A fifth of UK organisations do not provide IT security training for staff

Survey reveals UK office workers do not understand basic security threats and organisations are failing to provide adequate training to help identify them.

  • 10 years ago Posted in

A quarter of UK office workers do not know what phishing is and almost a fifth of UK organisations do not provide training to help staff understand security threats, a survey from PhishMe has revealed.


The survey, which was conducted by One Poll in December 2013 and looked at the attitudes of 1,000 UK office workers, revealed that UK organisations are taking a lackadaisical approach to security training, with 19 percent not providing any staff security training whatsoever, and 24 percent not providing basic security training, including induction training, classroom training, employee security policy training or phishing training.
The recent spate of cyber attacks against some of the world’s leading brands have highlighted the significant impact cybercrime can have on organisations. Businesses cannot afford to ignore or short-change the importance of staff security training given the odds of compromise. Failure to do so can result in significant financial losses to organisations, as well as loss of Intellectual Property, confidential customer data, and customer trust.
Commenting on the findings, Rohyt Belani, CEO of PhishMe, said: “Phishing is one of the biggest security threats to organisations and it is critical that staff are given continuous training on how to identify evolving threats. Attackers use techniques such as spear-phishing where they create very credible looking malware-bearing emails and target specific individuals within an organisation, based on publicly available information. A disengaged employee population makes it increasingly difficult for organizations to defend against advanced cyber attacks.”


“Organisations that provide staff with immersive security training are able to leverage them as a line of defence and a robust attack detection mechanism, to better protect their networks. Even if a company has all the latest security technologies in place to protect their systems, human susceptibility is still one of the leading causes of a successful breach.”


Phishing has proven to be a very effective low-cost attack vector that bypasses most traditional detection methods. Several prominent security firms have confirmed in their research to be the top attack method threatening the enterprise today. With cyber criminals, nation-state actors, and most recently hacktivists like the Syrian Electronic Army, carrying out successful attacks via email, office workers can only expect more of the same in the future.
 

Research shows ‘game needs to be changed,’ with security innovation years behind that of the...
Node4 has released its Mid-Market IT Priorities Report 2021. The independent report reveals that...
Atos has launched Atos OneCloud Sovereign Shield, a set of solutions, methodologies, and...
New distribution agreement set to bolster Westcon-Comstor’s Zero Trust offering in more markets...
Research from Avast has found that employees in almost a third (31%) of Small and Medium...
This year, over half of MSPs or their end customers have been attacked by ransomware but only 53%...
Trend Micro has published new research revealing that 90% of IT decision makers claim their...
Cyber consultants call on businesses to act now, or risk budgets shrinking further in ‘real...