EY is a global leader in in assurance and advisory services. For several decades EY has been conducting a Global Information Security Survey (GISS). The 2018 security survey from EY provides some valuable insight into the cybersecurity threat. Cybersecurity attacks continue to grow in size and sophistication. As the report reveals, social engineering or phishing remains a significant threat. Below are some key facts relating to phishing and security awareness.
Phishing ranks as the top cyber threat to organizations. (Page 9)
Most successful cyber breaches contain “phishing and/or malware” as starting points. (Page 9)
22 percent of organizations see phishing as their greatest security threat. (Page 9)
34 percent of organizations see careless or unaware employees as a vulnerability. (Page 10)
Only 15 percent of organizations say their information security reporting currently fully meets their expectations. (Page 19)
Employee security awareness remains a key practice in reducing the risk from phishing and other cybersecurity threats. Learn how the PhishingBox system of training, testing, and reporting can reduce your organizations risk to one of the greatest cybersecurity threats.
Protect Your Employees (And Your Clients)!
Running simulated phishing tests will determine your employees' susceptibility to social engineering and phishing scams. Train your employees and help them identify spear phishing and ransomware attacks.
Cyberattacks continue to make headlines, and the message is clear: human error remains at the heart of most data breaches. From high-profile incidents like DoorDash’s social engineering breach to findings in Verizon’s DBIR, attackers are increasingly exploiting trust, urgency, and simple mistakes rather than technical flaws. This article explores why security awareness training and phishing simulations are no longer optional, how they reduce real-world risk, and how platforms like PhishingBox help organizations turn employees into a strong, proactive human firewall.
October is Cybersecurity Awareness Month 2025—a reminder that protecting data starts with everyday actions. This year’s theme focuses on using strong passwords, turning on MFA, recognizing phishing, and updating software. Learn how PhishingBox helps organizations turn awareness into action through phishing simulations, training courses, and reinforcement emails. Download the 2025 Cybersecurity Awareness Month Guide to plan your campaign and strengthen your organization’s security culture.