Urgent.News

What's breaking now, across thousands of outlets.

Tech

‘The gap was not the awareness’: The company phishing trainings you loathe aren’t enough when nearly 1 in 4 security pros say their MFA is optional

Most security pros surveyed call their company secure, yet 44% say an AI-driven phishing attack got through last year.

‘The gap was not the awareness’: The company phishing trainings you loathe aren’t enough when nearly 1 in 4 security pros say their MFA is optional

New survey data reveals that despite most employees receiving security training, nearly a quarter still consider their company's multifactor authentication (MFA) policies optional. The study, conducted by Yubico and Okta, found that 82% of 1,890 technology and security professionals had undergone employer security training; however, 23% of respondents believed their organizations did not mandate MFA for all applications and services. This discrepancy exists despite 88% of respondents describing their enterprise as secure.

Cybersecurity experts warn that while awareness is crucial, it is not enough to prevent employees from falling for convincing phishing scams. Lorrie Faith Cranor, director of Carnegie Mellon University's CyLab, explains that phishing attacks often exploit real needs, such as job opportunities, immigration issues, or pleasing superiors. Even employees with good habits can be distracted, making them vulnerable to sophisticated phishing attempts.

The survey also revealed that 55% of respondents received personalized phishing attacks, and 44% reported their organizations had experienced at least one successful AI-driven phishing attack in the previous year. Phishing messages are becoming increasingly difficult to detect, as they are often written by AI agents with perfect grammar and mimic corporate style and branding. Cranor noted that even advanced warning signs, such as typos, are less reliable due to AI-generated phishing messages.

To enhance security, the report recommends incorporating stronger authentication methods into the onboarding process. While 52% of employees received username-and-password credentials upon starting their roles, the study did not clarify whether these accounts also required MFA. Passkeys, which use cryptographic credentials tied to legitimate sites, can provide better protection but do not prevent account access theft through gift card purchases.

Cranor emphasized that MFA offers substantial protection but can be vulnerable to various attacks. For example, text-message codes can be compromised if an attacker convinces a mobile carrier to transfer a victim's number to their own phone. Similarly, authenticator apps can be undermined if a scammer poses as a help-desk employee and requests users to read out a code. Cranor stressed the importance of never sharing MFA codes.

Training remains essential, but it should focus on teaching concrete skills and providing practical practice. Employers should also integrate verification procedures into employees' daily tasks, such as double-checking requests that appear to come from superiors but seem suspicious. However, Cranor pointed out that many existing training efforts have not been rigorously evaluated, and employers should conduct controlled experiments to assess the effectiveness of their security awareness programs.

Written by urgent.news from Fortune's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at fortune.com →

More in Tech

Why "Delete This" Messages Sometimes Never Arrive

Think about a hostel or PG. When you check out, you're supposed to tell the warden, and the warden marks your room as free. Simple system. Works fine until the day it doesn't.

  • "Delete This" messages may never arrive if app crashes or network glitches.
  • Software systems rely on "tell them" approach for resource release.
  • Regular reconciliation prevents lingering errors from unconfirmed completions.

More from Friday 9 October →