Skip to content

Cyber Insurance News

The Leading Source for Cybersecurity Insurance News, Insights and Data

2024 Phishing Trends: How Employee Awareness Training Can Combat Rising Threats

Posted on October 22, 2024October 22, 2024 By Martin Hinton

The famous line goes, ‘To err is human; to forgive, divine.’ However, a more fitting line from Alexander Pope’s poem might be, ‘All seems infected that th’ infected spy.’ In the world of cybersecurity, the infection is phishing, and no one is immune. Last week, we reported on an Arctic Wolf report revealing a striking disconnect: 80% of IT and security professionals expressed high confidence in their organization’s ability to resist phishing attacks, yet 64% admitted to having fallen for phishing scams themselves. This paradox dovetails neatly with the latest phishing trends found in recent reports, which underscore the escalating vulnerabilities in cybersecurity, particularly within the human layer of defense.

The “2024 Phishing by Industry Benchmarking Report” from KnowBe4 highlights the growing susceptibility of employees across industries to phishing attacks and emphasizes the critical need for ongoing security awareness training. These phishing trends shed light on a sobering reality: despite advancements in technical defenses, the human element remains the most exploitable entry point for cybercriminals.

Our takeaways follow; you can get the whole report here.

Image of the cover of "2024 Phishing by Industry Benchmarking Report" from KnowBe4.

Key Findings:

Phish-Prone Percentage (PPP):

The “Phish-Prone Percentage” (PPP) is at the heart of the report, a metric that measures the percentage of employees likely to fall for phishing scams. In 2024, the average PPP across all industries stood at 34.3%, up slightly from 2023. This indicates that despite improved technology, employees remain highly susceptible to social engineering attacks. Those without cybersecurity awareness training are particularly vulnerable.

Industry Vulnerability:

Healthcare and Pharmaceuticals top the list of industries most vulnerable to phishing, according to the phishing trends report, with a PPP of 51.4% for large organizations (1,000+ employees). Other sectors, including Insurance (48.8%) and Energy & Utilities (47.8%), also rank high in susceptibility. With their large databases of sensitive information, these industries are prime targets for cybercriminals.

Training’s Impact:

The report offers a clear solution: comprehensive, ongoing security training. Organizations that implemented security awareness programs saw significant improvements, with the average PPP dropping by almost 50% to 18.9% after just 90 days of training. After a full year of continued training, this figure plummeted to just 4.6%, underscoring the power of regular education in reducing phishing risks.

Regional Variations:

The report highlights geographic disparities in vulnerability, noting regional phishing trends. The Asia-Pacific region, for example, bore the brunt of global cybersecurity incidents, accounting for 23% of attacks. North America and Europe followed closely, reflecting the global scope of phishing threats.

A Pressing Threat to Manufacturing:

According to the report and the accompanying press release, the manufacturing industry is especially vulnerable, accounting for 25% of all cyber incidents across the top 10 industries. Manufacturing’s interconnected nature, reliance on operational uptime, and high value of intellectual property make it an attractive target. Phishing remains the primary attack vector, often followed by exploiting public-facing applications.

The manufacturing sector has also seen a dramatic 266% increase in malware designed to steal sensitive information like login credentials and banking details. Meanwhile, ransomware attacks, especially those involving extortion, have risen by 56%, with the average ransom payment reaching $2.4 million, an 88% increase from last year.

Human Weaknesses Exposed:

While cyber defenses have become more sophisticated, the report makes clear that the human layer remains the Achilles’ heel. Untrained or inadequately prepared employees are the weakest link in an organization’s cybersecurity posture. In companies with more than 1,000 employees and no security training, the PPP is a staggering 37.5%, meaning nearly four out of every 10 employees could fall victim to phishing attacks.

The report emphasizes that instead of viewing employees as inherent vulnerabilities, organizations should empower them as active participants in their cyber defense strategy. Comprehensive security awareness training is no longer optional but essential for safeguarding businesses against increasingly sophisticated threats. Recent phishing trends highlight the necessity of this approach.

Conclusion:

The “2024 Phishing by Industry Benchmarking Report” is a wake-up call for organizations across all sectors. It highlights the persistent and evolving risks posed by cybercriminals and underscores the importance of focusing on technology and the human element of security. With phishing attacks growing in volume and complexity, organizations prioritizing ongoing security training and fostering a cybersecurity awareness culture will be best equipped to protect their data and operations in today’s digital landscape. Track the latest phishing trends to stay ahead of new threats.

Other News: The Role of Human Error in Cybersecurity Failures and How to Mitigate It(Opens in a new browser tab).

Other News: Taiwan records over 50 DDoS cyberattacks in September.

Cyber Insurance, Cybersecurity, Cybersecurity Report Tags:2024 Phishing by Industry Benchmarking Report, 2024 Phishing Trends, cyber insurance, cyber liability insurance, Cybersecurity, KnowBe4, phishing

Post navigation

Previous Post: Cyber Insurance for Energy And Utility Sector Expands with CAC Group’s CyberPeril Pro
Next Post: Strengthening Critical Infrastructure Security: RKON Expands Cybersecurity Services

Related Posts

  • The Cyber Insurance Talent Shortage, Perspective from AXA XL Cyber Insurance
  • mShift and CyberCube Partner to Enhance Cyber Risk Transparency for SMEs Cyber Insurance
  • Redefining Critical Infrastructure: The Rising Stakes of School Cybersecurity and Resilience Cyber Insurance
  • Specter of State-Backed Attacks Continues to Bedevil Carriers and Potential Policy Holders Cyber Insurance
  • How Many Clients Make Claims on their Cyber Insurance Policies?  Cyber Insurance
  • Balancing Openness and Security: The Cybersecurity Challenge in Education Cybersecurity

Get the Cyber Insurance Newsletter

Receive weekly updates on the top news on cyber insurance.

Cyber Insurance News

Cyber Insurance News
In the wake of the Harrods hack and cyberattacks impacting other retailers, the alarming state of UK cybersecurity will be revealed in 2024. From cyberattacks hitting major UK retailers like Co-op and Harrods to small businesses struggling without protection, the message is clear—cybercrime is a national threat.

New research by Pen Underwriting reveals that while 90% of UK and Irish businesses feel secure, only 47% have dedicated cyber insurance. Even more shocking—only 18% of businesses earning under £1 million are covered. The cost isn’t just financial—real people suffer, like the couple who lost their wedding cake due to a ransomware attack.

Watch now to understand:

Why UK businesses are dangerously unprepared

How cyberattacks are more common than fires or theft

The key role of employee training, data backups, and multi-factor authentication (MFA)

Why cyber insurance is no longer optional

Visit www.cyberinsurancenews.org for the latest cyber insurance and cybersecurity updates.

#UKCybersecurity #CyberInsurance #SmallBusinessSecurity #CyberCrime
Harrods hack UK Cybersecurity Crisis: Shocking Stats, Real Victims & Business Risks. #cybersecurity
Cyber Insurance Compliance Is Reshaping Security in 2025!

Cyber insurance compliance is no longer optional—it's a driving force behind how companies build and execute cybersecurity strategies. In this video, we break down the latest insights from the 2025 State of Pentesting report:

✅ 59% of U.S. businesses now implement new security tools based on insurer recommendations
✅ 93% of CISOs are guided by mandates from insurance providers
✅ Pentesting isn't just for compliance—it's about proving you're covered and protected
✅ The average enterprise is spending $187,000+ annually on penetration testing

As premiums stabilize, cyber insurance compliance is pushing companies toward proactive, automated, and continuous risk assessment. Learn how to stay ahead, reduce exposure, and align with both regulators and insurers.

💡 Don’t forget to like, subscribe, and hit the bell to stay updated on the latest in cybersecurity and insurance trends!

#CyberInsuranceCompliance #CyberSecurity #PenetrationTesting #CISO #InfoSec #CyberInsurance #RiskManagement #Compliance2025 #EnterpriseSecurity #CyberDefense #TechTrends #InsuranceTech
Cyber Insurance Compliance Is Reshaping Security in 2025 #cyberinsurance
In this video, we break down the massive cyber insurance settlements following the CDK Global ransomware attack that rocked the automotive industry. 🚗💻

Auto giants like Asbury Automotive Group reported up to $10 million in cyber insurance recovery, while AutoNation only recently filed their claim — months after the breach! We explore the financial disclosures, the delayed responses, and what this means for car dealerships, investors, and cybersecurity preparedness.

Learn:
✔️ How cyber insurance is shaping post-breach recovery
✔️ Why SEC filings like 10-Q and 8-K matter
✔️ What lessons other businesses can learn from this
✔️ The real cost of a ransomware attack in automotive retail

🔔 Subscribe for more deep dives into cybersecurity, tech, and industry trends!
#cyberinsurance #CDKGlobal #RansomwareAttack #AutoIndustry #CyberSecurityNews
$10M Cyber Insurance Payout: CDK Ransomware Fallout Hits Auto Giants | #cyberinsurance
Load More... Subscribe

Categories

  • AI & Cyber Insurance
  • AI & Cybersecurity
  • Critical Infrastructure cyber insurance and security
  • Cyber Cat Bonds/Cyber Catastrophe Bonds
  • Cyber Insurance
  • Cyber Insurance APAC
  • Cyber Insurance Best Practices
  • Cyber Insurance Captive
  • Cyber Insurance Carriers & Brokers
  • Cyber Insurance Claims
  • Cyber Insurance EU
  • Cyber Insurance Financial Institutions
  • Cyber Insurance for Government
  • Cyber Insurance for Healthcare
  • Cyber Insurance for Schools
  • Cyber Insurance for SMEs/SMBs
  • Cyber Insurance For Startups
  • Cyber Insurance for Utilities
  • Cyber Insurance Geographic Markets
  • Cyber Insurance Industry Groups
  • Cyber Insurance Investments and M&A
  • Cyber Insurance Jobs
  • Cyber Insurance Laws & Regulations
  • Cyber Insurance Litigation
  • Cyber Insurance Market Size
  • Cyber Insurance MENA
  • Cyber Insurance News & Information Podcst
  • Cyber Insurance People
  • Cyber Insurance Policies & Strategies
  • Cyber Insurance Premiums
  • Cyber Insurance Reports
  • Cyber Insurance Settlements
  • Cyber Insurance Sunday – Upload
  • Cyber Insurance Systemic Risks
  • Cyber Insurance Tech
  • Cyber Insurance Threats
  • Cyber Insurance UK
  • Cyber Insurance Underwriting
  • Cyber Insurance Wholesaler
  • Cyber Regulations
  • Cyber War Exclusions
  • Cybersecurity
  • Cybersecurity and Credit Ratings
  • Cybersecurity for SMBs
  • Cybersecurity in Education
  • Cybersecurity Investment
  • cybersecurity jobs
  • cybersecurity M&A
  • Cybersecurity people
  • Cybersecurity Report
  • Cybersecurity Training
  • Department of Homeland Security
  • EU Cybersecurity
  • Insurance Linked Securities/ILS
  • Insurance Loss Warranty contract/ILW
  • Managed Service Providers
  • National Association of Insurance Commissioners' (NAIC) model cybersecurity law
  • Non-criminal Claims/Non-Malicious Claims
  • Opinion/Commentary
  • Personal Cyber Insurance
  • Personal CyberSecurity
  • Ransomware Insurance
  • Reinsurance
  • Risk Modeling
  • SEC Cyber Disclosure Rule
  • Small Business
  • Supply Chain Cybersecurity And Insurance

Send Ideas, Requests & Comments




    Tags

    AI Artificial Intelligence At-Bay Beazley CFC Chubb Cloud Security Coalition Corvus Cowbell Cowbell Cyber crowdstrike cyber attack Cybercrime cyber crime CyberCube cyber insurace cyberinsurance cyber insurance cyber insurance for small businesses Cyber Insurance Market Cyber liability Insruance cyber liability insurance cyberliabilityinsurance Cyber Resilience Cyber Risk Cyber Risk Management cyber security Cybersecurity cybersecurity insurance Cyber threats Data Breach Howden Lloyds Marsh Microsoft personal cyber insurance phishing Ransomware Ransomware Insurance reinsurance Resilience Risk Management SecurityScorecard small business
    • Cyber Insurance Books
    • Cyber Insurance Reports & Documents
    • Cyber Insurance Acronyms/Terms
    • Cyber Insurance Companies: Carriers, Brokers & Vendors
    • Industry Response: Potential Federal Insurance Response to Catastrophic Cyber Incidents
    • Ransomware Insurance
    • How Much Is Cyber Insurance?
    • Considerations for Buying Cyber Insurance
    • Cyber Liability Insurance Near Me
    • Cyber Insurance Quote
    • Newsletter
    • Legal Analysis & Full Text of 2023 SEC Rule: Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure
    • Glossary
    • About Cyber Insurance News
    • Privacy Policy

    • Biggest Myths Around Cyber Insurance? Cyber Insurance
    • New SEC Disclosure from MOVEit Owner Reveals Gory Details of Cyber Insurance Coverage, Lawsuits & SEC Subpoena Cyber Insurance
    • Dubbed “Cairney,” Beazley’s new Cyber Cat Bond Listed on Bermuda Stock Exchange (BSX)  Cyber Insurance Best Practices
    • Tailored Cybersecurity Practices Can Lower Insurance Costs, Gallagher Re Report Cyber Insurance
    • SecurityScorecard Report Highlights Escalating Supply Chain Cyber Risks for Global 2000 Cybersecurity
    • Global Ransomware Attacks Surge in Q2 2024: Corvus Insurance Report Cyber Insurance
    • CFC Enhances Cyber Cover for Professional Service Providers Cyber Insurance
    • PEGs Want Their Portfolio Companies to Have Cyber Insurance. But What’s the Best Way? Cyber Insurance Best Practices

    Related Cybersecurity Sites

    http://www.whatiscyberliability.com

    https://www.whatiscyberinsurance.com

    http://www.ddosattacktutorial.com

    http://www.ransomwareremovaltool.com

    Our Privacy Policy: https://cyberinsurancenews.org/privacy-policy/

    Copyright © 2024 Cyber Insurance News.

    Powered by PressBook Premium theme