Show notes
Ep 2: Vishing Increases Phishing Success Rate by 3 TimesEpisode 2 reviews an article on InfoSecurity Magazine. Phishing was the number 1 threat vector in 2021 closely followed by vulnerabilities. For clarity, vulnerabilities are defined as software and hardware glitches the manufacturer has issued patches or updates for which the owner of the software or hardware has yet to update.What made the phishing statistic more interesting is that when a phishing attack included vishing (voice phishing) the success rate was nearly 3 times higher than phishing attacks without vishing. Of course, I have a real-world example of exactly how such an attack would work.Here’s the original article on InfoSecurity MagazineTranscript of Ep 2: Vishing Increases Phishing Success Rate by 3 TimesPeople are the weakest link in any cybersecurity plan. We’re distracted, exhausted, and often unmotivated. It’s time to change the approach used to protect our businesses, technology, identity, and data. The human element has to be front and center in the war against data breaches and ransomware attacks it’s time to educate.Welcome to the human element podcast, visit our website at thehumanelement.net for more content to help you strengthen your awareness of the people problem in cybersecurity. I am Scott Gombar. Owner and Washtech is a client-focused, security-minded proactive IT service provider. Welcome to episode two vishing makes phishing campaigns three times more successful. Hello, everyone. Scott Gombar, owner of Nwaj Tech, we are back again with the second episode of the human element podcast where we talk about well the human element of data breaches and ransomware attacks and cyberattacks and all that fun stuff. And today, I’ve got an article on info security dash magazine.com info security magazine. And the title of the article is vishing makes phishing campaigns three times more successful by Phil Muncaster. And the article talks about the number one and number two threat vectors for 2021. Last year and number one probably shouldn’t come as a surprise given what podcast you’re listening to is Phishing. Phishing was 41% or globally. Phishing overtook vulnerability exploitation as the top pathway for compromise globally, in 2021, accounted for 41% of initial access attempts, which is up 33% from 33%, in 2020, so it went from 33% to 41%. And the number two threat vector was vulnerabilities and that is identified software holes, I guess you could say in different software and hardware. So in other words, if I have a Microsoft Windows computer, Windows 10 computer, and patch Tuesday rolls around, and I don’t apply those patches and some of those patches are for critical vulnerabilities are a zero-day. And I don’t apply those patches and my computer is now vulnerable. That’s a vulnerability and the number two threat vector for 2021 was vulnerabilities. So the number one phishing number two vulnerabilities and the number of vulnerabilities was 30. Or to go 33%. I think it was 33%. It’s interesting because I wrote an article not too long ago on my company’s website and nwajtech.com. And nwajtech.com. And the article was about the big four and talked about phishing, we talked about the Big Four, by the way, it was about the four easiest ways into a business into a network into technical or technology-based structure infrastructures. And we talked about the four easiest ways in. Two of them were phishing and unpatched software hardware. And in the article talks about some of the more common commonly exploited vulnerabilities one from 2021, which was a Java, Java, D serialization Volden vulnerability,



