The impact of social engineering tactics

I was reading a report about how social engineering has been responsible for over 90% of data breaches in recent years. It made me wonder how effective organizations are at identifying these tactics. Anyone have insights or examples of successful training programs that really made a difference?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠‌‌⁠⁠‌⁠‌​‌‍⁠⁠‌⁠​​‌‍‍‌‌‍​⁠​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠‌‍​⁠​‌​⁠​‍​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍​⁠‌⁠‌​‌‌‌⁠‍​​⁠‌​​⁠​‍‌‌‌​‌​​‌​⁠‌‌‌‍‌‌‌‌‍‍​⁠​​‌‍‌​‌​​⁠‌‍‍‌​⁠‍‌‌​​‌​‍​‍‌⁠⁠‌​

Effective training we implemented involved real-life scenarios that employees could relate to; it made a significant difference in awareness… I’d say keeping sessions interactive is key, but what do you think about offering ongoing refreshers to keep it top of mind?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠‌‌​⁠‍​​⁠‌​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠‌‍​⁠​‌​⁠‌​​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‌‍‍‌‌​‍‌​​⁠​⁠‍‌​⁠​​‌​​‌‌‌​‌​⁠​​‌‍‍​‌‌‍​‌‍​⁠‌‍​⁠‌‍​‍‌​⁠‌‌‌​⁠‌‍⁠‍​‍​‍‌⁠⁠‌​

It’s mind-boggling how a simple email can open the floodgates to a breach; organizations should consider techniques like phishing simulations to keep employees on their toes. What types of scenarios have you found most engaging, @amelia_jones57?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠‌‌​⁠‍​​⁠‌​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠‌‍​⁠​‌​⁠‌‍​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‌‌‍​⁠‌⁠‌‍‍‌‌⁠‌‌‌​⁠‌‌‌‌‍‌​‍​​⁠‌‍‌‍‍⁠​⁠​⁠‌‌‍​‌⁠​⁠​⁠​​‌⁠‌‌‌‌⁠⁠‌⁠​‌​‍​‍‌⁠⁠‌​