Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

DRTV

End of Bibblio RCM includes -->

Regular User Awareness Training Still the Best Security Tactic

Email continues to be the largest area of exposure for most organizations, and phishing emails lead the charge, according to Stu Sjouwerman, founder and CEO of KnowBe4. And while AI and machine learning can make a difference, these same tools are used by the bad guys, Sjouwerman adds. Regular, monthly trainings help reduce phishing click rates.

Comment  | 
Print  | 
//Comments
Newest First  |  Oldest First  |  Threaded View
lakers85
lakers85,
User Rank: Strategist
5/3/2019 | 8:03:49 AM
Email Security Appliance
I would hope that most, if not all, SMB and large organizations would utilitze some form of an email secuirty appliance or software to help limit the number of phishing email entering the organization. Lets face it, how much training do end users actually receive on a yearly basis...let alone on a monthly basis.

At the end of the day, the human factor is the catch all and recognizing that you should 'not' click on that link is the ultimate security measure to prevent a breach. 
REISEN1955
REISEN1955,
User Rank: Ninja
3/12/2019 | 12:21:25 PM
Re: Email rule
Jackson county, Georgia - $400,000 ransomeware payment - gee betcha under education would have helped here.  Also having a competant IT department with a real backup and disaster recovery plan too.  
RyanSepe
RyanSepe,
User Rank: Ninja
3/8/2019 | 3:15:26 PM
Re: Email rule
Agreed, the worst thing I see is when a user isn't sure who a phish is supposed to go to so they forward it around the company. 
REISEN1955
REISEN1955,
User Rank: Ninja
3/7/2019 | 2:31:53 PM
Email rule
Easy: IF YOU DON'T NEED IT, DON'T READ IT, DELETE IT.    This would save about half the world. 
Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Developing and Testing an Effective Breach Response Plan
Whether or not a data breach is a disaster for the organization depends on the security team's response and that is based on how the team developed a breach response plan beforehand and if it was thoroughly tested. Inside this report, experts share how to: -understand the technical environment, -determine what types of incidents would trigger the plan, -know which stakeholders need to be notified and how to do so, -develop steps to contain the breach, collect evidence, and initiate recovery.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-4377
PUBLISHED: 2022-12-09
A vulnerability was found in S-CMS 5.0 Build 20220328. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Contact Information Page. The manipulation of the argument Make a Call leads to cross site scripting. The attack can be launched rem...
CVE-2022-4375
PUBLISHED: 2022-12-09
A vulnerability was found in Mingsoft MCMS up to 5.2.9. It has been classified as critical. Affected is an unknown function of the file /cms/category/list. The manipulation of the argument sqlWhere leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed t...
CVE-2022-33187
PUBLISHED: 2022-12-09
Brocade SANnav before v2.2.1 logs usernames and encoded passwords in debug-enabled logs. The vulnerability could allow an attacker with admin privilege to read sensitive information.
CVE-2022-38765
PUBLISHED: 2022-12-09
Canon Medical Informatics Vitrea Vision 7.7.76.1 does not adequately enforce access controls. An authenticated user is able to gain unauthorized access to imaging records by tampering with the vitrea-view/studies/search patientId parameter.
CVE-2022-41947
PUBLISHED: 2022-12-08
DHIS 2 is an open source information system for data capture, management, validation, analytics and visualization. Through various features of DHIS2, an authenticated user may be able to upload a file which includes embedded javascript. The user could then potentially trick another authenticated use...