Free Phishing Test
SECURITY AWARENESS CULTURE

Phishing in Your Company – It Happened. What Next?

05-apr-2022 5 minutes read

Huge financial losses, a data breach affecting contractors, the loss of key customers’ trust—and ultimately insolvency and bankruptcy. Does that sound like a nightmare? Unfortunately, it does not have to be fiction.

Your company could face this scenario after a successful phishing attack. One of the most common consequences of such an attack is the exposure of personal data. Under the GDPR, this can result in a fine of up to EUR 10 million or 2% of the company’s annual turnover.

So is your company prepared to withstand an attack? Do your employees know how to recognize one and what to do if it happens?

What to do when an employee has been targeted?

When a phishing attack hits a company, keeping a clear head is essential. Emotions run high, which is why the targeted employee should follow a defined response plan.

Time matters. Every company should prepare for its most important risks and document clear security procedures that explain what to do step by step. Anyone who falls victim to a cybercriminal must know where to find those procedures and whom to notify.

15 key questions for CISOs:
Check if your company is ready for modern cyberattacks

The person responsible for incident response—such as an IT specialist—takes control of the situation. They work to contain the attack, limit its impact, preserve evidence and restore normal operations.

Key actions for the incident handler

  • Isolate the employee’s system from corporate resources to protect other computers, servers and cloud data and to begin the investigation. In practice, this means:
    • disconnecting the computer from the network and domain,
    • carrying out an initial analysis,
    • preserving evidence,
    • quarantining the device or restoring the system from a trusted image.
    • Terminate all active sessions associated with the employee’s account.
    • Check whether the compromised system was used for further activity inside or outside the company, and monitor the affected account for signs of misuse.
    • If the employee’s password may have been compromised, reset it immediately and replace it with a unique password. If the same password was used elsewhere, change it there as well. Review recent activity on every account that used the password, preferably in the relevant logs.
    • Verify whether other employees were targeted by the same or a similar campaign. Not everyone will notice an attack or report it.
    • For a serious incident, consider engaging an independent digital-forensics specialist, at least during the initial response. An external specialist can assess the situation without the assumptions and context that may influence the internal team.
    • Carry out a data-breach analysis and implement appropriate remediation measures.
    • For a personal-data breach, assess the likely impact on the affected individuals and the risk to their rights and freedoms. Immediately notify your Data Protection Officer or the person responsible for personal-data protection.

    If the breach is likely to pose the following level of risk to individuals’ rights and freedoms:

    • High: report the personal-data breach to the Polish data-protection authority (UODO) and notify the affected users. The notification must be made within 72 hours of becoming aware of the breach.
    • Low: for example, where the data is not sensitive in the context of the risk, or the stolen records were encrypted and are unlikely to be decrypted, notify UODO without necessarily notifying the users. Failure to report a breach or inform users when required may result in a fine of up to EUR 10 million or 2% of the company’s annual turnover.

    Preventing phishing attacks

    Phishing is a global and costly problem. More than 90% of cyberattacks begin with a social-engineering technique such as phishing. Suspicious messages land in corporate inboxes every day. It is easier for cybercriminals to manipulate a person than to bypass technical controls. Phishing is so effective because it exploits human weaknesses and susceptibility to manipulation.

    When employees recognize and report phishing, they can protect the company from serious losses—even bankruptcy. Every organization must address security at both levels: technology and the security-awareness skills of its people. That applies to prevention as well as incident response.

    1. Educate your employees. Building awareness of cyber threats takes time and practice. The sooner you start, the sooner employees can recognize an attack and respond appropriately.
      • Act strategically by building a security culture.
      • Act consistently. Planned, regular activities produce the best results. Practical training and attack simulations build safer habits and the ability to recognize attempts to compromise your organization.
      • Keep security visible and reinforce the message over time.
      • Set clear security requirements. Credentials for systems, email, bank accounts and payment cards are prime targets. Teach employees good security practices, require unique passwords stored in a password manager, and protect accounts with multi-factor authentication (MFA or 2FA). Enforce MFA on corporate systems, require strong passwords, restrict access to data and use software controls to enforce security procedures wherever possible.
      • Measure behavior. Check how employees respond to simulated threats and measure both their susceptibility and the organization’s overall risk.
      • Motivate and engage. Make security part of the company’s culture and encourage employees to share good practices with their families and apply them in their private lives.

    Do not leave your employees to face hackers alone. Cybercriminals often operate in specialized criminal groups and use increasingly convincing social-engineering techniques.

    Consider Practical Anti-Phishing Training. Use our experience to strengthen your employees’ ability to recognize phishing and to test and develop their practical response skills.

Gain specialised knowledge about cybersecurity

Build a resilient cybersecurity culture with our support

Let's discuss your organization's cyber needs

Fill in the form

Would you like to test the resilience of your systems?

Fill in the form to schedule a free, no-obligation consultation. We will discuss the scope of the penetration tests and prepare a proposed approach tailored to your organization and infrastructure.
Would you prefer to speak to us directly?
+48 732 123 579