Defense & Response ยท 3.1
๐ก๏ธ Building Your Defenses
Habits that work regardless of how clever the attack isโฑ ~2 min
Awareness Is Your Shield
Be vigilant and recognize the signs. If something feels odd or too good to be true, it may be a scam. Trust that instinct โ it's often your subconscious noticing an inconsistency before you consciously identify it.
Core Protective Habits
| Habit | Why It Works |
|---|---|
| Think before you click | Avoid clicking links or opening attachments from unknown or unexpected sources โ even if they look legitimate |
| Guard your personal information | Never share passwords, credit card numbers, or personal data in messages or emails, no matter who is asking |
| Set strong, unique passwords | Use a different strong password for every account โ a password manager makes this practical |
| Use multi-factor authentication | Enable MFA wherever possible; it adds a layer of security even if a password is stolen |
| Verify the caller's identity | If someone claims to represent a company, ask for proof, or contact the organization directly through a number you look up independently |
| Stay informed | Keep learning about new scams and techniques โ attacker tactics evolve constantly |
| Stick to trusted sources | Only download files and software from official, trusted sources to avoid malware |
The Verification Habit โ Out-of-Band Confirmation
๐ SecurityThe single most effective defense against pretexting, vishing, and CEO fraud is out-of-band verification: if you receive an unusual request (wire transfer, password reset, urgent favor) through one channel, verify it through a completely different channel. A suspicious email from your 'CEO'? Call them on their known phone number โ don't reply to the email or call a number it provides.
๐ก TipOrganizations should establish a clear policy: any financial transfer request, no matter how urgent it appears or who it claims to be from, requires verbal confirmation through a known, pre-established phone number before action is taken. This single policy stops the vast majority of CEO fraud and wire transfer scams.
For Organizations: Building a Security Culture
- โขRegular phishing simulation tests โ send fake phishing emails internally to measure and improve click rates over time
- โขClear reporting process โ make it fast and blame-free for employees to report a suspicious message or a mistake (clicking a bad link)
- โขMandatory MFA on all accounts, especially email, VPN, and financial systems
- โขLeast privilege access โ limit what any single compromised account can actually do
- โขVerification policies for financial requests โ out-of-band confirmation for any payment or credential change
๐ง Quick Checkfirst try = +5 XP
The single best defense against a suspicious 'urgent' request from your CEO isโฆ
๐ฎ Practice what you learned
โญ 0 XP๐ฅ 0 days