The Weakest Link: How to Diagnose, Detect, and Defend Users from Phishing

Front Cover
MIT Press, Aug 16, 2022 - Computers - 272 pages
0 Reviews
Reviews aren't verified, but Google checks for and removes fake content when it's identified
An expert in cybersecurity lays out an evidence-based approach for assessing user cyber risk and achieving organizational cyber resilience.

Phishing is the single biggest threat to cybersecurity, persuading even experienced users to click on hyperlinks and attachments in emails that conceal malware. Phishing has been responsible for every major cyber breach, from the infamous Sony hack in 2014 to the 2017 hack of the Democratic National Committee and the more recent Colonial Pipleline breach. The cybersecurity community’s response has been intensive user training (often followed by user blaming), which has proven completely ineffective: the hacks keep coming. In The Weakest Link, cybersecurity expert Arun Vishwanath offers a new, evidence-based approach for detecting and defending against phishing—an approach that doesn’t rely on continual training and retraining but provides a way to diagnose user vulnerability.

Vishwanath explains how organizations can build a culture of cyber safety. He presents a Cyber Risk Survey (CRS) to help managers understand which users are at risk and why. Underlying CRS is the Suspicion, Cognition, Automaticity Model (SCAM), which specifies the user thoughts and actions that lead to either deception by or detection of phishing come-ons. He describes in detail how to implement these frameworks, discussing relevant insights from cognitive and behavioral science, and then presents case studies of organizations that have successfully deployed the CRS to achieve cyber resilience. These range from a growing wealth management company with twenty regional offices to a small Pennsylvania nonprofit with forty-five employees.

The Weakest Link will revolutionize the way managers approach cyber security, replacing the current one-size-fits-all methodology with a strategy that targets specific user vulnerabilities.
 

What people are saying - Write a review

We haven't found any reviews in the usual places.

Contents

HOW SOCIAL ENGINEERING EVOLVED
23
WHAT MAKES SOCIAL ENGINEERING POSSIBLE
41
HOW CISOS ARE DEALING WITH SOCIAL ENGINEERING
65
WHY DO PEOPLE FALL FOR SOCIAL ENGINEERING?
89
THE KEY SYMPTOM
117
PERFORMING AN ACCURATE DIAGNOSIS
135
CONDUCTING A USER CYBER RISK ASSESSMENT
159
FROM CYBER RISK TO CYBER HYGIENE
179
A TALE OF FIVE IMPLEMENTATIONS
203
REVERSING THE SOCIAL ENGINEERS ADVANTAGES
225
Notes
247
Copyright

Other editions - View all

Common terms and phrases

About the author (2022)

Arun Vishwanath, a leading expert in cybersecurity, has held faculty positions at the University at Buffalo, Indiana University, and the Berkman Klein Center for Internet & Society at Harvard University. He has written on human cyber vulnerability and related topics for CNN, the Washington Post, and other major media.

Bibliographic information