• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

My TechDecisions

  • Best of Tech Decisions
  • Topics
    • Video
    • Audio
    • Mobility
    • Unified Communications
    • IT Infrastructure
    • Network Security
    • Physical Security
    • Facility
    • Compliance
  • RFP Resources
  • Resources
  • Podcasts
  • Subscribe
  • Project of the Week
  • About Us
    SEARCH
IT Infrastructure, Network Security

Phishing Click Rates Mean More Training, Awareness are Needed

Large enterprises with at least 10,000 employees have the highest phishing click rates, according to a new report from Terranova Security.

February 1, 2023 Zachary Comeau Leave a Comment

Phishing Success rates
Rogatnev/stock.adobe.com

Large enterprises with at least 10,000 employees are the most susceptible to phishing schemes that promise a gift despite having access to more cybersecurity resources than smaller businesses, according to a new report on phishing link click rates from Terranova Security, a subsidiary of Fortra (previously HelpSystems).

The report is based on the 2022 Gone Phishing Tournament hosted by Terranova Security and co-sponsored by Microsoft, which evaluated how employees respond to phishing attacks. The 2022 Phishing Benchmark Global Report finds that all organizations need to continue to implement security awareness and training programs to educate end users on phishing attacks.

Over 250 organizations and 1.2 million users participated in the tournament, making it one of the largest phishing tournaments of its kind and a real-life example of how successful phishing attacks still are today.

According to the report, 7% of all end users at large enterprises who participated in the 2022 phishing simulation clicked on the link in the phishing email, and 3% failed to recognize the warning signs of the simulation’s webpage and entered their credentials on the malicious page.

While those phishing click rate totals are seemingly low, it only takes one privileged end user to click on a malicious link or enter their credentials for attackers to find their way into an organization’s network.

Additionally, this year’s form completion total is concerning, as 44% of those who clicked on the phishing simulation link eventually completed the web form on the subsequent webpage and submitted their credentials.

To put those numbers in perspective, an enterprise-level organization with 10,000 employees targeted with a phishing attack would have seen 700 of their employees lick n the phishing link, and over 300 of those would have entered their credentials.

“Given our reliance on online systems and data to conduct many business transactions and services, this is really concerning,” says Theo Zafirakos, chief information security officer at Terranova Security.

The report suggested that larger organizations need to ensure that end users are completing their training and awareness programs, as they fared the worst. In fact, phishing success rates consistently increase along with the size of the organization. Phishing click rates at organizations with under 100 employees was 3.6%, 4.9% at organizations with 100 to 499 employees, 5.6% at organizations with 500 to 2,999 employees and 6.3% at organizations with 3,000 to 9,000 employees.

When separated by industry, nonprofit, education, manufacturing, and food and agriculture had the worst phishing click rates, with all scoring over 6%. Meanwhile, public sector, energy and finance industries kept their phishing click rates under 3.5%

However, this report indicates that end users are becoming more aware, as only 3% of all recipients failed to recognize the phishing webpage and submitted their credentials, which is down from 14.4% in 2021.

“The results from this year’s Gone Phishing Tournament underscore the importance of taking a human-centric approach to security awareness training and content,” says Brand Koeller, principal product manager of Microsoft Defender, in a statement. “Technical safeguards alone can’t guarantee information security. Addressing the human risk factor should be a top priority for all organizations.”

Tagged With: Cybersecurity, phishing, Terranova Security

Related Content:

  • Microsoft Loop IT What You Need to Know About Microsoft Loop
  • YAMAHA UC ADECIA Yealink Yamaha UC Partners With Yealink for Audio &…
  • Microsoft, ChatGPT, GPT-4, GPT-3.5 What’s New With ChatGPT and Generative AI This…
  • CISA Ransomware CISA Wants You To Report Anything You Know…

Free downloadable guide you may like:

  • Four IT Trends That Will Define 2023Expert Series: Four IT Trends That Will Define 2023

    Learn about four key technologies we identified as critical to your IT organization’s success in 2023, as well as how to invest in new innovations emerging from each.

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Get the FREE Tech Decisions eNewsletter

Sign up Today!

Latest Downloads

Four IT Trends That Will Define 2023
Expert Series: Four IT Trends That Will Define 2023

Learn about four key technologies we identified as critical to your IT organization’s success in 2023, as well as how to invest in new innovations ...

Harnessing the Power of Digital Signage
Harnessing the Power of Digital Signage

Choosing the best solutions for messaging, branding, and communicating in today’s content-everywhere landscape

Blueprint Series Cover: What works for hybrid work
Blueprint Series: What Works for Hybrid Work

Download this free resource to learn about how IT leaders can effectively manage and implement a hybrid work model.

View All Downloads

Would you like your latest project featured on TechDecisions as Project of the Week?

Apply Today!
Sharp Microsoft Collaboration HQ Logo

Learn More About the
Windows Collaboration Display

More from Our Sister Publications

Get the latest news about AV integrators and Security installers from our sister publications:

Commercial IntegratorSecurity Sales

AV-iQ

Footer

TechDecisions

  • Home
  • Welcome to TechDecisions
  • Subscribe to the Newsletter
  • Contact Us
  • Media Solutions & Advertising
  • Comment Guidelines
  • RSS Feeds
  • Twitter
  • Facebook
  • Linkedin

Free Technology Guides

FREE Downloadable resources from TechDecisions provide timely insight into the issues that IT, A/V, and Security end-users, managers, and decision makers are facing in commercial, corporate, education, institutional, and other vertical markets

View all Guides
TD Project of the Week

Get your latest project featured on TechDecisions Project of the Week. Submit your work once and it will be eligible for all upcoming weeks.

Enter Today!
Emerald Logo
ABOUTCAREERSAUTHORIZED SERVICE PROVIDERSTERMS OF USEPRIVACY POLICY

© 2023 Emerald X, LLC. All rights reserved.