{"id":4608,"date":"2024-06-01T08:09:26","date_gmt":"2024-05-31T20:09:26","guid":{"rendered":"https:\/\/ostermanresearch.com\/2024\/06\/01\/some-thoughts-on-fortras-phishing-benchmark-global-report-2023\/"},"modified":"2025-03-10T16:47:56","modified_gmt":"2025-03-10T03:47:56","slug":"some-thoughts-on-fortras-phishing-benchmark-global-report-2023","status":"publish","type":"post","link":"https:\/\/ostermanresearch.com\/2024\/06\/01\/some-thoughts-on-fortras-phishing-benchmark-global-report-2023\/","title":{"rendered":"Some thoughts on Fortra&#8217;s Phishing Benchmark Global Report 2023"},"content":{"rendered":"\n<p>Fortra published a report presenting the findings from its phishing simulation exercise in October 2023 with around 300 organizations and 1.37 million individual participants. The <a href=\"https:\/\/www.fortra.com\/resources\/press-releases\/fortras-terranova-security-unveils-latest-global-phishing-benchmark-report\" target=\"_blank\" rel=\"noreferrer noopener\">press release<\/a> presents the highlights. Full details are available in the <a href=\"https:\/\/www.terranovasecurity.com\/resources\/guides\/gone-phishing-report-2023\" target=\"_blank\" rel=\"noreferrer noopener\">report<\/a> itself (registration required).<\/p>\n\n\n\n<p>Key findings per the report:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>On receiving the phishing simulation message, 10.4% of all recipients clicked the link. This opened a web page that masqueraded as a valid site and asked for username and password details. Of those who had clicked, 65% entered their details and lost their credentials. Here&#8217;s one of the diagrams from the report.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2024\/06\/terranovadata.jpg?ssl=1\" alt=\"\" class=\"wp-image-371\"\/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Aaarrgghhh.<\/li>\n\n\n\n<li>Per Fortra, &#8220;<em>Phishing links don&#8217;t click themselves &#8211; human beings, however well-intentioned, do.<\/em>&#8220;<\/li>\n\n\n\n<li>Click rates varied by industry &#8211; education was worst (16.7% vs. 10.4% average), finance was best (6.3% vs. 10.4% average). There&#8217;s a full breakdown in the report.<\/li>\n\n\n\n<li>The percentage of recipients-who-clicked-the-link who then submitted their password also varies by industry. Education takes worst place again &#8211; 72.8% of those who clicked lost their credentials. Finance is third from best, at 45.2%. Agriculture and food were in first place \/ best place &#8211; at 29.1%.<\/li>\n\n\n\n<li>A decade ago, the <a href=\"https:\/\/www.researchgate.net\/publication\/289254657_2013_Verizon_Data_Breach_Investigations_Report\" target=\"_blank\" rel=\"noreferrer noopener\">Verizon 2013 Data Breach Investigation Report<\/a> said this about the mathematics of phishing: sending 10 phishing messages almost guarantees a click. Put another way, 10%. Page 38 of the VDBIR 2013 has this box:<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2024\/06\/vdbir2013.jpg?ssl=1\" alt=\"\" class=\"wp-image-373\"\/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>A decade later, click rates remain the same or are slightly worse.<\/li>\n\n\n\n<li>Yes, users need to be trained &#8211; especially as threats become more sophisticated due to AI, phishing toolkits, MFA bypass as routine, etc. Don&#8217;t stop doing that. But &#8230; revisit \/ reassess \/ recheck the efficacy of whatever technical protections you are using and keep those phishing and BEC emails as far away from a user&#8217;s inbox as possible.<\/li>\n\n\n\n<li>On that note, you should read our report on the role of <a href=\"https:\/\/ostermanresearch.com\/portfolio\/orwp_0358-ai-email-security\/\" data-type=\"jetpack-portfolio\" data-id=\"4153\" target=\"_blank\" rel=\"noreferrer noopener\">AI in email security<\/a>.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Fortra&#8217;s report on a large phishing simulation test found that 10.4% of users clicked the link. A decade ago, Verizon&#8217;s data said 10%. Aarrgghh.<\/p>\n","protected":false},"author":384585,"featured_media":4724,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[712027195,712027178],"tags":[712027521],"class_list":["post-4608","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-email-security","category-phishing","tag-research-reports-we-didnt-write"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2024\/06\/fortra2024.png?fit=1100%2C350&ssl=1","jetpack_likes_enabled":true,"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/pcHAk4-1ck","_links":{"self":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/4608","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/users\/384585"}],"replies":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/comments?post=4608"}],"version-history":[{"count":3,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/4608\/revisions"}],"predecessor-version":[{"id":4725,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/4608\/revisions\/4725"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/media\/4724"}],"wp:attachment":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/media?parent=4608"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/categories?post=4608"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/tags?post=4608"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}