85 percent of organizations have suffered phishing attacks!

That is straight from the Wombat 2016 State of the Phish report.  Is that depressing or what!  The sad thing is, phishing can be thwarted most of the time.  But, it requires diligent training of your ENTIRE staff.  Including the board members, owners, executives and doctors.  Everyone needs to be trained to identify phishing attacks and resist opening the link and/or attachment.

Phishing - White Word on Red Puzzles on White Background. 3D Render.

A few stats from the report.

  1. 85% of organizations have suffered phishing attacks.
  2. 37% of executives have been victims of phishing.
  3. 30% of phishing emails get opened.
  4. #1 delivery of malware is via email attachments.
    1. #2 delivery of malware is web based.
    2. #3 delivery of malware is hyperlinks in email.
  5. 250% increase in phishing attacks in first quarter of 2016.
    1. You are under attack by the cyber criminals.
  6. 93% of phishing emails carried ransomware.
  7. Average cost of a phishing attack is $1.6 million.  Obviously, this is because huge corporations have experienced successful phishing attacks.  But, never the less a phishing attack will cost your dearly.

Jonathan Crowe at Barkly has a great blog with charts for more details.  He also has a Phishing Field Guide: How to Keep Your Users Off the Hook

Here are a few tips to help you avoid catching the wrong phish (malware, computer bug).

  1. Train your staff on cyber security.  Our HIPAA course covers phishing and other cyber security training.
  2. Train your staff using a false phishing campaign.
  3. Configure your email to filter out phishing emails.
  4. Double check the email address is from someone you know.  Otherwise, you should probably NOT open it.
  5. Double check the url, does it go to the right web site?  Do you recognize the url, does it make sense?
  6. Not sure about an email?  Call and talk to the sender first.
  7. Turn off macros if asked when opening any file.
  8. Setup an email gateway to block all attachments and require users to download expected attachments from the server.

Here are some free phishing simulators you might try http://resources.infosecinstitute.com/top-9-free-phishing-simulators/.  The DOD also offers a free phishing test tool at http://iatraining.disa.mil/eta/phishing_v2/launchpage.htm.

Hope these tips help you protect your patients, protect your practice, and protect yourself.

@barklyprotects, #phishing