Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Beyond the Phish Report from Wombat Security Reveals the No. 1 Problem Area for End-Users is Protecting Confidential Information

by The Gurus
June 17, 2020
in Editor's News
data breach
Share on FacebookShare on Twitter

Wombat Security Technologies (Wombat), the leading provider of cyber security awareness and training, today announces the release of its 2017 Beyond the Phish Report. The analysis of more than 70 million questions and answers – a significant increase from 20 million in 2016 – across 10 categories identifies strengths and weaknesses tied both directly to phishing and threats beyond the phish. The report examines end-user knowledge of business-critical best practices such as data protection measures, mobile device security, safe social sharing and password hygiene. Understanding of these knowledge levels is critical as poor cyber hygiene in these areas can compound the phishing threat and weaken security postures in general.
Though there is a modest overall improvement in the rate of questions answered incorrectly compared to 2016, a drop of nearly 10%, gains and losses in various categories offset each other. In addition to analysing results by category level, Wombat also examined industry data to see how various industries compared on both a general and category-specific level. Highlights from the 2017 User Risk Report are incorporated throughout to compare knowledge levels to admitted end-user behaviors.
“We continue to see in our year-over-year results that reinforcement and practice are critical to learning retention. As with any learned skill, organisations need to work on cybersecurity awareness and knowledge to see continual improvements,” said Joe Ferrara, President and CEO of Wombat. “Organisations that focus on building a culture of security and empowering their employees to be a part of the solution develop the most sustainable and successful security awareness training programs. By sharing our data in the Beyond the Phish Report, we hope to be a part of building those cultures and helping organisations successfully change behavior in previously undiscovered areas of vulnerability.”
Key areas from the report analysis that reveal room for improvement include the following:

  • The number one problem area for end users, with 26% of questions missed, is protecting confidential payment card and healthcare information. Users struggled the most with questions around the use of shared login credentials.
  • Protecting mobile devices and information saw the most significant downgrade in performance year-over-year, with users struggling to understand the implications and ramifications of unsafe mobile applications and invasive permissions.
  • Employees in healthcare, transportation and retail performed the lowest on average across all categories.
  • End-users across all industries answered a quarter of questions incorrectly around the protection and disposal of personally identifiable information.
  • All but one industry performed worse in questions around using the internet safely after positive numbers in 2016, showing that organisations cannot make assumptions about levels of risk from one year to the next.

While there is always room for improvement with regard to managing end-user risk, the 2017 Beyond the Phish Report also highlights categories and industries in which employees are improving year-over-year and have answered the highest percentage of questions correctly:

  • All industries saw an improvement over 2016 in questions around identifying phishing attacks. The rate of incorrectly answered questions was 24% on average in 2017 compared to 28% on average in 2016.
  • Social media use saw the largest year-over-year improvement, a positive trend as the use of social media platforms continues to rise globally.
  • Working safely outside the office also showed a significant improvement year-over-year, which continues to be important to organizations as 43% of employees work remotely at least part of the time according to Gallup.
  • On average, end-users performed well on the new category around protecting yourself against scams, which focuses on the recognition of different types of social engineering techniques.
  • As in 2016, the best understood category for end-users focused on password safety where only 12% of answers were incorrect in 2017.

Furthermore, the 2017 Beyond the Phish Report shows it’s important for organisations to use a combination of simulated attacks and question-based knowledge assessments to evaluate their end users’ susceptibility to phishing attacks. For example, the 2017 State of the Phish Report revealed an 18% click rate on phishing attacks with healthcare employees, yet 26% of questions around phishing were answered incorrectly in this same industry. Using both types of assessment tools gives a more complete picture of vulnerability.
About the Beyond the Phish Report
The 2017 Beyond the Phish Report evaluated more than 70 million questions answered by the end-users of Wombat Security customers in ten categories within Wombat’s CyberStrength® Knowledge Assessments and training modules from June 2016 through May 2017. The report highlights strengths and weaknesses tied both directly to phishing and goes beyond the phish to analyse knowledge of other business-critical practices, including data protection measures, mobile device security, safe social sharing, and password hygiene. You can download the full report here.
About Wombat Security Technologies
Wombat Security Technologies provides information security awareness and training software to help organizations teach their employees secure behavior. Their SaaS-based cybersecurity education solutions include a platform of integrated broad assessments, as well as a library of simulated attacks and brief interactive training modules. Wombat’s solutions help organizations reduce successful phishing attacks and malware infections up to 90%. Wombat, recognized by Gartner as a leader in the Magic Quadrant for Security Awareness Computer-Based Training Vendors, is helping small and medium businesses, as well as Fortune 1000 and Global 2000 customers in industry segments such as finance and banking, energy, technology, higher education, retail, and consumer packaged goods to strengthen their cybersecurity defenses

Tags: CyberCyber hygienecybersecurityphishtechWombat
ShareTweet
Previous Post

Businesses paid £222M to ransomware hackers last year, new Datto study finds

Next Post

Mass-Scale Ransomware Attacks Providing Hackers the Ability to Earn Quick Money

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol