Industry specific results illustrate business implications and highlight knowledge deficiencies in end-user cybersecurity knowledge
PITTSBURGH, Sept. 19, 2017 - Wombat Security Technologies (Wombat), the leading provider of cyber security awareness and training, today announces the release of its 2017 Beyond the Phish Report. The analysis of more than 70 million questions and answers – a significant increase from 20 million in 2016 – across 10 categories identifies strengths and weaknesses tied both directly to phishing and threats beyond the phish. The report examines end-user knowledge of business-critical best practices such as data protection measures, mobile device security, safe social sharing and password hygiene. Understanding of these knowledge levels is critical as poor cyber hygiene in these areas can compound the phishing threat and weaken security postures in general.
Though there is a modest overall improvement in the rate of questions answered incorrectly compared to 2016, a drop of nearly 10%, gains and losses in various categories offset each other. In addition to analyzing results by category level, Wombat also examined industry data to see how various industries compared on both a general and category-specific level. Highlights from the 2017 User Risk Report are incorporated throughout to compare knowledge levels to admitted end-user behaviors.
“We continue to see in our year-over-year results that reinforcement and practice are critical to learning retention. As with any learned skill, organizations need to work on cybersecurity awareness and knowledge to see continual improvements,” said Joe Ferrara, President and CEO of Wombat. “Organizations that focus on building a culture of security and empowering their employees to be a part of the solution develop the most sustainable and successful security awareness training programs. By sharing our data in the Beyond the Phish Report, we hope to be a part of building those cultures and helping organizations successfully change behavior in previously undiscovered areas of vulnerability.”
Key areas from the report analysis that reveal room for improvement include the following:
While there is always room for improvement with regard to managing end-user risk, the 2017 Beyond the Phish Report also highlights categories and industries in which employees are improving year-over-year and have answered the highest percentage of questions correctly:
Furthermore, the 2017 Beyond the Phish Report shows it’s important for organizations to use a combination of simulated attacks and question-based knowledge assessments to evaluate their end users’ susceptibility to phishing attacks. For example, the 2017 State of the Phish Report revealed an 18% click rate on phishing attacks with healthcare employees, yet 26% of questions around phishing were answered incorrectly in this same industry. Using both types of assessment tools gives a more complete picture of vulnerability.
About the Beyond the Phish Report
The 2017 Beyond the Phish Report evaluated more than 70 million questions answered by the end-users of Wombat Security customers in ten categories within Wombat’s CyberStrength® Knowledge Assessments and training modules from June 2016 through May 2017. The report highlights strengths and weaknesses tied both directly to phishing and goes beyond the phish to analyze knowledge of other business-critical practices, including data protection measures, mobile device security, safe social sharing, and password hygiene. You can download the full report here.
About Wombat Security Technologies
Wombat Security Technologies provides information security awareness and training software to help organizations teach their employees secure behavior. Their SaaS-based cybersecurity education solutions include a platform of integrated broad assessments, as well as a library of simulated attacks and brief interactive training modules. Wombat's solutions help organizations reduce successful phishing attacks and malware infections up to 90%. Wombat, recognized by Gartner as a leader in the Magic Quadrant for Security Awareness Computer-Based Training Vendors, is helping small and medium businesses, as well as Fortune 1000 and Global 2000 customers in industry segments such as finance and banking, energy, technology, higher education, retail, and consumer packaged goods to strengthen their cybersecurity defenses.
Wombat Security Contact:
412-621-1484 x 126