Cyber Security Masterclass: The Human Factor and Importance of Awareness Training

In 2023, 53% of businesses suffered at least one cyber-attack. And the landscape is showing no signs of improvement in 2024, especially with the rise of AI-enhanced fraud that is expanding the attack surface and calling for even stronger safety measurements.

We deliver a wide cyber security service portfolio and work with quality partners to provide cyber security solutions our clients can count on.

Now we’re offering a full series of cyber security masterclasses to share our knowledge and help every organisation stay safe.

First in the series, we partnered with KnowBe4, the world’s first and largest security-awareness training platform, for a “Top Cyber security Threats in 2024” webinar. Amongst other subjects, we talked about the human factor in cyber security, how scammers and cybercriminals attempt to trick us, what the latest cyber threats are, and what we can do about the problem.

You can find a short summary of the webinar below:

Why employee cyber security awareness is critical in protecting organisations

When it comes to cybercrime, we so often imagine hackers sitting in dingy basements in big gaming chairs, doing their best to crack our business systems and escape with our precious data. And we’re not saying that doesn’t happen (with or without fancy chairs and dingy basements). But there is definitely a large human factor when it comes to cybercrime that isn’t about hackers at all. Put simply, it’s us. We’re the problem. Too many company owners and employees aren’t aware of the tactics that scammers use or what to look for. Too many people react to credible-seeming emails that ask them to transfer money to pay an invoice, without checking if that email is real.

The answer to those problems is to educate our employees and raise awareness. While cyber security services must do their bit in blocking as many scam emails as possible, some will still get through. Employees need to know what to look for and what to do if they get a suspicious email.

Raising awareness and teaching people to slow down, think, and find the right way to react is a critical part of cyber security.

 

An overview of social engineering

What is social engineering? It’s how scammers work, in a nutshell. They do their best to psychologically manipulate people into giving away sensitive information, clicking links they shouldn’t click on, or even handing over hard-earned money.

We should be quite familiar with these types of emails and other attack methods, including the poor Nigerian prince who wants to give you all his millions so he can get his money into the UK before it’s taken from him. Or you may well have received multiple texts in the last few years, supposedly from Royal Mail, DPD, or other carriers asking you to pay the excess postage on a parcel.

While you might laugh, some of these attack methods are getting increasingly sophisticated. You can still spot many scam emails because of poor grammar and spelling, but some emails now look exactly like the company they are pretending to be from, and the differences really are hard to spot.

Another way attackers push people into making mistakes is to rush them. They create urgency in their messages – “Pay this invoice before your account is shut down,” “Contact Amazon immediately on this link, or the world will end!” Well, not quite, but you get the idea. It’s all too easy for our lizard brain to take over and for any thinking to be bypassed in the rush to sort the problem out. And then the scammers are in your system, and it’s too late.

 

What are the top attack methods in 2024?

There are so many ways for cybercriminals to attack businesses. Phishing, whaling, malware, spoof links, worms, trojans… we could go on. All of those have been around for years, and we’re certain to continue seeing them in 2024.

We also expect ransomware to still be a large part of cybercrime in 2024, where computers are locked until a ransom has been paid. Some bad actors take this further and threaten to sell any stolen data and payment must be made to prevent that.

QR code phishing is relatively new, where a genuine QR code has a sticker over it with a link straight to a spoof site. Criminals can either upload malware onto your system or get you to take action, such as paying money or giving them sensitive details, like your password.

Deep fakes are also on the rise, either in videos or in voice calls where it genuinely does look and sound like the person you were expecting, but it isn’t. This can be extremely powerful and highly persuasive, and it’s difficult to see that it is a fake.

We also now have items in our homes that can be attacked. With the Internet of Things, if you have an Amazon Echo Dot, or similar, a smart fridge, smart lighting, or other items, these things all connect to the internet and they can be hacked. You need to know what information you’re giving away and where it’s going.

However, it’s not all bad news. Educating yourself and your employees does make all the difference in protecting your company from outside attackers. And we also recommend two approaches: “Think before you click,” and “Trust, but verify.” Simple, but effective. Both of them give you time to rethink and check what you’re doing, and the second one gets you to just make sure who you’re communicating with by closing contact with the scammer and using the real phone number to call the company and check if the contact was real.

Stay tuned for our series of cyber security webinars, to learn more about the subject and how you can protect yourself and your business from cyber threats.

And if you can’t wait for our next masterclass, go ahead and sign up for your free phishing security test from KnowBe4, our partner. Let us test your employees’ know-how on scams and provide you with an overall company score to see just how “Phish-prone” your people are!

Josh Kent

About the author

Josh Kent is the marketing Co-ordinator for Forge Technologies, writing for the Forge website and social media. Passionate about tech, sports, and reading, Josh's work for Forge focuses on keeping people up to date with both news about Forge and the tech industry as a whole.

Related Articles

Building Resilience Across the UK Financial System: The Rise of Critical Third-Party Oversight

From 13 July 2026, UK financial regulators have taken a significant step to strengthen the resilience...

Community Innovation Becomes Industry Standard: The Next Chapter for Azure Landing Zones

Microsoft has announced that Azure Landing Zones (ALZ) will move from a community-led initiative into...

Elevating Endpoint Management with Microsoft Intune

From 1 July 2026, Microsoft has expanded Intune capabilities within Microsoft 365 E3 and E5 licences....

How can we help?

Considering a particular technology?
Got a question for our team?
Please get in touch, we’re here to help.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.