APJ Security

APAC IT decision-makers woefully underprepared for cyber risks

Jacqueline Jayne

Only 3% can correctly identify which emails and SMS are legitimate or scams  and fewer than half know the steps to take following a data breach.

 KnowBe4, the provider of the world’s largest security awareness training and simulated phishing platform, today announced new research which has found IT decision-makers are complacent about risks to the business from phishing and BEC (Business Email Compromise – also known as CEO Fraud). Surprisingly, fewer than half (45 percent) of APAC IT decision makers say they are concerned about phishing as a risk to their organisation, while even fewer are concerned about BEC (34 percent).   

When asked to determine whether example emails and SMS were real or fake, only three percent of APAC IT decision-makers were able to correctly identify them all. In addition, more than a quarter (27 percent) of APAC IT decision-makers use their work phones for personal activity and 25 percent use their work email address for personal activity.  

Jacqueline Jayne, Security Awareness Advocate for APAC at KnowBe4 is concerned: “When those charged with keeping a business secure are unaware of the risks and unable to identify scam emails and SMS messages, their organisations are at significant risk. According to the ACCC, Australians lost a record $323 million to scams in 2021 (up a massive 84 percent from the previous year) and Singapore’s Anti-Scam Centre states Singaporeans lost $201.7million in the first half of 2021. If those in charge of security are unaware of best practices, then they cannot educate and train employees. ”  

“When employees are using their work email address for personal activities such as online shopping, they are much more likely to fall victim to a phishing attack that uses a hook such as delivery delays to entice the victim to click through. Having a clear separation between work and personal activities makes it much easier to spot when an email is a scam – if you know you never shop online using your work email address, then you know that email from Amazon cannot be real.”  

“When employees are using their work email address for personal activities such as online shopping, they are much more likely to fall victim to a phishing attack.”

Jacqueline Jayne, Security Awareness Advocate for APAC at KnowBe4

Data breach protocol  

Alarmingly, fewer than half (46%) of APAC IT decision-makers say they are confident they would know the steps they would need to take following a cyber incident or data breach in their organisation.   

Furthermore, just four in ten APAC IT decision-makers believe the employees in their organisations understand the business impact of falling victim to a cyber attack (47%), are confident their employees can identify phishing and BEC emails (42%) and that their employees report all emails they believe to be suspicious (39%).


Read More News: https://www.enterpriseitworld.com/security/ I Watch CIOtv: https://ciotv.live/ I Read IT Partner News: https://www.smechannels.com/

Related posts

New Cyber Risk Management can Anticipate and Eliminate Breaches

enterpriseitworld

ALE Launches Purple on Demand in Asia Pacific

enterpriseitworld

Cisco reimagines security with Hypershield

enterpriseitworld
x