal data of union members. Union membership is classified as ‘special category’ sensitive data under Data Protection legislation. If, for example, a phishing attack managed to capture the password and username of a union employee who has access to the union’s membership system, and there were no additional security checks (such as multi factor authentication) the results could be catastrophic.
There is also now a greater expectation on employees to be more aware of the risks. While training, communication and good security technology and protocols are a must, one practice that can really help is running regular phishing simulations.
A phishing simulation is where a fake phishing email is sent to employees to assess how people will interact with a real phishing attempt. These emails will look like actual phishing emails. For example, the email address, text and any links will give away clues to people aware of phishing risks that the emails are fake.
Phishing emails can be very clever, and everyone can be vulnerable. It’s easier to be caught off guard at certain times, such as when dealing with busy working periods, or when tired at the end of the day.
With these training simulations, interactions are captured, so that the tech teams can see how successful the email would be if it had been a real attempt. Individuals who give away their credentials can be identified. Additional training can then be targeted to those who need it, with online training often provided automatically at the end point of the simulation as well.
Regular phishing simulations really help raise awareness, but employers should use them for training and education rather than policing employees. They should be used to educate people and not to punish.
I’m the virtual Chief Information Officer at the TUC, and I introduced regular phishing simulations at the organisation a few years ago. We’ve seen a noticeable improvement in the awareness of phishing since they were introduced, and people are now much better at spotting these fake phishing attempts.