ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Future proofing employee cyber-protections

AJ Nash at ZeroFox argues that safeguarding brand reputation starts with protecting employees online

 

This year, organisations and their employees are facing a plethora of new social engineering threats, as hackers use increasingly available public information for more sophisticated attacks.  

 

The reality is that employees’ digital activity creates a data-rich trail for threat actors to capture and exploit. In fact, 74% of data breaches reportedly involve a human element, and 41% of company data breaches involve employees’ personally identifiable information - highlighting the scale of attacks targeting employees to break through the corporate firewall.  

 

Social engineering attacks have typically been aimed at an enterprise’s C-suite, where the stakes are higher for reputation. But, as cyber-criminals grow more opportunistic, they target a wider level of personnel, especially those with access to sensitive data or information (e.g. finance, HR).

 

On top of this, the boom in generative AI has enabled threat actors to evolve their tactics to include impressive spoof emails that are more convincing and targeted.   

 

With all of this in mind, what social engineering threats do companies need to be aware of in 2024, given that failure to do so risks financial loss and the erosion of brand and reputation? And how can they future-proof employee protection strategies to stay ahead of this ever-changing threat landscape?  

 

The social engineering threat landscape 

In recent years, the workforce has evolved into one underpinned by connectedness – requiring increased use of real-time chats, video calls, social media, and group chats. All of the information shared on these channels represents risk to employees and organisations.

 

The nature of these platforms encourages sharing and open communication, which can lead to the oversharing of offensive or malicious content, unsafe links, sensitive data, and more.

 

Additionally, key personnel within the workforce are frequently impersonated on social media by cyber-criminals, who make fake accounts using their name, likenesses, and other personal information. While these accounts may employ different tactics and have varied goals, they can lead to the same result: damage to an organisation’s brand.

 

Ultimately, this reputational backlash can damage consumer loyalty, revenue, or investor confidence.

 

Removing information adversaries need

Gartner recently reported that social engineering attacks will continue to increase considerably, with threat actors seeing humans as the most vulnerable point of exploitation, and our experts agree! 

 

The abundance of personal information that is readily accessible on public domains and social media sites (and more) provides threat actors with ample resources to create effective social engineering attacks to target nearly anyone.

 

Given the high-profile elections taking place globally and in the UK this year, the stakes for government organizations are particularly high. Threat actors will very likely target election workers and government officials with phishing attacks that use pressure and scare tactics to elicit prompt actions without proper due diligence.

 

And those campaigns are usually more successful when the adversaries can create conversations or construct phishing campaigns that align with their targets’ worldview or capitalise on their known or suspected fears.

 

This can include pretending to be associated with the same group to create a sense of connectedness, threats of legal action (when threat actors impersonate government entities) to frighten or intimidate, or several variations designed to fool or convince a target to take an action that will be detrimental to themselves or their organisation.

 

Both government and non-government organisations also benefit from ongoing deep and dark web monitoring to detect and mitigate threat actor movement that originates from employees’ digital exposures. Identifying attack chatter, leaked credentials, and other indicators of compromise enables an organisation’s security team to take action before any damage can be done.

 

Solutions that remove exposed employee personally identifiable information (PII) from websites threat actors use as resources for planning their attacks are also highly recommended because they result in security teams focusing on their most important cyber-security objectives instead of expending valuable and limited resources on the arduous process of creating 100s (or 1,000s) of takedown requests per year.

 

Prevention includes protecting everyone

Given that the financial cost of phishing can be enormous, protecting employees online starts with educating them to recognise when they are being targeted for social engineering via social media, email, and text.

 

Internal security training on these threats, combined with testing that simulates real attacks,  empowers employers to understand employee’s susceptibility and keep adapting to meet their security training needs.

 

As Gartner predicts human failure will be responsible for over half of significant cyber-incidents by 2025, the importance of extending protection to every employee - not just high-profile executives -  is clear.

 

Everyone is a target within an organization’s expanding external attack surface, and every breach of sensitive information risks costly operational downtime, revenue loss, and reputational damage.

 


 

AJ Nash is VP and Distinguished Fellow of Intelligence at ZeroFox

 

Main image courtesy of iStockPhoto.com and AndreyPopov


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543