Spear phishing in cloud-based small and medium sized enterprises: Development of guidelines for defence and prevention

Location:  Zoom link (Please ask Steven Schmidt for access)  

Date/Time: 03.05.2021, 14:00-15:30 

SPEAKER: Viktor Schlüter (TU Berlin)

Abstract: Phishing is an IT security attack vector responsible for billions of euros in damages worldwide, every year. Spear phishing is a more targeted form of phishing, often used for effective attacks against high value targets.  This thesis first presents an overview over the relevant research literature and then develops guidelines that collect research insights on how companies can prevent spear phishing attacks. The guidelines specify machine-centered measures such as secure configuration of the mail systems and human-centered measures such as phishing trainings. These guidelines are evaluated in a small user study with three companies and the resulting training data is analyzed, leading to the conclusion that in this study the guidelines showed a significant training effect.



