What is Phishing?

Phishing is a type of social engineering where a criminal tries to entice information out of you.

Phishing comes in many forms with the most popular one being via email. Phishing by email is one of the most successful tools used by cyber criminals. 91% of successful targeted attacks begin with a Phishing email. Email is the one door in an organisation that is always open and it is therefore the one door always used by criminals to try and gain access.

A Phishing email will usually try and infer urgency on the user to do something. This could be to click on a link or open an attachment. There may be a further action on the linked web page to enter some personal or account details which are then stolen by the cyber criminal.

There are some good public resources to help users identify what a phishing email looks like and how to identify them.

There is also a very good Security awareness training document published by NIST which could be used by organizations looking to tackle this problem in a logical way.