Train Your Staff to Recognise Threats
Most cybersecurity awareness, education, and training programmes assume staff to be in a rational mode when making cybersecurity decisions, despite humans only processing decisions consciously five percent of the time.
Cyber awareness programmes should consider the other ninety-five percent of the time by helping your staff build alternative decision-making strategies that can form into habits over the long term.
Methods of Persuasion
Authority
This is one of the most widespread and successful methods of persuasion found in phishing emails. Phishing emails using authority takes advantage of the fact that humans trust the opinions of experts and use this as a shortcut to decision-making.
These emails come from fictitious senders in powerful positions such as company CEOs, and could incorporate displays of awarded accolades and accreditations.
Scarcity
This is another powerful persuasion technique used regularly to build urgency, such as stating there only be 24 hours to update system details or an account will be suspended.
Humans want the things they cannot have, so social engineers limit the quantity of time within their emails to motivate recipients into fast action.
Commitment and Consistency
Cybercriminals also often use commitment and consistency by naming recipients as customers or readers. This leaves them needing to remain consistent with their previous decisions even if the claims are not true.
Liking and Similarity
It is an approach that sits in the middle of both usage and success rates, using rapport and compliments to get recipients to carry out their suggested threat action.
This can be seen in phishing emails from potential LinkedIn connections who compliment your work and suggest they have similar areas of interest.
Reciprocity
This is ‘middle of the road’ in relation to usage and success rate. ‘Free gifts’ or ‘discounts’ are offered in return for recipients interacting with links or attachments. Humans feel a need to repay debt, so if a gift is offered the recipient will feel compelled to conduct the threatening action.
While reciprocity may work well in a home-based context the offer of free gifts may appear out of place in the workplace.
Social Proof
This is used less frequently but can still occur. Social proof relies on us as humans following the lead of others with whom we are associated with. Phishing emails now ask recipients to forward an email to peers who may be interested, with the recipient, in turn, becoming social proof to those they email.
Curiosity
Cybercriminals use this additional method to move one outside of an email to learn more. While it is used regularly, its current success rate is low. This is potentially due to using a simple method that is easy to deploy, e.g. just sending a link but in the hope that at least some percentage will catch the bait.
OutThink
FUEL has partnered with OutThink to include its award-winning human risk management platform as one of the software solutions we offer our clients.
To find out how the OutThink Cybersecurity Human Risk Management platform raises awareness, drives more secure behaviours, and increases motivation across an organisation, please get in touch with us at FUEL Online. info@fuelonline.co.za