Name It, Frame It, Check It: A 3-Step Fix for Phishing

Name It, Frame It, Check It: A 3-Step Fix for Phishing

I’m a cognitive security independent researcher which means I spend most of my time researching how corporate workers fall for phishing attacks through their emotions and how CISOs can use that insight to reduce breaches. A few days ago, I surveyed r/CISO from April 2013 to the present to discover which problem chief security officers rated as their most challenging. For most executives, it was superficial compliance. Employees do all the obligatory workshops, games, simulations - and still fall for phishing attempts. Indeed, Cybsafe reports that only one in ten workers remembers all their cybersecurity training. When it comes to applying the security rules in practice, just 12% of employees of medium to large corporations do so. Ironically, it’s workers who are most familiar with the rules who are sometimes duped. Why do employees pass security training—and still fall for bait? To cite psychologists Kahneman and Tversky, employees - as do all of us - function through a System 1–System 2 dynamic. System 1 is that instinctive emotion-baited reaction “I want that iPhone; I’ll click the link.” System 2 is the tedious afterthought: “hmm maybe the email is a scam”. By that time, the attacker’s already inside. What is needed is to somehow flip the sequence: have detached System 2 inspect the email for phishing bait before emotion-driven System 1 kicks in. How do we do that? Neuroscientists link System 1 to the brain's emotional center (the amygdala), and System 2 to the logic-processing prefrontal cortex (PFC) - the part of the brain that memorizes security rules Studies showed me that when people are triggered by emotion, their limbic region activates. When they're trained to see that same situation as it is - focusing on its neutral, objective facts, blood in the brain flows from amygdala to reality-monitoring PFC and people are usually able to make the right decision. Could focusing on just the raw data neutralize phishing threats? I hired 24 individuals from Reddit, vetted them to ensure they worked for businesses and handled heavy email loads, then ran them through 30-minute Google Meet training sessions. I trained the control group—12 people—on common social engineering tactics like phishing. I trained the experimental group—12 others—on the same tactics, plus my method for analyzing emails objectively, using the two examples below Example 1: The Phishing Lure Hacker’s emotional bait: Anxiety or curiosity (what are those emails!) Deconstruction (focusing on neutral facts): Name it: Find the command: "Recover_Messages." Frame it: Summarize message (“The message claims 6 emails were withheld and requests a click to recover them") Check it: If in doubt, verify with IT/Security. Example 2: The Bait Hacker’s emotional bait: Greed (Gimme that iPhone!) Deconstruction (focusing on neutral facts): Name it: Find the command - “Scan QR code” Frame it: Summarize message (“The message claims a reward is available for an iPhone15 and requests a scan to claim it”) Check it: If in doubt check with IT/Security Fourteen days later, I sent all 24 participants a surprise test email from a pseudonym ('Ellie Robinson') using Proton Mail: Participants who responded received an automated email debriefing them that the message was our pre-agreed phishing test. Results: Six people from the control group fell for the lure, while only one person from the experiment group responded to my phishing simulation. “Name it, Frame it, Check it” When I discussed this rough experiment with my CISO connections, two of them suggested using my model to invert the standard approach.In other words, instead of endeavoring to memorize all the rules, employees simply focus on only one thing: Look for the command (What does Sender want me to do?) The brain is now in analytical mode. It’s shifted from heady emotion to focused analytical processing - from emotion-driven System 1 to reality-monitoring System 2. Released from emotion, workers can now "stand back”, summarize the message in third-person language (further reinforcing the neural loop of objective analysis) and, if uncertain, contact their supervisor. For example, here’s what Nilesh told me he did when he received my test: Name it: He looked for what the sender wanted him to do (Send Sender a screenshot of his Reddit account). Frame it: He summarized it (Email told recipient to provide Sender a screenshot of his Reddit account for possible compensation**).** Check it: He asked me whether I’d sent him the email (I didn’t respond because I wanted to see whether he would click). Conclusion As threats become more convincing through sophisticated AI, we face two problems:First, how to persuade employees to remember the admittedly boring security rules when it matters most. Second, how to prevent employees from falling for emotion-driven bait. To help employees prevail, we use a three-step approach: Name it - Find the command Frame it - Summarize the email message in third-person language Check it - If in doubt, verify with IT/ Security. With our analytical brain now in charge, employees are more likely to make the right decision.

Original Source

Read the full article at Hackernoon →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.