The diploma thesis covers the field of business cyber security, specifically the problem of phishing attacks, where the attacker tries to use social engineering techniques to persuade the victim to trust him and consequently issue private data that could be convenient for a security breach of a business system or to misrepresent other organs of the system to which the victim has access. For the diploma thesis, an application was created that served as an internal web application, built on the foundations of MEAN stack technology, which enabled the implementation of penetration tests and thus provided a detailed insight into which types of employees are vulnerable to different types of attacks. Employees were examined according to their demographic and business characteristics (gender, year of birth, years of experience, position in the company ...). The expected outcome of the experiment was a good insight into which types of employees are most vulnerable and which types of malicious e-mails are the most successful, and at the same time, the additional result of this project was the application itself as a product. During the experiment at the company, out of 1.384 e-mails sent (173 participants were sent 8 different cases of malicious e-mail), approximately 8 % (110) recorded interaction with the body of the e-mail. From the obtained results it was possible to well analyze the performance of individual e-mails, where a 26 % success rate was dominated by an e-mail, which encouraged subjects to check the record of their leave of absence in the new system of the company. In the field of risk rates for different business sectors, phishing attacks were most successful in the commercial sector. Age-related risk level statistics show that a subject's susceptibility to such attacks increases in proportion to his or her age, with the youngest interval (20 to 29 years inclusive) reaching a 3 % risk level and the oldest interval (60 to 69 inclusive years) a 13 % sensitivity. Furthermore, the level of risk increased in proportion to the length of service (measured in years) of the subject except for one anomaly, which was represented by an interval of 20 to 24 years inclusive. Among the most critical in terms of the level of risk among the positions in the company, the "head of internal logistics" and "preparation for work" ranked first with a 50 % level of risk.
|