Phishing and Human Error. Beyond Training and Simulations
摘要
Phishing is catalogued in the literature as one of the most common and at the same time most effective attacks at the time of realizing an adverse event in an organization. It is an action based on intelligence, deception and distraction that focuses on individuals to motivate them to take actions that end up with the compromise of their sensitive data. In this sense, companies have focused their efforts to prevent this type of attacks based on training and simulations, understanding phishing as a result contrary to what is expected by the corporation, which has ended up being ineffective. Consequently, this article proposes the understanding of phishing as a consequence, where the context and everything that involves the individual is what is relevant to explain the unexpected behavior, following the theory of human error that, without releasing the person from responsibility for their actions, understands and highlights aspects that go beyond the regular and standard training, to motivate a vigilant and more resistant to deception posture.