By Ray Birch
DES MOINES, Iowa—It’s time more credit unions change the way they train staff to defend against cyber threats—and one area needing greater attention is mobile device usage, asserts one security expert.
Corey Skadburg, COO of cybersecurity training firm BrightWise, told CUToday.info adjustments need to be made not only to account for how crooks are changing their tactics, but to also align with ways employees like to learn.
As CUToday.info has reported, cyber security experts have consistently stressed the importance of staff cyber defense training, as employees can be the company’s strongest defense—or greatest weakness—against hackers.
Skadburg agrees, saying while organizations are making excellent strides in training staff on the right things to do to protect the company—such as not opening suspicious emails or clicking on links in messages that are not from a trusted source—many are overlooking the growing threat from mobile attacks.
Crooks Look to Mobile
For example, Skadburg said as employees are getting better at not falling for phishing attacks on their laptop or desktop devices, crooks are now turning more of their attention to mobile.
“The majority of phishing attacks are still happening through email, over a laptop or desktop, but more of these threats are moving toward phones,” he said. “Criminals are using social media, text messaging, and more.”
Skadburg explained part of the problems is many more employees are using their mobile phones and devices for work now.
“And it's easier for attackers to send a phishing attack through your mobile device, because an attack is just not as top of mind when people are using their phone,” said Skadburg. “Plus, the screen isn't big, so you can't really see the links as well. All this makes it easier for fraudsters to trick you and compromise your phone.”
Using The CU’s WiFi
Skadburg said mobile device compromises open up a whole new range of access points for crooks to invade the credit union’s systems.
“If your phone is connected to your company network, hackers can swim into the system that way,” said Skadburg. “Let's just say you connect your phone to your company's Wi-Fi network; you enter your login and password and now the crook steals those credentials. They can then use those credentials to log into the credit union’s system and they’re in. They can even get in if your phone is infected and you plug it into your computer to charge it. Also, once they compromise your phone they can get all your contacts and send messages to them that look like they came from you.”
Not only does cyber defense training need to focus more on mobile, but many companies need to change the way they train staff, argues Skadburg, saying too many organizations rely on once-a-year, one-hour formal training in a classroom setting. What he contends is needed is more on-demand, shorter training modules delivered in “bite-size,” more easily digestible chunks. He also said that’s a better way to train to keep up with crooks’ changing tactics.
“The majority of organizations do security awareness training once a year. It's 30 to 60 minutes and it's boring. It's PowerPoint, blah blah blah. Instead of doing once a year formal sit-down training, offer different types of training on demand. Break up your training throughout the year.”
To Get Serious, Make it Fun
And find ways to make it fun, insisted Skadburg, who believes gamification is a good fit for cyber security education.
“Build a gamified leaderboard. Names of employees who do well in the training games are displayed alongside emoji-esque trophies and other digital carrots that show off their status as stand-out employees,” he suggested. “A lot of companies are starting to do gamification in their overall training, and it really brings out the competitive side of people—people like to compete. You can give away fun and inexpensive prizes for top performers, like a jeans day or an extra vacation day. People like these leaderboards, they like to see their names at the top.”
Outside Threats, Outside Settings
Training can even take place outside of a traditional company setting, said Skadeburg.
“Host after-hours social events, a trivia night or another competitive activity. It’s teaching through fun, and it’s a great way to learn. You can showcase some of the latest threats, ways to prevent the attacks, get people talking more about cyber security, and just bring greater awareness of these threats to your team,” he said.
Skadburg emphasized mobile has to become a bigger part of the security discussion.
“Make sure employees know their phone is not any more safe than their desktop and they should be taking the same precautions on their phones as they do with their desktops,” he said. “Anything that can happen on the desktop can happen on their cell phone, and in many cases things could be worse. Because once crooks have access to your phone they have access to a lot of data because people store so much information on their phone. Staff need to be really careful when using their phones for work purposes.”
