Phishing Explained and Tips to Protect Your Firm Against a Phishing Attack

Phishing Explained and Tips to Protect Your Firm Against a Phishing Attack

In recent years, the tactics employed by cybercriminals have become ever more inventive and sophisticated, and today’s hackers now employ a wide range of methods to infiltrate both personal and corporate data. Indeed, modern cybercriminals have even started turning to artificial intelligence (AI) to detect weaknesses and backdoors in corporate security and autonomously launch attacks.

While there are some obvious steps you can take to protect your firm’s data from the more common types of attack, one method used by online criminals is notoriously hard to detect and prevent – namely, the new security phenomenon of phishing.

What is a phishing attack?

Phishing is a form of social engineering that aims to exploit our basic human nature to trust. In a phishing attack, a hacker will masquerade as a trusted source or entity, typically by email, to persuade the target to part with personal or sensitive details that can thereafter be used against them. Typical examples include posing as the target’s bank to request a password update or even making a mock website branded to look just like the one of the original trusted source.

Why is phishing so dangerous – and so hard to prevent?

Phishing mostly occurs by email and is almost impossible to detect by modern anti-virus and security systems. Unlike other forms of cyberattacks like malware or ransomware, there is no infected software to alert a security program – so the best prevention against phishing boils down to educating your staff to spot the tell-tale signs.

How to help prevent falling victim to a phishing attack

Of course, for the best protection, you could (and should) install email authentication and encryption systems like those provided by Proofpoint, but, even then, it’s a good idea to educate your staff.

In recent years, there has been a growing problem in many firms with staff using their own devices on corporate networks. These so-called bring your own device (BYOD) issues potentially leave networks wide open to attack if employees connect with an infected device, so it makes good sense to teach your staff how to spot the tell-tale signs of potential phishing emails, including:

Requests for personal information: No reputable organisation or business will ever ask for sensitive information by email, so you should never reply to an email asking for passwords or personal data.

Don’t click links in suspicious emails: A common tactic used in a phishing attacks is to redirect the user to an infected web page, so avoid clicking links in emails that look suspicious. You simply don’t know where the link might take you.

Avoid opening email attachments unless you’re 100% sure where they came from: In some cases, a phishing attack will involve sending infected attachments – however, the rule of not opening files attached to emails stands as sound advice against all potential security issues.

Check the sender address: It’s very easy to title the sender address of an email as being from a trusted source; however, just hovering your mouse over the address often reveals a very different story. If an email purports to have come from a respected source – but you remain in doubt about its authenticity – you should contact the firm’s customer support department to check if it’s real.