Generated by Rank Math SEO, this is an llms.txt file designed to help LLMs better understand and index this website. # Phriendly Phishing: Human Risk Management ## Sitemaps [XML Sitemap](https://phriendlyphishing.com/sitemap_index.xml): Includes all crawlable and indexable pages. ## Posts - [How to Spot a Catfishing Scam and Protect Yourself Online](https://phriendlyphishing.com/post/how-to-spot-a-catfishing-scam/): Scamwatch logs 3,400 romance scam reports a year. Learn how to spot catfishing scams and protect yourself online. - [OneStep Group and Phriendly Phishing Announce Strategic Partnership](https://phriendlyphishing.com/post/onestep-group-and-phriendly-phishing-announce-strategic-partnership/): In aged care, cyber security is about more than protecting systems, it’s about protecting people, dignity and trust. - [Cyber Resilience in Aged Care: Protecting Data, People and Trust](https://phriendlyphishing.com/post/cyber-resilience-in-aged-care-protecting-data-people-and-trust/): In aged care, cyber security is about more than protecting systems, it’s about protecting people, dignity and trust. - [What is Business Email Compromise (BEC) – and how can you protect your organisation?](https://phriendlyphishing.com/post/what-is-business-email-compromise-bec-and-how-can-you-protect-your-organisation/): Business Email Compromise (BEC) can be one of the most financially damaging types of phishing attacks facing Australian organisations today. - [Why People Fall for Phishing](https://phriendlyphishing.com/post/psychology-of-phishing-why-people-still-click/): Busy people make fast decisions. Attackers design emails around exactly that. Here's the psychology behind why clicks happen and how training helps. - [Cyber security for small businesses in Australia](https://phriendlyphishing.com/post/cyber-security-for-small-businesses-in-australia/): Cyber security for small businesses is no longer a “nice to have”, it’s a must. But where do you begin when the costs of running a business are already high? One thing to remember is that small businesses in Australia are definitely being targeted by cyber criminals, who see them as easier targets due to limited resources and often minimal security protections. - [Custom vs Off-the-Shelf Cyber Security Services for Small Business: What’s Right for You?](https://phriendlyphishing.com/post/custom-vs-off-the-shelf-cyber-security-services-for-small-business-whats-right-for-you/): Small businesses are increasingly targeted by cyber threats, and that makes cyber security services for small business more important than ever. - [How attackers exploit human nature: Social engineering cyber security examples explained](https://phriendlyphishing.com/post/how-attackers-exploit-human-nature-social-engineering-cyber-security-examples-explained/): Not sure whether to hire a scissor lift or a boom lift? This guide walks you through the different types of access equipment and helps you pick the best fit for your project. - [CAPTCHA Scams and Phishing Scams: What You Need to Know](https://phriendlyphishing.com/post/captcha-scams-and-phishing-scams-what-you-need-to-know/): You’ve seen a CAPTCHA before — those “I’m not a robot” checkboxes or image puzzles designed to block bots and allow real humans through, in fact CAPTCHA is an acronym for “Completely Automated Public Turing test to tell Computers and Humans Apart”. But what happens when cyber criminals turn this very tool against you? - [What to do if you’re caught in a data breach](https://phriendlyphishing.com/post/what-to-do-if-youre-caught-in-a-data-breach/): It’s an all too familiar feeling. You hear that a company you trust has suffered a data breach, and your sensitive information might be in the wrong hands. - [Phishing Resilience for SMBs](https://phriendlyphishing.com/post/phishing-resilience-for-smbs/): Phishing attacks remain one of the most pressing cyber threats facing small and medium businesses (SMBs) in Australia. - [Phishing and Protecting Privacy](https://phriendlyphishing.com/post/phishing-and-protecting-privacy/): Privacy is not just about personal information; it’s information that can be business critical. - [Understanding AiTM and MitM Attacks](https://phriendlyphishing.com/post/understanding-aitm-and-mitm-attacks/): A lot of our security awareness training is centred around phishing, and for good reason - it's still true that around 90% of breaches happen due to human error. - [Why Phishing Email Training is Critical to Human Risk](https://phriendlyphishing.com/post/why-phishing-email-training-is-critical-to-human-risk/): Phishing emails are sneaky messages designed to trick employees into handing over sensitive information and remain one of the biggest threats to organisations today. - [Cyber Resilience: The role of a Business Continuity Plan (BCP)](https://phriendlyphishing.com/post/cyber-resilience-the-role-of-a-business-continuity-plan-bcp/): When we think of cyber security resilience, we generally think of technical safeguards, but protecting an organisation involves more than technical defences. Although these components are important, your toolkit also requires administrative and leadership strategies. - [How information security awareness training creates a culture of security](https://phriendlyphishing.com/post/how-information-security-awareness-training-creates-a-culture-of-security/): When it comes to cyber security, staying safe isn’t just about ticking compliance boxes; it’s about fostering a security-first culture that prevents breaches, protects sensitive data, and keeps your organisation resilient. Efficient information security awareness training is one of the best ways to manage your human risk. - [What are the unwritten rules of security in your organisation?](https://phriendlyphishing.com/post/what-are-the-unwritten-rules-of-security-in-your-organisation/): For running a tight ship – policies and procedures are essential, but when it comes to day-to-day cyber security, the essential things that really shape behaviour and change aren’t always written down. - [How to create compelling phishing attack simulations for employees](https://phriendlyphishing.com/post/how-to-create-compelling-phishing-attack-simulations-for-employees/): Before you cast the net, decide what you’re phishing for. Are you testing general security awareness? Evaluating employee responses to a specific phishing attack simulation or reinforcing a new company policy? - [Scammers are on the hunt this Easter holidays](https://phriendlyphishing.com/post/scammers-are-on-the-hunt-this-easter-holidays/): Whether you’re planning a relaxing getaway, a road trip, or just a long weekend to unwind this Easter holidays, the extra time off is a great opportunity to recharge but don’t let your guard down. - [What is Malvertising?](https://phriendlyphishing.com/post/what-is-malvertising/): Phishing attacks are constantly evolving, and while using malvertising, or malicious advertising, to trick unsuspecting users isn’t new – it's becoming more frequent and more brazen. - [Catfishing: Beyond Romance Scams](https://phriendlyphishing.com/post/catphishing-beyond-romance-scams/): When most people think of catfishing, they imagine a lonely heart being deceived into a romantic relationship with a fake persona. - [Brushing Scams and QR Codes: What you need to know](https://phriendlyphishing.com/post/brushing-scams-and-qr-codes-what-you-need-to-know/): A brushing scam involves receiving unexpected packages containing items you didn’t order. The goal? Fraudulent sellers use your name and address to generate fake reviews, boosting their products’ visibility and ratings on e-commerce platforms. - [Data Privacy: Take Control of Your Data](https://phriendlyphishing.com/post/data-privacy-safeguarding-your-organisations-most-valuable-asset/): Last year, we explored the importance of protecting your digital footprint. This means restricting what personal data is freely available online, or accessible with a bit of digging. This advice also applies to organisations. - [How to Start a Cybersecurity Awareness Program](https://phriendlyphishing.com/post/how-to-start-a-cybersecurity-awareness-program/): Creating a cyber security awareness program is essential for organisations of all sizes, especially with the rapidly evolving threats that can affect employees from all parts of the team. - [Safer Internet Day – Keep Everyone Safe Online](https://phriendlyphishing.com/post/safer-internet-day-keep-everyone-safe-online/): The Safer Internet Day campaign raises awareness about online abuse. We can all play it fair online through simple actions like being safe, respectful, and kind. - [Boosting email security awareness](https://phriendlyphishing.com/post/boosting-email-security-awareness/): Email remains the backbone of communication for both individuals and organisations. It’s widespread use also makes it one of the most targeted channels for cyber-attacks. - [The role of phishing simulations in advancing security awareness and culture](https://phriendlyphishing.com/post/the-role-of-phishing-simulations-in-advancing-security-awareness-and-culture/): Phishing remains one of the most significant threats to organisational cyber security. Scammers are constantly evolving their techniques, like a game of cat and mouse, creating sophisticated phishing emails that can be challenging even for seasoned professional. - [How to avoid LinkedIn scams](https://phriendlyphishing.com/post/how-to-avoid-linkedin-scams/): LinkedIn is a valuable platform for building professional connections, finding job opportunities, and growing your career. - [Navigating the truth: misinformation, disinformation, and cyber security](https://phriendlyphishing.com/post/navigating-the-truth-misinformation-disinformation-and-cyber-security/): Misinformation refers to false information shared without specific harmful intent – like sharing posts without checking sources or passing on information as fact when you are not fully informed. - [The puzzle of cyber security awareness training](https://phriendlyphishing.com/post/the-puzzle-of-cyber-security-awareness-training/): Just like a jigsaw puzzle, robust cyber security involves quite a few intricate pieces that must fit together perfectly to create a complete picture of security. - [Why Phishing Simulations are the perfect training for strengthening the human firewall](https://phriendlyphishing.com/post/why-phishing-simulations-are-the-perfect-training-for-strengthening-the-human-firewall/): According to Statista, phishing was the most prevalent type of scam in Australia in 2023, with over 108,000 cases reported. - [Secure Our World: Cyber Security Awareness Month 2024](https://phriendlyphishing.com/post/secure-our-world-cyber-security-awareness-month-2024/): Welcome to Cyber Security Awareness Month 2024! This year, we're talking about a simple but powerful message: Secure Our World. - [Should you pay a ransomware request?](https://phriendlyphishing.com/post/should-you-pay-a-ransomware-request/): Ransomware attacks are an insidious way of attacking a network or device. Bad actors are expanding their business models to include cryptocurrency demands, personal profiling of targets and highly customised ransom demands. - [Top phishing scams to look out for](https://phriendlyphishing.com/post/top-phishing-scams-to-look-out-for/): Phishing scams are constantly evolving, and according to Scamwatch - SMS phishing, (or ‘Smishing’) and ‘Vishing’ (voice phishing, or over the phone) are now two of the most popular delivery methods based on amount of money lost as well as traditional email phishing. - [Modern communication creates modern phishing problems](https://phriendlyphishing.com/post/modern-communication-creates-modern-phishing-problems/): Most of us can be contacted anytime, anywhere thanks to SMS, and various chat applications. Chat apps like Microsoft Teams, Slack, Discord, and WhatsApp (to name a few) are often used for both professional and personal communication. - [Privacy and Online Security Myths](https://phriendlyphishing.com/post/privacy-and-online-security-myths/): Ideally, we all want to keep our data and identities safe online, but there's a lot of confusion about what online privacy means in the real world. - [Understanding privacy: Transparency, accountability, and security](https://phriendlyphishing.com/post/understanding-privacy-transparency-accountability-and-security/) - [Cyber security best practices for employees in enterprise organisations](https://phriendlyphishing.com/post/cyber-security-best-practices-for-employees-in-enterprise-organisations/): Enterprise organisations usually have a larger, and more diverse workforce - This means different kinds of workers are in play - [Beyond passwords: strategies for protecting your digital identity](https://phriendlyphishing.com/post/beyond-passwords-strategies-for-protecting-your-digital-identity/): One of the most valuable things we have is our identity. With almost all of our financial, government and medical records accessible online – it’s important to make sure that you, and only you have access to your sensitive information. Recovering from identity theft can take time and a lot of administrative red tape, causing more distress and loss in the meantime. - [Understanding the emerging cyber threats: Vishing and Generative AI](https://phriendlyphishing.com/post/understanding-the-emerging-cyber-threats-vishing-and-generative-ai/): Vishing, or voice phishing, combines traditional deceptive practices with modern technology, using mobile and land-line phones to manipulate individuals into revealing confidential information. - [Leading positive change in cyber security culture](https://phriendlyphishing.com/post/leading-positive-change-in-cyber-security-culture/): Cyber security is not just a technical challenge, it’s also a cultural one. To be a leader or champion in cyber security awareness, the first step is fostering a positive security culture. - [Promoting cyber security resilience for educators](https://phriendlyphishing.com/post/promoting-cyber-security-resilience-for-educators/): How resilient are your team members? For educators in secondary and tertiary institutions, the challenge is not only to protect the organisation or institution’s data, but also to foster a culture of cyber security awareness and resilience among their faculty and students. - [Scammers are on the hunt: Diversify your cyber security plan](https://phriendlyphishing.com/post/scammers-are-on-the-hunt-diversify-your-cyber-security-plan/): While many are preparing for long weekend celebrations, scammers are also preparing their own bag of tricks. Holiday periods often see a surge in online scams, making it crucial for organisations to fortify their security awareness. - [Teaching Cyber Security For Teens](https://phriendlyphishing.com/post/teaching-cyber-security-for-teens/): Young people are native screen users, that is, they don’t know a world without internet-connected devices, games and technology. As educators, it's our duty to guide the younger generation to be safe in the online world. It’s no longer enough to learn about how to use these devices correctly, they need to be informed about how to protect themselves and empower them to guide others. - [Cyber security risks and trends in GenAI](https://phriendlyphishing.com/post/cyber-security-risks-and-trends-in-genai/): 2023 brought a lot of challenges in the cyber space - the trend of large data breaches continued and security was, and is on the minds of many. - [The invisible threat: Protecting your organisation from online data tracking](https://phriendlyphishing.com/post/the-invisible-threat-protecting-your-organisation-from-online-data-tracking/): Data tracking is an invisible process that can impact your company’s privacy and security. - [Taking control of your data](https://phriendlyphishing.com/post/taking-control-of-your-data/): 2023 saw a lot of data breaches and cyber threats in the public eye, showing that the need for robust data security strategies is critical. Even if you have an IT team, there are essential practices you can implement to assist them in protecting your organisation’s data. - [Understanding clickbait tactics](https://phriendlyphishing.com/post/understanding-clickbait-tactics/): Phishing emails are more than just a spray approach to scams. Most of them use sophisticated clickbait tactics to play on human psychology; leveraging emotions and curiosity to entice clicks and engagement. - [Protecting your organisation: The vital role of reporting suspicious emails](https://phriendlyphishing.com/post/protecting-your-organisation-the-vital-role-of-reporting-suspicious-emails/): With our lives dominated by digital communication, the risk of a phishing attacks is high. These deceitful attempts to extract sensitive information pose significant risks to organisational security. - [Spear phishing: The targeted threat executives need to know about](https://phriendlyphishing.com/post/spear-phishing-the-targeted-threat-executives-need-to-know-about/): While phishing can be done on a mass scale, sending emails to purchased or stolen email lists – there is a similar threat that is far more precise: spear phishing. ## Pages - [PhishFit Human Risk Scoring](https://phriendlyphishing.com/solutions/phishfit/) - [Protected: Cyber Security Awareness for Education](https://phriendlyphishing.com/cyber-security-awareness-for-education/) - [ISO 27001:2022 Certified](https://phriendlyphishing.com/iso-27001-certified/) - [Phishing Awareness Training](https://phriendlyphishing.com/solutions/phishing-awareness-training/) - [Free Cyber Resilience Tools](https://phriendlyphishing.com/resources/free-cyber-resilience-tools/) - [Free Ransomware Simulator](https://phriendlyphishing.com/resources/free-cyber-resilience-tools/free-ransomware-simulator/) - [Free Phishing Simulation](https://phriendlyphishing.com/resources/free-cyber-resilience-tools/free-phishing-simulation/) - [Free Cyber Security Training Preview](https://phriendlyphishing.com/resources/free-cyber-resilience-tools/free-cyber-security-training-preview/) - [Cyber Resilience Program](https://phriendlyphishing.com/solutions/cyber-resilience-program/) - [Become a Partner](https://phriendlyphishing.com/partner-with-us/become-a-partner/) - [Platform](https://phriendlyphishing.com/solutions/platform/) - [Cyber Resilient Culture](https://phriendlyphishing.com/solutions/cyber-resilient-culture/) - [Secure Care](https://phriendlyphishing.com/solutions/secure-care/) - [Terms and Conditions](https://phriendlyphishing.com/terms-and-conditions/) - [Dark Net Chronicles](https://phriendlyphishing.com/dark-net-chronicles/) - [Digital Footprint Awareness](https://phriendlyphishing.com/resources/digital-footprint-awareness/) - [Data Privacy Awareness](https://phriendlyphishing.com/resources/data-privacy-awareness/) - [Holiday Scams Toolkit](https://phriendlyphishing.com/resources/holiday-scams-toolkit/) - [Cyber Security Awareness Month](https://phriendlyphishing.com/resources/cyber-security-awareness-month/) - [Scammers on the Hunt](https://phriendlyphishing.com/resources/scammers-on-the-hunt/) - [Resources](https://phriendlyphishing.com/resources/) - [Solutions](https://phriendlyphishing.com/solutions/) - [Phish Focus](https://phriendlyphishing.com/solutions/phishing-focus/) - [SMB Security Awareness](https://phriendlyphishing.com/solutions/smb-security-awareness/) - [USB Drop Testing and Reporting](https://phriendlyphishing.com/solutions/usb-drop-testing-and-reporting/) - [Security Awareness Training](https://phriendlyphishing.com/solutions/security-awareness-training/) - [Enterprise Security Awareness](https://phriendlyphishing.com/solutions/enterprise-security-awareness/) - [Webinars](https://phriendlyphishing.com/webinars/) - [Case Studies](https://phriendlyphishing.com/case-studies/) - [About Us](https://phriendlyphishing.com/about-us/) - [Request a Demo](https://phriendlyphishing.com/request-a-demo/) - [Partner with us](https://phriendlyphishing.com/partner-with-us/) - [Contact Us](https://phriendlyphishing.com/contact-us/) - [Blog](https://phriendlyphishing.com/blog/) - [Privacy Policy](https://phriendlyphishing.com/privacy-policy/) - [Home](https://phriendlyphishing.com/)