Social Engineering and the Value of Data: The Need of Specific Awareness Programs

ADVANCES IN HUMAN FACTORS IN CYBERSECURITY(2020)

引用 3|浏览8
暂无评分
摘要
In the field of cybersecurity human factor is considered one of the most critical elements. Security experts know well the importance of people's security behaviors such as managing passwords, avoiding phishing attacks and similar. However, organizations still lack a strong cybersecurity culture to manage security risks related in particular to the human factor. In this paper we describe the results of a study involving 212 employees belonging to two companies operating in the service sector. Within a cybersecurity awareness project executed in each company, employees participated in workshop sessions and were asked to evaluate the credibility and the success probability of a list of the most common security risk scenarios based on social engineering techniques. Cyber-attacks based on these techniques are considered among the most successful because use psychological principles to manipulate people's perception and obtain valuable information. The comparison of results obtained in the two companies shows that awareness training programs pay off in terms of raising people's attention to cyber-risks.
更多
查看译文
关键词
Human factors,Cybersecurity,Social engineering,Cyber hygiene,Awareness
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要