10 steps to creating a corporate phishing awareness program

15
10 STEPS to Creating a Corporate Phishing Awareness Program

Upload: wiley

Post on 12-Feb-2017

879 views

Category:

Technology


1 download

TRANSCRIPT

Page 1: 10 Steps to Creating a Corporate Phishing Awareness Program

10 STEPSto Creating a Corporate Phishing Awareness Program

Page 2: 10 Steps to Creating a Corporate Phishing Awareness Program

Phishing awareness programs help enterprises protect themselves from phishing scams and breaches. It’s a highly effective way of educating employees and helping them spot phishing attacks.

Page 3: 10 Steps to Creating a Corporate Phishing Awareness Program

The ins and outs of such a program depend very much on the company, but here’s a basic outline of a typical program to give you an idea of what’s involved.

Page 4: 10 Steps to Creating a Corporate Phishing Awareness Program

Write a phishing e-mail that is realistic, current, and relevant and isn’t psychologically damaging to your staff

Page 5: 10 Steps to Creating a Corporate Phishing Awareness Program

Run that e-mail through the appropriate departments (such as HR and legal) to get approval, which will likely involve edits and new iterations

Page 6: 10 Steps to Creating a Corporate Phishing Awareness Program

Ensure your lists are updated—adding new hires and removing those who have left the company

Page 7: 10 Steps to Creating a Corporate Phishing Awareness Program

Prepare a proper educational landing page for people who click on the phish

Page 8: 10 Steps to Creating a Corporate Phishing Awareness Program

Load the system you will use with the e-mail lists, phishing e-mail, and landing pages

Page 9: 10 Steps to Creating a Corporate Phishing Awareness Program

Schedule and test the sending of the e-mail

Page 10: 10 Steps to Creating a Corporate Phishing Awareness Program

Ensure the e-mail is sent without any problems

Page 11: 10 Steps to Creating a Corporate Phishing Awareness Program

Collect all data, which might include number of clicks, number of people who report the phish, and so on

2615 8

Page 12: 10 Steps to Creating a Corporate Phishing Awareness Program

Report on the data, giving information in regard to positive or negative trends

2615 8

Page 13: 10 Steps to Creating a Corporate Phishing Awareness Program

Repeat the process each month or quarter

Page 14: 10 Steps to Creating a Corporate Phishing Awareness Program

As you can see, this is not a part-time job. Maybe you can hire someone to help you run this program internally or you might have someone on staff that is perfect for the job. But if you don’t have the staff, skill, or desire to run a phishing program internally then a consultant will be able to run it for you.

Page 15: 10 Steps to Creating a Corporate Phishing Awareness Program

For more on setting up and running a corporate phishing program, check out

PHISHING DARK WATERSThe Offensive and Defensive Sides of Malicious E-mails

by Christopher Hadnagy and Michele Fincher