What are the most effective ways to prevent Social Engineering attacks in a remote workforce?
Since my company moved to a permanent remote-first model, we’ve seen a massive uptick in sophisticated phishing and business email compromise (BEC) attempts. We have the standard MFA and VPN protocols, but the human element remains our weakest link. How are you guys training employees to spot deepfake audio or well-crafted spear-phishing emails?
2024-11-04 in Cyber Security by Jessica Morgan
| 17244 Views
All answers to this question.
Standard annual training is no longer enough. We’ve implemented "Phish-testing" where we send out fake, safe phishing emails once a month. If an employee clicks the link, they get an immediate 5-minute refresher module. We also established a "no-questions-asked" verification policy. If anyone receives an urgent request for a wire transfer or sensitive data, they must call the requester on a pre-verified number, regardless of who the email claims to be from.
Answered 2024-11-05 by Patricia Higgins
Is your IT team using DMARC and DKIM to filter out spoofed domains? Sometimes technical controls can catch what the human eye misses.
Answered 2024-11-06 by William Vance
-
William, we do have DMARC enabled, but the attackers are now using compromised accounts from our actual vendors. It's technically "clean" mail but with malicious intent. That's why the human side is becoming so critical for us lately.
Commented 2024-11-07 by Jessica Morgan
We use a "Security Champion" program where one person in each non-tech department is trained to be the first point of contact for suspicious activity.
Answered 2024-11-08 by Thomas Wright
-
I love the Security Champion idea, Thomas. It makes security feel less like an "IT problem" and more like a shared responsibility across the whole company.
Commented 2024-11-09 by Patricia Higgins
Write a Comment
Your email address will not be published. Required fields are marked (*)

