Examine phishing as a form of social engineering and its significance for organizations. Describe the attack lifecycle, the most common types of phishing messages, and recognizable indicators, and briefly summarize the relevant EU and Slovenian guidelines. In the practical part, set up a test environment and conduct a simulation campaign on a selected group of employees using different types of messages. Based on the response, identify factors of susceptibility to fraud and provide recommendations for technical and organizational measures to reduce the effectiveness of phishing attacks.
|