ClearView IT Blog

ClearView IT has been serving the Phoenix area since 2005, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

How to Prepare Your Team to Fight Phishing

How to Prepare Your Team to Fight Phishing

While last year saw a significant decrease in its number of data breaches, the number of records that were leaked doubled… and then some. Part of this can likely be attributed to a spike in the use of ransomware, indicating a resurgence in interest of the mean-spirited malware. This means that your business may very well see more ransomware infection attempts coming its way—the only question is, are your team members prepared for them?

To keep your business and its data sufficiently secured, it will be important to teach your team to effectively identify and avoid phishing. One effective way to do it: try and phish them yourself, via a phishing attack simulation.

How Does a Phishing Attack Work?

Let’s go through the basic process of a phishing attack, just as a quick review:

An attacker, posing as someone else, sends their victim a message making some promise or threat that somehow—either through fear or temptation—coerces their contact into reacting to it, usually by following a link or opening an attachment. This methodology allows such schemes to bypass many restrictions set by security protocols and solutions, as the vulnerability it takes advantage of is the human user.

Therefore, when it comes to defending against the phishing attempts that are virtually guaranteed to target your business at some point, your team members need to be prepared. Let’s discuss what you need to teach them, and how to best prepare them to make sure they’ll overcome any they encounter.

Phishing Lessons to Pass On

Remind Them How Hackers Think

It’s important that your users are cognizant of how clever hackers and scammers can be when it comes to their ruses, and how they often take advantage of current events and information. Many phishing attacks as of late have been themed around COVID-19, pertaining to updates, warnings, and offers of personal protective equipment.

Hackers will try to capitalize on user panic and knee-jerk reactions whenever they possibly can to keep these users from thinking before they act. Therefore, it makes sense to have users look more critically at their incoming messages to evaluate whether a message seems “phishy” or not.

Provide Signs of Problematic Links

A favorite tool of these hackers is that of the spoofed link—basically, a link to one website disguised as a link to another. Others will just use a URL that is different but looks passable enough to slip by unnoticed.

These domains can be tricky. Let’s look at a few red flags to keep an eye out for (in this case, the attacker using Amazon as a disguise):

If the email is from Amazon, a link should lead back to Amazon.com or accounts.amazon.com. If there is anything strange between “Amazon” and the “.com” then something is suspicious. There should also be a forward slash (/) after the “.com.” If the URL was something like amazon.com.mailru382.co/something, then you are being spoofed. Everyone handles their domains a little differently, but use this as a rule of thumb:

  • amazon.com - Safe
  • amazon.com/activatecard - Safe
  • business.amazon.com - Safe
  • business.amazon.com/retail - Safe
  • amazon.com.activatecard.net - Suspicious! (notice the dot immediately after Amazon’s domain name)
  • amazon.com.activatecard.net/secure - Suspicious!
  • amazon.com/activatecard/tinyurl.com/retail - Suspicious! Don’t trust dots after the domain!

 Some of these things can be challenging to spot, so you and your users need to be extra careful about checking (and double-checking) links.

Give Safe Links to Use

Even better, you could provide your team members with the links they are expected to use when being directed to certain places by their clients, rather than using the links potentially given in an email. These trusted links can be a real lifesaver, particularly when it becomes apparent that an email was an attack that a trusted link has helped your team to avoid.

Enforce Password Practices and Processes

The security of your team’s collective password policies is important for you to address, as these passwords are often the keys to the castle that cybercriminals are phishing for. Therefore, you need to ensure that your team is not only using best practices but are also handling these passwords appropriately, using tools like two-factor authentication wherever applicable and being generally cautious.

Evaluating Their Preparedness

Finally, once you’ve taught them the signs and precautions, you need to make sure that you check their proficiency in following through. To do this, a phishing test is in order.

A phishing test is simply a phishing attack you run against your own business to help identify where your weaknesses are. By showing you which team members are susceptible to an attack, you can correct the vulnerability through training and other assistance.

What Makes a Successful Phishing Test?

To effectively run a phishing test, you should not inform your team that one is incoming—to do so would defeat the purpose of the evaluation. If you do, make sure you keep it vague and never specify when they should expect it—that way, you can avoid skewing your results.

However, you also need to keep basic ethics in mind. Being shady—like some companies have been concerning their phishing “evaluations” in the past (we’re looking at you, GoDaddy)—will not help your security. You want to communicate trust with your team, and hope it is reciprocated.

As for your other security needs, lean on ClearView IT for assistance. Give us a call at 866-326-7214 to learn more.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Tuesday, 06 May 2025
If you'd like to register, please fill in the username, password and name fields.

Captcha Image

Tag Cloud

Tip of the Week Security Technology Best Practices Business Computing Hackers Productivity Software Network Security Privacy Data Cloud Business User Tips IT Support Internet Hardware Innovation Email Hosted Solutions Malware Efficiency Workplace Tips Computer Google Microsoft Collaboration Android Cybersecurity Business Management Phishing IT Services Backup Ransomware Data Backup communications Smartphone Microsoft Office Upgrade Smartphones Small Business Network Mobile Devices Data Recovery Communication Managed IT Services Productivity Quick Tips Social Media Users VoIP Mobile Device Tech Term Automation Facebook Business Continuity Windows 10 Disaster Recovery Passwords Holiday Covid-19 IT Support Browser Apps Windows 10 Managed Service Cloud Computing Outsourced IT Miscellaneous Data Management Internet of Things Managed Service Provider Remote Work Saving Money Government Operating System Windows Workplace Strategy Artificial Intelligence Managed IT services Gadgets Networking App Virtualization Business Technology Spam Mobile Device Management Blockchain Server WiFi Bandwidth Information Remote Encryption Gmail Office History Budget Two-factor Authentication Office 365 Apple Information Technology Employee/Employer Relationship Big Data Wi-Fi Health Analytics Access Control Conferencing Data Security Cybercrime BDR Save Money Help Desk Hacking Employer-Employee Relationship IT Management Voice over Internet Protocol Training Hacker Remote Computing Cost Management Patch Management Compliance Document Management Vendor Remote Monitoring Search... Vulnerabilities Best Practice Retail Mobile Office Alert BYOD Managed Services Hiring/Firing Computing Outlook Data loss Vendor Management Hard Drive Money Password Customer Service Unified Threat Management Firewall Legal Augmented Reality Word Applications IBM Data storage Project Management Website Travel Virtual Reality Websites Social Engineering Monitoring Mobility Cryptocurrency Storage Meetings The Internet of Things Black Market Healthcare YouTube Cleaning Remote Workers Google Maps Robot Scam Laptop Windows 7 Free Resource User VPN Windows 11 How To Update Social Sports SaaS Twitter DDoS Chrome Law Enforcement Paperless Office End of Support Printer iPhone Antivirus Education Data Breach Cortana Mobile Computing Maintenance Content Filtering Marketing Router Running Cable Downloads Virtual Machines Computer Care Co-Managed IT Bluetooth Entertainment Computer Repair Distributed Denial of Service Multi-factor Authentication Office Tips Vulnerability Private Cloud Professional Services Memory Software as a Service Data Protection Saving Time Managed Services Provider Politics Wireless Technology eWaste Computers Machine Learning Bitcoin Settings Virtual Private Network Telephone HIPAA Solid State Drive Downtime Current Events Safety Tech Terms Excel Solutions Virtual Desktop Chromebook Drones Managed IT Digital Experience Images 101 Automobile Integration Display Taxes How To Virtual Assistant Microchip Employees PowerPoint Flexibility Disaster Administration Avoiding Downtime Presentation Holidays Physical Security Identity Theft Lithium-ion battery Processor Specifications Hack Notifications IT Consultant Unified Communications Cooperation Video Conferencing Customer Relationship Management Processors Google Docs Start Menu User Tip Shopping Vendor Mangement Legislation Securty News Medical IT Domains Music Evernote Paperless Network Management Samsung Computer Accessories SQL Server Uninterrupted Power Supply Be Proactive Licensing Webcam PCI DSS Proxy Server Gig Economy Business Mangement Emails Humor Fake News Business Communications Service Level Agreement Internet Service Provider Tablets Botnet Computing Infrastructure Azure Workplace Strategies Device security Managed IT Service Rental Service Micrsooft Management Regulations Compliance Google Calendar Wireless Headphones Memes Supercomputer Microsoft Excel Flash Public Speaking Telephone Systems Business Growth Tech Human Resources Virus Going Green Net Neutrality Streaming Media Business Cards Error Financial Data Motion Sickness Keyboard Comparison Bookmark Risk Management Google Drive Troubleshooting IT Hard Drives Piracy Banking Google Wallet intranet Term Google Apps Download Telework Corporate Profile Smart Technology HTML Messenger Wireless Deep Learning Shortcut Knowledge Television Environment Browsers Smartwatch Telephony Nanotechnology Communitications Employer Employee Relationship Microsoft 365 Heating/Cooling Windows XP Software License Business Metrics Hosted Solution Social Networking Google Play Upload Procurement Cabling Social Network FinTech Tablet G Suite Books Mouse Society Data Analysis CES VoIP Business Owner Screen Reader IT Assessment Tracking Language Mobile Technology Value Security Cameras Trends Supply Chain Management Customer Resource management Organization Supply Chain Devices Cyber security Web Server Reading Monitors Visible Light Communication SharePoint Windows 8 Fileless Malware Smart Devices Digital Payment Tip of the week Company Culture Gamification Remote Working Worker Advertising Telephone System AI Access Workplace Regulations Trend Micro Relocation Staffing Displays Work/Life Balance IP Address Tech Support Directions Digital Security Cameras Time Management Inbound Marketing Backup and Disaster Recovery Electronic Health Records Public Cloud Transportation Desktop Wasting Time Content Electronic Medical Records Spyware Scams Accountants eCommerce Modem Audit Videos Database Surveillance File Sharing In Internet of Things Managing Costs Hacks Network Congestion Redundancy Electronic Payment Health IT Cache Cables Equifax Reliable Computing Recovery SSID Writing Competition Media Unified Threat Management Tactics Development Workers Hard Drive Disposal Employer/Employee Relationships Phone System LiFi Virtual Machine Entrepreneur Username Reviews Point of Sale Startup Optimization CCTV Scalability Documents Freedom of Information Application Printing Text Messaging Proactive IT Business Intelligence Navigation 2FA Touchscreen Addiction Administrator email scam Teamwork Mobile Security Hypervisor Computer Malfunction Bring Your Own Device Emergency Data Storage Shortcuts

Blog Archive

Recent Comments

No comments yet.

Interested In A Free Consultation?