As the end of the financial year looms, many of us are looking at budgets and earmarking areas in our businesses that require spending in the next tax year. IT is one function that I know can cause some sleepless nights for CFOs looking to balance spending with positive ROI.
[see_also]
IT security is one area that doesn’t appear to offer any real return on investment. It’s just something you need to have in place to protect your business from cyberattack, prevent data breaches, and ensure business continuity.
While you can barricade your business against cyberthreats with firewalls, anti-virus, email filtering, anti-spam, encryption, UTM etc., there is one major threat to your business that is often overlooked by senior managers. In fact, sometimes they are guilty themselves of lowering cybersecurity defences as this threat comes from within: your staff.
I’m not talking about disgruntled employees deliberately attacking your systems or allowing access to those with criminal intent, nor am I thinking about absentminded staff leaving sensitive data in full view on a crowded train – although these are also security risks that must be addressed. Instead, I’m focusing on a sophisticated threat that can dupe even senior members of staff: ‘spear phishing’ or ‘whaling’.
Spear phishing has been associated with some of the worse cyberattacks in recent years: eBay, Target, TalkTalk, Sony, to name but a few. In a recent survey conducted by Vanson Bourne and sponsored by Cloudmark, eighty four per cent of respondents said that a spear phishing attack had penetrated their organisation’s security defences. Respondents also said that approximately twenty eight per cent of spear phishing attacks are getting through their security defences.
Before delving into what this kind of attack looks like, the good news is that it’s one area of IT security that you can address without spending large sums of money. Raising awareness, robust IT security policies, and staff training are your best line of defence when it comes to phishing scams, which will be reassuring if you were wondering how to stretch next year’s IT budget.
Phishing is a technique where scammers send emails to individuals with attachments that contain malicious code, or a link to an infected site, request login details fraudulently or, as is becoming increasingly common, request bank transfers to fraudulent accounts. Most people are aware of this type of scam and are well versed in deleting suspicious looking emails both at home and at work. Often these will use poor grammar and come from unknown senders, who hope that a proportion of emails sent will land in the inboxes of a soft target.
However, they become harder to spot when the scammer has more information about the target. For example, some victims of the TalkTalk data breach were targeted in this way even before the data breach hit the news headlines, with emails and telephone calls from individuals who seemed to be legitimate employees of TalkTalk.
This more targeted approach is the difference between phishing and spear phishing, and when used in the business environment, scammers will single out individuals who fit certain criteria.
Instead of an email from an unknown sender, your employees could receive an email from someone purporting to work for your organisation. The email itself may look legitimate with company logos and contact information. Your employee may already have had correspondence with this individual, and feel that they’re a trusted source. Then once that trust has been established they hit the recipient with malware and your employee happily opens that attached document or clicks on the link…
Spear phishing uses social engineering principals and is highly targeted. Instead of casting the net wide and hoping that they catch a few fish, the scammers go after a big fish who will deliver exactly what they want. Employees are first identified as likely channels and then nurtured over a period of time with several emails or messages.
Online forums provide an ideal place for scammers to identify targets. Here they can monitor support requests, find individual’s contact details, and then email them offering a solution to whatever problem they have. They may start the process in the actual forum, commenting on your employee’s request and suggesting solutions, all the time building trust. This leads on to email communications with the scammer and a spear phishing attack.
As stated before, protecting your business from spear phishing will not require your entire IT budget. Instead you can reduce the risk of phishing attacks by helping your employees protect your business.
This can be done in two ways:
1. Raising awareness of security risks through training and awareness campaigns
2. Providing the tools to detect these attacks
If spear phishing is a new phrase for you, then it’s likely that many of your employees won’t have heard of it either. It’s therefore important to educate them about these kinds of security risks and the consequences of a phishing attack of this type. As these attacks are constantly evolving and becoming more sophisticated, especially those using social engineering, it is worthwhile asking an IT security professional or your IT service provider to deliver this training.
With a more knowledgeable workforce it becomes easier for them to adhere to security guidelines and use techniques that protect your business systems. In brief these include:
Employees should never send logins via email, should not click on URLs shared in emails (instead enter them manually or search for websites online), should look for inconsistencies in emails headers, suspicious email addresses and odd looking URLs, and should verify website and email addresses independently.
Employees should never open or download unsolicited attachments without first double-checking their authenticity, and employers should have clear procedures on how documents are shared within the organisation – for example by using a file sharing system.
Ensure that any online banking systems have authorisation procedures in place to ensure a single person, not matter how senior, cannot make a bank transfer without a second person verifying.
[see_also]
Diverting some of next year’s IT security budget into staff training and awareness campaigns could be money well spent, protecting your business long term from phishing attacks.
Bruce Penson, MD at Pro Drive IT
Image Credit: Shutterstock/bluebay
https://healthtylifetips.blogspot.com/2025/04/childrens-hospital-care-role-of.html
https://healthtylifetips.blogspot.com/2025/04/understanding-your-rights-for-medical.html
https://healthtylifetips.blogspot.com/2025/04/balancing-work-and-motherhood.html
https://medium.com/@healthadvice01/best-ways-to-manage-seasonal-allergies-expert-tricks-79bb4dca6ad9
https://mywikiisblog.tumblr.com/post/779794817537490944/importance-of-regular-dental-checkups-for-oral
https://mywikiisblog.tumblr.com/post/779797716908818432/understanding-medical-necessity-definition-and
https://mywikiisblog.tumblr.com/post/779799277026279424/legitimate-reasons-for-a-doctors-excuse-kids
https://mywikiisblog.tumblr.com/post/779801224787689472/army-office-grooming-legal-medical-exemptions
https://mywikiisblog.tumblr.com/post/779801660332638209/medical-record-keeping-legal-aspects-compliance
https://mywikiisblog.tumblr.com/post/779802922113548288/informed-consent-in-healthcare-why-it-matters
https://mywikiisblog.tumblr.com/post/779804078263894016/proof-of-pregnancy-form-purpose-and-importance
https://medium.com/@healthadvice01/best-ways-to-manage-seasonal-allergies-expert-tricks-79bb4dca6ad9
https://healthrealwealth.weebly.com/blog/common-dental-problems-and-how-to-prevent-them
https://healthrealwealth.weebly.com/blog/calling-in-sick-like-a-pro-avoiding-boss-suspicion
https://healthrealwealth.weebly.com/blog/when-to-see-a-psychiatrist-signs-you-shouldnt-ignore
https://healthrealwealth.weebly.com/blog/stress-and-anxiety-management-how-culture-plays-a-role
https://healthrealwealth.weebly.com/blog/chargebacks-vs-refunds-which-one-works-best-for-flights
https://healthrealwealth.weebly.com/blog/different-anemia-kinds-root-causes-a-breakdown
https://healthrealwealth.weebly.com/blog/accelerate-post-op-healing-expert-backed-strategies
https://justpaste.it/aub6y
https://justpaste.it/g0l31
https://justpaste.it/i799j
https://justpaste.it/hcmzf
https://justpaste.it/ibbgd
https://justpaste.it/jaui1
https://justpaste.it/2w0tx
https://medium.com/@healthadvice01/disability-benefits-how-to-apply-successfully-44d75b06051e
https://medium.com/@healthadvice01/what-to-expect-during-an-urgent-care-visit-key-insights-0ae736924f1e
https://allmenuz.weebly.com/blog/business-side-of-restaurant-catering-pricing-and-logistics
https://allmenuz.weebly.com/blog/senior-menus-discounts-winning-customer-loyalty
https://allmenuz.weebly.com/blog/vegetarian-chili-a-flavorful-hearty-meat-free-option
https://allmenuz.weebly.com/blog/how-to-choose-the-perfect-restaurant-for-a-family-meal
https://allmenuz.weebly.com/blog/common-mistakes-in-drawing-poses-and-how-to-fix-them
https://allmenuz.weebly.com/blog/why-order-food-online-top-5-benefits-explained
https://allmenuz.weebly.com/blog/homemade-vs-fast-food-chicken-nuggets-which-tastes-better
https://allmenuz.blogspot.com/2025/04/history-of-veterans-day-impact-on.html
https://allmenuz.blogspot.com/2025/04/how-to-start-career-in-restaurant.html
https://allmenuz.blogspot.com/2025/04/how-to-find-and-use-restaurant-coupons_2.html
https://allmenuz.blogspot.com/2025/04/running-successful-catering-service-key.html
https://allmenuz.blogspot.com/2025/04/pennywise-drawing-ideas-unique-and.html
https://allmenuz.blogspot.com/2025/04/best-times-to-open-restaurant-best.html
https://allmenuz.tumblr.com/post/779787778481340416/science-behind-ice-cream-what-makes-it-so
https://allmenuz.tumblr.com/post/779779890884018176/evolution-of-desserts-classic-sweets-to-modern
https://allmenuz.tumblr.com/post/779780917058240512/best-restaurant-discount-strategies-how-to-save
https://allmenuz.tumblr.com/post/779783267310239744/the-art-of-cooking-the-perfect-prime-rib-cooking
https://allmenuz.tumblr.com/post/779784614805979136/why-a-visible-restaurant-phone-number-boosts-your
https://allmenuz.tumblr.com/post/779786011754594304/drawing-stylish-glasses-a-step-by-step-guide
https://allmenuz.tumblr.com/post/779787443950010368/the-rise-of-restaurant-delivery-convenience-vs
https://allmenuz.jimdosite.com/blog/butter-vs.-margarine-choosing-the-healthier-option/
https://medium.com/@menuz/how-restaurants-can-support-charities-through-fundraising-9e3e60eeb4d3
https://medium.com/@menuz/buffalo-wings-history-how-they-became-americas-favorite-9a8c36f070a5
https://medium.com/@menuz/best-restaurant-deals-and-discounts-for-veterans-save-now-d29a584c2c74
https://jpst.it/4eCA5
https://justpaste.it/gn76l
https://justpaste.it/h4719
https://justpaste.it/a7s1b
https://justpaste.it/frxip
https://justpaste.it/hklge
https://sites.google.com/view/healthadvice01/all-blogs/digital-anxiety-how-social-media-contributes-to-stress
https://sites.google.com/view/healthadvice01/all-blogs/best-hr-tech-for-managing-work-absences-top-tools
https://sites.google.com/view/healthadvice01/all-blogs/return-to-work-interviews-purpose-and-best-approaches
https://sites.google.com/view/healthadvice01/all-blogs/first-trimester-symptoms-and-how-to-manage-them
https://sites.google.com/view/healthadvice01/all-blogs/how-to-choose-the-best-ergonomic-chair-for-your-needs
https://healthylife9061.wordpress.com/2025/03/25/impact-of-bed-rest-on-labor-effects-on-delivery-health/
https://healthylife9061.wordpress.com/2025/03/25/best-exercises-for-a-healthy-spine-pain-free-back/
https://healthylife9061.wordpress.com/2025/03/25/impact-of-nutrition-on-mental-health-eat-for-mind/
https://healthylife9061.wordpress.com/2025/03/25/common-foods-that-can-cause-food-poisoning-beware/
https://healthylife9061.wordpress.com/2025/03/25/best-and-worst-excuses-skipping-work-explained/
https://healthylife9061.wordpress.com/2025/03/25/how-vaccines-work-the-science-behind-immunization/
https://healthtylifetips.blogspot.com/2025/03/can-you-take-sick-leave-for-ibs-legal.html
https://healthtylifetips.blogspot.com/2025/03/how-long-does-cold-last-recovery.html
https://healthtylifetips.blogspot.com/2025/03/how-long-does-cold-last-recovery.html
https://healthtylifetips.blogspot.com/2025/03/how-long-can-you-stay-on-bed-rest.html
https://mywikiisblog.tumblr.com/post/778524270597980160/how-to-get-a-refund-for-a-canceled-flight-a-guide
https://mywikiisblog.tumblr.com/post/778525672236810240/best-iron-rich-foods-to-fight-anemia-boost-your
https://mywikiisblog.tumblr.com/post/778528677288919040/common-mistakes-to-avoid-during-surgery-recovery
https://mywikiisblog.tumblr.com/post/778529495742365696/emergency-passport-applications-the-role-of-a
https://mywikiisblog.tumblr.com/post/778531384109203456/preventing-school-absences-tips-for-keeping-kids
https://mywikiisblog.tumblr.com/post/778533068609929217/how-to-treat-a-sprained-ankle-at-home-healing
https://mywikiisblog.tumblr.com/post/778524270597980160/how-to-get-a-refund-for-a-canceled-flight-a-guide
https://mywikiisblog.tumblr.com/post/778525672236810240/best-iron-rich-foods-to-fight-anemia-boost-your
https://mywikiisblog.tumblr.com/post/778528677288919040/common-mistakes-to-avoid-during-surgery-recovery
https://mywikiisblog.tumblr.com/post/778529495742365696/emergency-passport-applications-the-role-of-a
https://mywikiisblog.tumblr.com/post/778531384109203456/preventing-school-absences-tips-for-keeping-kids
https://mywikiisblog.tumblr.com/post/778533068609929217/how-to-treat-a-sprained-ankle-at-home-healing
https://healthylife9061.wordpress.com/2025/03/12/best-breeds-for-service-dog-training-top-picks-traits/
https://healthylife9061.wordpress.com/2025/03/12/how-to-support-a-loved-one-with-depression-helpful-tips/
https://mywikiisblog.tumblr.com/post/777708026480263168/creative-yet-acceptable-excuses-for-not-shaving
https://mywikiisblog.tumblr.com/post/777710967112990720/how-to-obtain-a-dentists-note-for-work
https://healthylife9061.wordpress.com/2025/01/28/coping-with-miscarriage-support-and-healing/
https://healthrealwealth.weebly.com/blog/workplace-health-building-a-productive-and-safe-environment
https://healthrealwealth.weebly.com/blog/vaccination-record-tracking-your-immunization-history
https://healthtylifetips.blogspot.com/2025/03/posture-support-improve-alignment.html
https://healthtylifetips.blogspot.com/2025/03/doping-in-sports-ethical-dilemmas-and.html
https://healthtylifetips.blogspot.com/2025/03/pre-surgery-preparation-essential-steps.html
https://sites.google.com/view/healthadvice01/all-blogs/reason-of-back-pain-common-causes-and-relief-methods
https://sites.google.com/view/healthadvice01/all-blogs/how-to-manage-anxiety-simple-ways-to-stay-calm
https://sites.google.com/view/healthadvice01/all-blogs/arthritis-symptoms-key-signs-you-shouldnt-ignore
https://sites.google.com/view/healthadvice01/all-blogs/how-to-cure-tonsillitis-best-remedies-for-fast-relief
https://sites.google.com/view/healthadvice01/all-blogs/flu-season-stay-safe-with-these-prevention-tips
https://sites.google.com/view/healthadvice01/all-blogs/miscarriage-signs-warning-symptoms-to-be-aware-of
https://sites.google.com/view/allmenuz/blog/restaurant-delivery-vs-takeout-pros-and-cons
https://sites.google.com/view/allmenuz/blog/most-popular-side-dishes-global-favorites-explained
https://sites.google.com/view/allmenuz/blog/seasonal-lunch-menu-trends-whats-hot-in-2025
https://sites.google.com/view/allmenuz/blog/different-variations-of-sweet-potato-sauce-sweet-vs-savory
https://sites.google.com/view/allmenuz/blog/creating-cherry-illustrations-draw-lifelike-fruit-art
https://sites.google.com/view/allmenuz/blog/are-boneless-wings-really-wings-a-culinary-debate
https://allmenuz.tumblr.com/post/778874372607934464/best-restaurants-for-family-friendly-dining-top
https://allmenuz.tumblr.com/post/778875496051228672/trends-in-wine-menus-whats-popular-in-2025
https://allmenuz.tumblr.com/post/778876930992783360/health-benefits-of-eating-baked-potatoes-explained
https://allmenuz.tumblr.com/post/778878074195509248/top-career-paths-in-the-restaurant-industry-today
https://allmenuz.tumblr.com/post/778881563719041024/anime-vs-realistic-bangs-drawing-techniques
https://allmenuz.tumblr.com/post/778883074944647168/common-gluten-free-mistakes-restaurants-should
https://allmenuz.blogspot.com/2025/03/history-and-popularity-of-prime-rib-in.html
https://allmenuz.blogspot.com/2025/03/how-to-secure-table-tips-for-booking.html
https://allmenuz.blogspot.com/2025/03/classic-ranch-dressing-recipe-homemade.html
https://allmenuz.blogspot.com/2025/03/digital-vs-paper-coupons-which-works.html
https://allmenuz.blogspot.com/2025/03/understanding-bird-anatomy-for.html
https://allmenuz.blogspot.com/2025/03/catering-trends-in-2025-meeting.html
https://allmenuz.weebly.com/blog/how-rewards-programs-influence-customer-behavior-and-loyalty
https://mywikiisblog.tumblr.com/post/777708460672483328/best-happy-hour-food-specials-pairing-drinks-with
https://mywikiisblog.tumblr.com/post/777709244679110656/best-variations-of-caesar-salad-history-and
https://mywikiisblog.tumblr.com/post/777709789783490560/10-delicious-and-nutritious-healthy-options-for
https://mywikiisblog.tumblr.com/post/777708571629633536/chicken-drawing-in-different-art-styles-a
https://sites.google.com/view/allmenuz/blog/worlds-top-10-restaurant-special-dishes-list-must-try
https://sites.google.com/view/allmenuz/blog/how-to-make-a-protein-packed-grilled-chicken-salad
https://sites.google.com/view/allmenuz/blog/vegetarian-and-vegan-easter-menu-options-meat-free-ideas
https://foodmenu.zohosites.in/blogs/post/best-mocktail-options-delicious-alcohol-free-drinks
https://sites.google.com/view/allmenuz/blog/peanut-appetizer-recipes-for-every-occasion
https://expatguidekorea.com/profile/roman-well/
https://wallhaven.cc/user/Roman01
https://diit.cz/profil/vcyqy7ki7k
https://www.metal-archives.com/users/Roman01
https://app.talkshoe.com/user/roman01/about
https://audio.com/roman-well
https://www.clarinetu.com/profile/rwell0456/profile
https://www.layaspaandyoga.com/members-area/rwell0456/profile
https://www.stickermule.com/u/104f6e230d2d671
https://www.grepmed.com/rwell0456
https://leetcode.com/u/iEQDjeBI6y/
https://rainplatform.wtelecom.es/user/72858/
https://www.credly.com/users/roman-well
https://www.longisland.com/profile/Roman01
https://qooh.me/Roman01
https://flightsim.to/profile/Romanwell01
http://freestyler.ws/user/464483/Roman01
https://www.bestadsontv.com/profile/474452/Roman-Well
https://www.pozible.com/profile/roman-well
https://propterest.com.au/user/18669/Roman01
https://producerbox.com/users/roman01
https://allmynursejobs.com/author/roman01/
https://aboutnursinghomejobs.com/author/roman01/
https://rndirectors.com/author/roman01/
https://aboutnursernjobs.com/author/roman01/
https://www.diversityofficermagazine.com/diversityjobs/author/roman01/
https://worldranksite.com/author/roman01-81901/
https://topbilliondirectory.com/author/roman01-72179/
https://microlinksite.com/author/roman01-73852/
http://www.fanart-central.net/user/romanwell01/profile
https://www.zerohedge.com/user/62DqWx61yiUXLvyatj7HXUUcPDE3
https://blatini.com/profile/roman01
https://www.thebostoncalendar.com/user/100722
https://www.adproceed.com/author/roman01/
https://www.ziparticle.com/author/roman01/
https://confengine.com/user/roman-well
https://www.outlived.co.uk/author/roman01/
https://classifieds.villages-news.com/author/roman01
https://vtforeignpolicy.com/author/roman01/
https://genteel-carnation-zh63g1.mystrikingly.com/