On20 June, teissTalk host Tom Langford was joined by Thomas Wendrich, Associate Partner, IBM; Jacqueline Hanson-Kotei, Senior Manager, Enterprise Information Security & Governance, MTN Ghana; andTorsten Wiedemeyer, VP Europe, Cyble.
More than nine in 10 (92%) organizations experienced an average of six credential compromises caused by email-based social engineering attacks in 2023, according to a new report by Barracuda. Attackers are targeting users via conversation hijacking, business email compromise and extortion. The researchers also found that cybercriminals are increasingly leveraging popular commercial URL shortening services to embed malicious links in phishing emails.
Getting people’s credentials is actually easier via social engineering (calling victims and being finessing them out of their passwords and pins) than hacking. Meanwhile, deep fakes take social engineering to the next level. While in 2022, ransomware and phishing were the top threat vectors, in 2023, it was identity theft. Education efforts to keep the workforce up-to-speed with cyber threats often fail because attacks change so fast.
At first, QR codes didn’t catch on as they were considered unsafe, but during and especially after Covid, they came back with a vengeance, while the risks they present are increasing. In the last quarter, 5% of email boxes have been targeted with QR codes. Ideally, users must be educated to a level where they can not only detect that something suspicious is happening to them online but can also think over various scenarios and decide which one is the best to adopt in that particular case.
As security has become stronger with multi-factor authentication, top level managers are often blackmailed into leaking confidential information or providing access to the crown jewels. The problem is that the C-suite typically doesn’t get any special or personalised protection. Members of the C-suite nowadays can be reached directly, criminals don’t need to go through P.A.s who, in the old days, functioned as gatekeepers. Some leaders like to circumvent security controls such as MFA or skip cybersecurity training.
Using OSINT – legally gathered information about an individual or organization from free, public sources and facing up to what can be learnt about a manager just collating openly available information from the internet, can be an eye-opener. Infosecurity professionals must get creative about the methodology they use with the C-suite to make them compliant. There are also tools for checking whether your passwords have already been exposed. Some password tools are better than others, but whichever you start using, it will be much safer than not using one at all. Once you’ve tried one, you can shop around for others and find the one that serves your purposes best.
2024, finally, is the year of cyber regulations – see the Cyber Resilience Act, which holds developers responsible for the software they create, even for the open-source components that it contains. It also sets a minimum time for supporting software that companies release. Note that company infosec policies must cover the acceptable use of social media too as employees, and especially members of the C-suite, must be aware that they represent the company even when interacting with other people online as an individual. However, it’s often hard to draw the line between company policy and someone’s personal opinions and communications.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543