BankInfo Security is reporting on soon to be published research which demonstrates that training to help workers avoid clicking on links from spear-phishing e-mails is generally ineffective.  Report co-author Eric Johnson, a Vanderbilt University professor, told BankInfo Security:

There’s just something in there, even for the most astute security folks. When you get a link that looks like it’s real, looks like it came from a friend, has a compelling message, it’s very hard to pull the finger back from the mouse.

 

The research paper is available for purchase at the IEEE.

Spearphishers deceive people into making bad email decisions that compromise security. Training doesn’t’ work. IT needs to help employees make better email processing decisions. That is where SP Guard comes into play. Using SP Guard, IT can determine a list of trusted senders and provide this information to staff in a simple and highly effective manner.

You can contact us at  408-727-6342,ext 3 or use our online form.