---
description: Cybercriminals are targeting senior executives in Australian companies. Discover which cyberattacks threaten them the most and how companies can respond.
image: https://gdm-localsites-assets-gfprod.imgix.net/images/getapp/og_logo-94fd2a03a6c7a0e54fc0c9e21a1c0ce9.png
title: Protect senior executives with security awareness training programs
---

# 70% of Australian executives are vulnerable to rising cyberattacks: Discover the key defence - security awareness training

Canonical: https://www.getapp.com.au/blog/6922/senior-executive-security-awareness-training-programs

Published on 25/09/2024 | Written by David Jani, Andrew Blair.

![70% of Australian executives are vulnerable to rising cyberattacks: Discover the key defence - security awareness training](https://images.ctfassets.net/63bmaubptoky/64lq0MXJzjIYLWR1JvCf4U/3beb4665e218c00a468a67111aeb32ea/GA-US-Header-Cybersecurity-Best-Practices-for-Your-Small-Business-1200x630-DLVR__1_.jpg)

> Senior executives in Australian companies manage critical business data, making them prime targets for cybercriminals. Without robust cybersecurity measures, these businesses are at a significant risk of data breaches.

-----

## Article Content

Senior executives in Australian companies manage critical business data, making them prime targets for cybercriminals. Without robust cybersecurity measures, these businesses are at a significant risk of data breaches.In this articleCyberattacks targeting Aussie senior executives have increased the most in global comparisonAussie employees expect senior executives to receive more cybersecurity training4 ways to prepare senior executives for cybersecurity risksMore senior company executives are now targets for fraud, whether artificial intelligence (AI)- generated deep fakes, biometric security breaches, or ID fraud. This is a finding from GetApp’s 2024 Executive Cybersecurity survey\*, which canvassed 2,648 IT and cybersecurity professionals across 11 countries, including 241 respondents from Australia. These kinds of attacks could run costs into millions, making it imperative to provide specialised cybersecurity training to all staff members, but especially to senior executives. To reinforce this, our study found that nearly half (49%) of Australian companies targeted by a cyberattack in the last 18 months prioritised training executives on security topics. Given the amount of data, company control, and money they have authority over, senior business executives offer a major prize to cyberattackers. Despite the urgency though, work pressure and time constraints can lead many leaders to skip cyberattack defence training. Is this a risk businesses can afford to take? Key insights70% of Australian senior executives have been targeted at least once by a cyberattack in the last 18 months according to surveyed IT and cybersecurity professionals69% of respondents whose company’s senior executives were previously targeted say cyberattacks against senior members of staff have increased22% of attacks in the last 18 months used AI-assisted deepfakes to target senior executives, although the majority of attacks were caused by phishing or malware86% of IT and cybersecurity professionals agree that senior executives should receive more cybersecurity training than other employees28% of Australian respondents say their companies have no extra cybersecurity training for senior executives, despite the risksCyberattacks targeting Aussie senior executives have increased the most in global comparison The Office of the Australian Information Commissioner (OAIC) publishes by-yearly reports on notifications received under the Notifiable Data Breaches (NDB) scheme to track the leading sources of data breaches and highlight emerging issues and areas for regulated entities’ ongoing attention.The key findings listed in the latest report (July to December 2023) mentioned that the authority received 483 notifications during this reporting period. This marks a 19% increase compared to the notifications earlier received in January to June 2023. Of which 44% of all data breaches resulted from cybersecurity incidents. \[1\]Similarly, Capterra’s survey findings also report an increase in cyberattacks, but specifically aimed at Australian senior executives. In fact, Australian senior executives are among the most affected among all respondents in our global survey.Seven out of ten (70%) IT and cybersecurity respondents report senior executives in their companies have been the target of at least one cyberattack in the last 18 months, which is also significantly above the global average of 63%. Senior executive targeting is also an increasing trend, with 69% of Australian respondents whose executives had been targeted by a cyberattack reporting that these attacks have risen over the last three years. Yet again, this is much higher than the 58% of global respondents who’ve witnessed a similar increase over recent years.Interestingly, in the same OAIC report, 30% of data breaches were sourced from human error marking a 36% increase compared to the 26% in the previous report (January to June 2023). \[1\] Minor mistakes can lead to major consequences in cybersecurity. A simple, easy-to-guess password can have major ramifications if it leads to a successful breach from a hacker. In our first article, analysing the survey data, we found that many businesses hit by cyberattacks retroactively focused on plugging gaps, such as weak passwords, software update regularity, or improving network security. If a staff member slips up in any of these ways, it may pose significant issues for the business. However, this risk is accelerated further if the person being targeted is in a company leadership position. What are the most common types of cybersecurity incidents targeting Aussie senior executives and why? While cyberattackers often modify their techniques to exploit vulnerable senior executives, some common practices continue to prevail. Respondents in our survey whose companies had suffered an attack targeting senior executives say breaches were facilitated mainly by phishing and malware attacks.Making things even more perilous is the fact that cyberattackers are deploying newer, more sophisticated methods to attack companies that are not defending high-end data securely enough. Affecting 22% of Australian respondents in targeted companies, AI-assisted deepfake attacks top the charts. Many of these attacks occur because of careless mistakes made by senior executives. Our data found a disregard for sharing sensitive information over unsecured channels and neglect to update software and systems regularly. However, Australian respondents are slightly more diligent in the global comparison, knowing to use strong passwords and download files from trusted sources. Which types of identity fraud are Australian senior executives most commonly subject to?There is also an especially serious risk factor of identity fraud facing executives more generally. Nearly half (48%) of our Australian respondents are working in companies hit by at least one identity fraud incident affecting a senior executive over the last 18 months. Compared to the global average, Australian senior executives witness significantly higher risks for document fraud.   Senior executives not adhering to their company’s security protocols can pose major threats to the business, especially given the access they have to secured data. While business leaders may have the capacity to override certain cybersecurity safety features in cases of urgency, it is important to know the risks of taking such actions. Avoid being marked as an easy target for cyberattacksUnfortunately, being targeted successfully by a cyberattacker makes further attacks more likely, especially if the target is seen as high value. Cybercriminals may share details of those who were successfully breached or who ended up sharing personal data, which can lead others to breach your systems through the same vulnerabilities. That’s why it’s important to strengthen your cybersecurity measures to avoid attacks.You can reduce the chances of unauthorised access with safety tools, such as multi-factor authentication (MFA), encryption, and identity management software.  Aussie employees expect senior executives to receive more cybersecurity trainingWe found that most (83%) Australian participants say they have cybersecurity training at least once a year or more. Our analysis unveiled that it is most common for senior executives to receive specialised cybersecurity training compared with other staff members. This is the case for 69% of Aussie senior executives compared to the global average of 57%. However, 28% of Aussie senior executives are not provided more enhanced training, putting them at significant risk.That’s not to say there isn’t extensive training company-wide. We found amongst our sample that the majority have workplace coaching on subjects such as cybersecurity and data privacy. Whilst this is a good start, executives may need additional instructions to succeed against advanced cyberattacks. For example, they may need to be prepared for more advanced, individualised social engineering methods such as ‘whaling’ (highly nuanced attacks on high-value targets), which targets C-level executives specifically. In total, 86% of Australian respondents agree that senior executives need more frequent and specialised training than regular employees. However, in many companies, this is not happening despite senior executives' crucial role in a company's defence against cyberattacks. This is a greater concern as attacks attempting to exploit them are likely to differ from those directed at rank-and-file employees.We focused on this factor in our survey to understand how well-prepared senior executives are to deal with potential cybersecurity threats. Overall, this is sufficiently addressed but some gaps remain.Those in the sample with no extra training for executives say that C-level staff have justified this decision for a few reasons. The most selected response indicates that Australian senior executives already possess sufficient knowledge (43%) which is significantly higher than the global average of 30%. Many who work in companies without extra training for their senior executives have confidence in their knowledge of cyber risks but there are reasons not to be too complacent. The danger posed by newer threats such as AI-generated deepfakes, identity fraud, or individualised social engineering attacks may require a rethink of this policy. It may now possibly be the case that ‘sufficient knowledge’ noted by participants might no longer be enough. This is why it’s especially important to ensure that senior executives are aware of the new and evolving cyberthreats and are able to identify the vulnerabilities to stay as up to date as possible.4 ways to prepare senior executives for cybersecurity risks There is a desire from employees and, in fact, an imperative for senior executives to be trained on the specific cybersecurity dangers they face. We’ve already seen in our findings that they are likely to be targeted and that any mistakes on their part that undermine network security can be costly.There are a number of new and developing threats that additional cybersecurity training can help prepare executives to face effectively. These include elements such as the following:Create awareness of current threats: Cyberthreats are evolving quickly, and senior executives need to stay current on the methods that can specifically target them. As discussed before, time constraints may affect executive-level cybersecurity training. However, businesses can also rely on security awareness training software to access courses and guidance that adapt to their busy schedules without needing a specialised course.Protect image and personal data: Executives represent a major target for social engineering attacks. A lot of information needed to impersonate an executive can be found online, either from company sources, local media, or their social network activities. Therefore, it is especially important to make executives aware of what they should and shouldn’t share online and to have them regularly review their information security.Conduct a risk assessment: Executives should feel empowered to make decisions but must also be aware of potential risks that may occur when carrying out certain activities, such as finalising high-value transactions that could be fraudulent. Understanding such risks enables businesses to prevent unwanted outcomes. These might include procedures to assess if a video call is a deepfake or having network monitoring implemented that can detect threats. Additionally, preventive steps can be initiated if an incident is noticed mid-attack, such as how to halt fraudulent transactions or recover lost funds, not to mention disaster recovery strategies if they do succeed. Ensure personal devices and networks are secure: Company information should always be kept solely on company devices, and where possible, secure Wi-Fi networks should be used only, but in today’s interconnected world, this doesn’t always happen. Insecure apps or malware, however, can represent a big issue if they get onto company infrastructure, which is why it is important to educate executives to be especially wary of exposing their devices to these risks. Using a mobile device management system can help secure mobile hardware by providing monitoring capabilities and controlling use policy. Looking for security awareness training software? Check out our catalogue\!

## Disclaimer

> Survey methodology\*GetApp's Executive Cybersecurity Survey was conducted in May 2024 among 2,648 respondents in the U.S. (n=238), Canada (n=235), Brazil (n=246), Mexico (n=238), the U.K. (n=254), France (n=235), Italy (n=233), Germany (n=243), Spain (n=243), Australia (n=241), and Japan (n=242). The goal of the study was to explore how IT and cybersecurity professionals are responding to the rising threat of biometric fraud. Respondents were screened for IT and cybersecurity roles at companies that use security software and have more than one employee. Respondents were screened for involvement in, or full awareness of, cybersecurity measures implemented at their company.SourcesNotifiable Data Breaches Report July to December 2023, Australian Government (OAIC) 

## About the authors

### David Jani

David is a Content Analyst for the UK, providing key insights into tech, software and business trends for SMEs. Cardiff University graduate. He loves traveling, cooking and F1.

### Andrew Blair

Andrew is a Content Analyst for GetApp, giving SMEs insights into tech, software and business trends. Interest in entrepreneurship, furthering projects and startups. 

## Related Categories

- [Artificial Intelligence (AI) Software](https://www.getapp.com.au/directory/1397/artificial-intelligence/software)
- [Cloud Security Software](https://www.getapp.com.au/directory/291/cloud-security/software)
- [Cybersecurity Software](https://www.getapp.com.au/directory/1035/cybersecurity/software)
- [Network Monitoring Tools](https://www.getapp.com.au/directory/480/network-monitoring/software)
- [Network Security Software](https://www.getapp.com.au/directory/1443/network-security/software)

## Related Articles

- [Automation: A quarter of SME employees think there will be a lack of job prospects in the future](https://www.getapp.com.au/blog/2576/future-of-automation-and-digital-skills-in-australia)
- [How to delete your personal data?](https://www.getapp.com.au/blog/2717/how-to-delete-personal-data)
- [AI cyberattacks push 66% Aussie companies to have a deepfake response plan](https://www.getapp.com.au/blog/6892/deepfake-response-plan-ai-cyberattacks)
- [What Is A Virtual Data Room? Plus The Tools & Tips For Setting Yours Up](https://www.getapp.com.au/blog/1483/what-is-a-virtual-data-room-tools-tips)
- [Data security processes: What do Australians expect from organisations?](https://www.getapp.com.au/blog/3663/data-security-australia)

## Links

- [View on GetApp](https://www.getapp.com.au/blog/6922/senior-executive-security-awareness-training-programs)
- [Blog](https://www.getapp.com.au/blog)
- [Home](https://www.getapp.com.au/)

-----

## Structured Data

<script type="application/ld+json">
  {"@context":"https://schema.org","@graph":[{"name":"GetApp Australia","address":{"@type":"PostalAddress","addressLocality":"Sydney","addressRegion":"NSW","postalCode":"2060","streetAddress":"Level 18 40 Mount Street North Sydney NSW 2060 Australia"},"description":"Review, Compare and Evaluate small business software. GetApp Australia has software offers, SaaS and Cloud Apps, independent evaluations and reviews.","email":"info@getapp.com.au","url":"https://www.getapp.com.au/","logo":"https://dm-localsites-assets-prod.imgix.net/images/getapp/getapp-logo-light-mode-5f7ee07199c9b3b045bc654a55a2b9fa.svg","@type":"Organization","@id":"https://www.getapp.com.au/#organization","parentOrganization":"G2.com, Inc.","sameAs":["https://twitter.com/getapp","https://www.facebook.com/GetAppcom","https://www.instagram.com/getappcom/","https://www.youtube.com/c/GetAppCom"]},{"name":"GetApp Australia","url":"https://www.getapp.com.au/","@type":"WebSite","@id":"https://www.getapp.com.au/#website","publisher":{"@id":"https://www.getapp.com.au/#organization"},"potentialAction":{"query":"required","target":"https://www.getapp.com.au/search/?q={search_term_string}","@type":"SearchAction","query-input":"required name=search_term_string"}},{"name":"Protect senior executives with security awareness training programs","description":"Cybercriminals are targeting senior executives in Australian companies. Discover which cyberattacks threaten them the most and how companies can respond.","url":"https://www.getapp.com.au/blog/6922/senior-executive-security-awareness-training-programs","about":{"@id":"https://www.getapp.com.au/#organization"},"@type":"WebPage","@id":"https://www.getapp.com.au/blog/6922/senior-executive-security-awareness-training-programs#webpage","isPartOf":{"@id":"https://www.getapp.com.au/#website"}},{"description":"Senior executives in Australian companies manage critical business data, making them prime targets for cybercriminals. Without robust cybersecurity measures, these businesses are at a significant risk of data breaches.","author":[{"name":"David Jani","@type":"Person"},{"name":"Andrew Blair","@type":"Person"}],"image":{"url":"https://images.ctfassets.net/63bmaubptoky/64lq0MXJzjIYLWR1JvCf4U/3beb4665e218c00a468a67111aeb32ea/GA-US-Header-Cybersecurity-Best-Practices-for-Your-Small-Business-1200x630-DLVR__1_.jpg","@type":"ImageObject","@id":"https://www.getapp.com.au/blog/6922/senior-executive-security-awareness-training-programs#primaryimage"},"headline":"70% of Australian executives are vulnerable to rising cyberattacks: Discover the key defence - security awareness training","@type":"BlogPosting","publisher":{"@id":"https://www.getapp.com.au/#organization"},"inLanguage":"en-AU","articleBody":"&lt;p&gt;&lt;b&gt;Senior executives in Australian companies manage critical business data, making them prime targets for cybercriminals. Without robust cybersecurity measures, these businesses are at a significant risk of data breaches.&lt;/b&gt;&lt;/p&gt;&lt;img title=&quot;GA-US-Header-Cybersecurity-Best-Practices-for-Your-Small-Business-1200x630-DLVR (1)&quot; alt=&quot;Australian senior executives undergoing security awareness training against AI-generated deepfakes&quot; class=&quot;aligncenter&quot; fetchpriority=&quot;high&quot; src=&quot;https://images.ctfassets.net/63bmaubptoky/64lq0MXJzjIYLWR1JvCf4U/3beb4665e218c00a468a67111aeb32ea/GA-US-Header-Cybersecurity-Best-Practices-for-Your-Small-Business-1200x630-DLVR__1_.jpg&quot; srcset=&quot;https://images.ctfassets.net/63bmaubptoky/64lq0MXJzjIYLWR1JvCf4U/3beb4665e218c00a468a67111aeb32ea/GA-US-Header-Cybersecurity-Best-Practices-for-Your-Small-Business-1200x630-DLVR__1_.jpg?w=400 400w, https://images.ctfassets.net/63bmaubptoky/64lq0MXJzjIYLWR1JvCf4U/3beb4665e218c00a468a67111aeb32ea/GA-US-Header-Cybersecurity-Best-Practices-for-Your-Small-Business-1200x630-DLVR__1_.jpg?w=700 700w, https://images.ctfassets.net/63bmaubptoky/64lq0MXJzjIYLWR1JvCf4U/3beb4665e218c00a468a67111aeb32ea/GA-US-Header-Cybersecurity-Best-Practices-for-Your-Small-Business-1200x630-DLVR__1_.jpg?w=1000 1000w, https://images.ctfassets.net/63bmaubptoky/64lq0MXJzjIYLWR1JvCf4U/3beb4665e218c00a468a67111aeb32ea/GA-US-Header-Cybersecurity-Best-Practices-for-Your-Small-Business-1200x630-DLVR__1_.jpg?w=1500 1500w, https://images.ctfassets.net/63bmaubptoky/64lq0MXJzjIYLWR1JvCf4U/3beb4665e218c00a468a67111aeb32ea/GA-US-Header-Cybersecurity-Best-Practices-for-Your-Small-Business-1200x630-DLVR__1_.jpg?w=2200 2200w&quot; sizes=&quot;(min-resolution: 2x) 2200px, (min-width: 992px) 1000px, 95vw&quot;/&gt;&lt;div class=&quot;table-of-contents&quot;&gt;&lt;h2 class=&quot;h3&quot;&gt;In this article&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;#Cyberattacks-targeting-Aussie-senior-executives-have-increased-the-most-in-global-comparison&quot; class=&quot;event&quot; data-evna=&quot;engagement_facet_click&quot; data-evcmp=&quot;table-of-contents&quot; data-evdst=&quot;jump-to_section&quot; data-evdtl=&quot;text-link_section-name&quot;&gt;Cyberattacks targeting Aussie senior executives have increased the most in global comparison&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;#Aussie-employees-expect-senior-executives-to-receive-more-cybersecurity-training&quot; class=&quot;event&quot; data-evna=&quot;engagement_facet_click&quot; data-evcmp=&quot;table-of-contents&quot; data-evdst=&quot;jump-to_section&quot; data-evdtl=&quot;text-link_section-name&quot;&gt;Aussie employees expect senior executives to receive more cybersecurity training&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;#4-ways-to-prepare-senior-executives-for-cybersecurity-risks&quot; class=&quot;event&quot; data-evna=&quot;engagement_facet_click&quot; data-evcmp=&quot;table-of-contents&quot; data-evdst=&quot;jump-to_section&quot; data-evdtl=&quot;text-link_section-name&quot;&gt;4 ways to prepare senior executives for cybersecurity risks&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;More senior company executives are now targets for fraud, whether artificial intelligence (AI)- generated deep fakes, biometric security breaches, or ID fraud. This is a finding from GetApp’s 2024 Executive Cybersecurity survey*, which canvassed 2,648 IT and cybersecurity professionals across 11 countries, including 241 respondents from Australia. &lt;/p&gt;&lt;p&gt;These kinds of attacks could run costs into millions, making it imperative to provide specialised &lt;a href=&quot;/directory/3809/security-awareness-training/software&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;cybersecurity training&lt;/a&gt; to all staff members, but especially to senior executives. To reinforce this, our study found that nearly half (49%) of Australian companies targeted by a cyberattack in the last 18 months prioritised training executives on security topics. &lt;/p&gt;&lt;p&gt;Given the amount of data, company control, and money they have authority over, senior business executives offer a major prize to cyberattackers. Despite the urgency though, work pressure and time constraints can lead many leaders to skip cyberattack defence training. Is this a risk businesses can afford to take? &lt;/p&gt;&lt;div class=&quot;box-hint&quot;&gt;&lt;div class=&quot;box-header fw-700 mb-4&quot;&gt;&lt;svg viewbox=&quot;0 0 26 28&quot; aria-hidden=&quot;true&quot; class=&quot;icon icon-star box-header__icon align-middle mb-1 me-2&quot;&gt;&lt;path d=&quot;M26 10.109c0 0.281-0.203 0.547-0.406 0.75l-5.672 5.531 1.344 7.812c0.016 0.109 0.016 0.203 0.016 0.313 0 0.406-0.187 0.781-0.641 0.781-0.219 0-0.438-0.078-0.625-0.187l-7.016-3.687-7.016 3.687c-0.203 0.109-0.406 0.187-0.625 0.187-0.453 0-0.656-0.375-0.656-0.781 0-0.109 0.016-0.203 0.031-0.313l1.344-7.812-5.688-5.531c-0.187-0.203-0.391-0.469-0.391-0.75 0-0.469 0.484-0.656 0.875-0.719l7.844-1.141 3.516-7.109c0.141-0.297 0.406-0.641 0.766-0.641s0.625 0.344 0.766 0.641l3.516 7.109 7.844 1.141c0.375 0.063 0.875 0.25 0.875 0.719z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;Key insights&lt;/div&gt;&lt;ul&gt;&lt;li&gt;70% of Australian senior executives have been targeted at least once by a cyberattack in the last 18 months according to surveyed IT and cybersecurity professionals&lt;/li&gt;&lt;li&gt;69% of respondents whose company’s senior executives were previously targeted say cyberattacks against senior members of staff have increased&lt;/li&gt;&lt;li&gt;22% of attacks in the last 18 months used AI-assisted deepfakes to target senior executives, although the majority of attacks were caused by phishing or malware&lt;/li&gt;&lt;li&gt;86% of IT and cybersecurity professionals agree that senior executives should receive more cybersecurity training than other employees&lt;/li&gt;&lt;li&gt;28% of Australian respondents say their companies have no extra cybersecurity training for senior executives, despite the risks&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;/div&gt;&lt;h2 id=&quot;Cyberattacks-targeting-Aussie-senior-executives-have-increased-the-most-in-global-comparison&quot;&gt;Cyberattacks targeting Aussie senior executives have increased the most in global comparison &lt;/h2&gt;&lt;p&gt;The Office of the Australian Information Commissioner (OAIC) publishes by-yearly reports on notifications received under the Notifiable Data Breaches (NDB) scheme to track the leading sources of data breaches and highlight emerging issues and areas for regulated entities’ ongoing attention.&lt;/p&gt;&lt;p&gt;The key findings listed in the latest report (July to December 2023) mentioned that the authority received 483 notifications during this reporting period. This marks a 19% increase compared to the notifications earlier received in January to June 2023. Of which 44% of all data breaches resulted from cybersecurity incidents. [1]&lt;/p&gt;&lt;p&gt;Similarly, Capterra’s survey findings also report an increase in cyberattacks, but specifically aimed at Australian senior executives. In fact, Australian senior executives are among the most affected among all respondents in our global survey.&lt;/p&gt;&lt;p&gt;Seven out of ten (70%) IT and cybersecurity respondents report senior executives in their companies have been the target of at least one cyberattack in the last 18 months, which is also significantly above the global average of 63%. &lt;/p&gt;&lt;p&gt;Senior executive targeting is also an increasing trend, with 69% of Australian respondents whose executives had been targeted by a cyberattack reporting that these attacks have risen over the last three years. Yet again, this is much higher than the 58% of global respondents who’ve witnessed a similar increase over recent years.&lt;/p&gt;&lt;img title=&quot;1-cybersecurity-threat-AU-GA-donut-chart&quot; alt=&quot;Donut chart showing most employees say Australian senior executives have become targets of cyberthreats in the last 18 months&quot; class=&quot;aligncenter&quot; loading=&quot;lazy&quot; src=&quot;https://images.ctfassets.net/63bmaubptoky/44hNFa219Ql8lSdrgR6r3J/a76a4441dc2f94035c9ff58bb2efb4ce/1-cybersecurity-threat-AU-GA-donut-chart.jpg&quot; srcset=&quot;https://images.ctfassets.net/63bmaubptoky/44hNFa219Ql8lSdrgR6r3J/a76a4441dc2f94035c9ff58bb2efb4ce/1-cybersecurity-threat-AU-GA-donut-chart.jpg?w=400 400w, https://images.ctfassets.net/63bmaubptoky/44hNFa219Ql8lSdrgR6r3J/a76a4441dc2f94035c9ff58bb2efb4ce/1-cybersecurity-threat-AU-GA-donut-chart.jpg?w=700 700w, https://images.ctfassets.net/63bmaubptoky/44hNFa219Ql8lSdrgR6r3J/a76a4441dc2f94035c9ff58bb2efb4ce/1-cybersecurity-threat-AU-GA-donut-chart.jpg?w=1000 1000w, https://images.ctfassets.net/63bmaubptoky/44hNFa219Ql8lSdrgR6r3J/a76a4441dc2f94035c9ff58bb2efb4ce/1-cybersecurity-threat-AU-GA-donut-chart.jpg?w=1500 1500w, https://images.ctfassets.net/63bmaubptoky/44hNFa219Ql8lSdrgR6r3J/a76a4441dc2f94035c9ff58bb2efb4ce/1-cybersecurity-threat-AU-GA-donut-chart.jpg?w=2200 2200w&quot; sizes=&quot;(min-resolution: 2x) 2200px, (min-width: 992px) 1000px, 95vw&quot;/&gt;&lt;p&gt;Interestingly, in the same OAIC report, 30% of data breaches were sourced from human error marking a 36% increase compared to the 26% in the previous report (January to June 2023). [1] &lt;/p&gt;&lt;p&gt;Minor mistakes can lead to major consequences in cybersecurity. A simple, easy-to-guess password can have major ramifications if it leads to a successful breach from a hacker. In our first article, &lt;a href=&quot;/blog/6892/deepfake-response-plan-ai-cyberattacks&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;analysing the survey data&lt;/a&gt;, we found that many businesses hit by cyberattacks retroactively focused on plugging gaps, such as weak passwords, software update regularity, or improving network security. &lt;/p&gt;&lt;p&gt;If a staff member slips up in any of these ways, it may pose significant issues for the business. However, this risk is accelerated further if the person being targeted is in a company leadership position. &lt;/p&gt;&lt;h3&gt;What are the most common types of cybersecurity incidents targeting Aussie senior executives and why? &lt;/h3&gt;&lt;p&gt;While cyberattackers often modify their techniques to exploit vulnerable senior executives, some common practices continue to prevail. Respondents in our survey whose companies had suffered an attack targeting senior executives say breaches were facilitated mainly by phishing and malware attacks.&lt;/p&gt;&lt;img title=&quot;2-cyberattack-types-AU-GA-bar-chart&quot; alt=&quot;Bar chart showing the most common ways cyberattackers target Australian senior executives&quot; class=&quot;aligncenter&quot; loading=&quot;lazy&quot; src=&quot;https://images.ctfassets.net/63bmaubptoky/3hcO9CFRAspTGRybas0NzP/5a65af2a5b116e4b24df831172e3d006/2-cyberattack-types-AU-GA-bar-chart.jpg&quot; srcset=&quot;https://images.ctfassets.net/63bmaubptoky/3hcO9CFRAspTGRybas0NzP/5a65af2a5b116e4b24df831172e3d006/2-cyberattack-types-AU-GA-bar-chart.jpg?w=400 400w, https://images.ctfassets.net/63bmaubptoky/3hcO9CFRAspTGRybas0NzP/5a65af2a5b116e4b24df831172e3d006/2-cyberattack-types-AU-GA-bar-chart.jpg?w=700 700w, https://images.ctfassets.net/63bmaubptoky/3hcO9CFRAspTGRybas0NzP/5a65af2a5b116e4b24df831172e3d006/2-cyberattack-types-AU-GA-bar-chart.jpg?w=1000 1000w, https://images.ctfassets.net/63bmaubptoky/3hcO9CFRAspTGRybas0NzP/5a65af2a5b116e4b24df831172e3d006/2-cyberattack-types-AU-GA-bar-chart.jpg?w=1500 1500w, https://images.ctfassets.net/63bmaubptoky/3hcO9CFRAspTGRybas0NzP/5a65af2a5b116e4b24df831172e3d006/2-cyberattack-types-AU-GA-bar-chart.jpg?w=2200 2200w&quot; sizes=&quot;(min-resolution: 2x) 2200px, (min-width: 992px) 1000px, 95vw&quot;/&gt;&lt;p&gt;Making things even more perilous is the fact that cyberattackers are deploying newer, more sophisticated methods to attack companies that are not defending high-end data securely enough. Affecting 22% of Australian respondents in targeted companies, AI-assisted deepfake attacks top the charts. &lt;/p&gt;&lt;p&gt;Many of these attacks occur because of careless mistakes made by senior executives. Our data found a disregard for sharing sensitive information over unsecured channels and neglect to update software and systems regularly. However, Australian respondents are slightly more diligent in the global comparison, knowing to use strong passwords and download files from trusted sources. &lt;/p&gt;&lt;img title=&quot;3-cyberattack-vulnerabilities-AU-GA-stacked-bar-chart&quot; alt=&quot;Stacked bar chart showing the top actions by senior executives that led to a cyberattack in Australia compared to the global average&quot; class=&quot;aligncenter&quot; loading=&quot;lazy&quot; src=&quot;https://images.ctfassets.net/63bmaubptoky/3UCgecvp6M6nLBPx40QYfW/14b272a6517e258f25be878cfcce7e63/3-cyberattack-vulnerabilities-AU-GA-stacked-bar-chart.jpg&quot; srcset=&quot;https://images.ctfassets.net/63bmaubptoky/3UCgecvp6M6nLBPx40QYfW/14b272a6517e258f25be878cfcce7e63/3-cyberattack-vulnerabilities-AU-GA-stacked-bar-chart.jpg?w=400 400w, https://images.ctfassets.net/63bmaubptoky/3UCgecvp6M6nLBPx40QYfW/14b272a6517e258f25be878cfcce7e63/3-cyberattack-vulnerabilities-AU-GA-stacked-bar-chart.jpg?w=700 700w, https://images.ctfassets.net/63bmaubptoky/3UCgecvp6M6nLBPx40QYfW/14b272a6517e258f25be878cfcce7e63/3-cyberattack-vulnerabilities-AU-GA-stacked-bar-chart.jpg?w=1000 1000w, https://images.ctfassets.net/63bmaubptoky/3UCgecvp6M6nLBPx40QYfW/14b272a6517e258f25be878cfcce7e63/3-cyberattack-vulnerabilities-AU-GA-stacked-bar-chart.jpg?w=1500 1500w, https://images.ctfassets.net/63bmaubptoky/3UCgecvp6M6nLBPx40QYfW/14b272a6517e258f25be878cfcce7e63/3-cyberattack-vulnerabilities-AU-GA-stacked-bar-chart.jpg?w=2200 2200w&quot; sizes=&quot;(min-resolution: 2x) 2200px, (min-width: 992px) 1000px, 95vw&quot;/&gt;&lt;h3&gt;Which types of identity fraud are Australian senior executives most commonly subject to?&lt;/h3&gt;&lt;p&gt;There is also an especially serious risk factor of identity fraud facing executives more generally. Nearly half (48%) of our Australian respondents are working in companies hit by at least one identity fraud incident affecting a senior executive over the last 18 months. Compared to the global average, Australian senior executives witness significantly higher risks for document fraud.   &lt;/p&gt;&lt;img title=&quot;4-identity-fraud-types-AU-GA-stacked-bar-chart&quot; alt=&quot;Stacked bar chart showing which types of cyberattacks Australian senior executives are more susceptible to in global comparison &quot; class=&quot;aligncenter&quot; loading=&quot;lazy&quot; src=&quot;https://images.ctfassets.net/63bmaubptoky/7GICsW88yudFsmiUFLWZCz/e10820c0e385d61f18ce9b24df9db35a/4-identity-fraud-types-AU-GA-stacked-bar-chart.jpg&quot; srcset=&quot;https://images.ctfassets.net/63bmaubptoky/7GICsW88yudFsmiUFLWZCz/e10820c0e385d61f18ce9b24df9db35a/4-identity-fraud-types-AU-GA-stacked-bar-chart.jpg?w=400 400w, https://images.ctfassets.net/63bmaubptoky/7GICsW88yudFsmiUFLWZCz/e10820c0e385d61f18ce9b24df9db35a/4-identity-fraud-types-AU-GA-stacked-bar-chart.jpg?w=700 700w, https://images.ctfassets.net/63bmaubptoky/7GICsW88yudFsmiUFLWZCz/e10820c0e385d61f18ce9b24df9db35a/4-identity-fraud-types-AU-GA-stacked-bar-chart.jpg?w=1000 1000w, https://images.ctfassets.net/63bmaubptoky/7GICsW88yudFsmiUFLWZCz/e10820c0e385d61f18ce9b24df9db35a/4-identity-fraud-types-AU-GA-stacked-bar-chart.jpg?w=1500 1500w, https://images.ctfassets.net/63bmaubptoky/7GICsW88yudFsmiUFLWZCz/e10820c0e385d61f18ce9b24df9db35a/4-identity-fraud-types-AU-GA-stacked-bar-chart.jpg?w=2200 2200w&quot; sizes=&quot;(min-resolution: 2x) 2200px, (min-width: 992px) 1000px, 95vw&quot;/&gt;&lt;p&gt;Senior executives not adhering to their company’s security protocols can pose major threats to the business, especially given the access they have to secured data. While business leaders may have the capacity to override certain &lt;a href=&quot;/directory/1035/cybersecurity/software&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;cybersecurity safety&lt;/a&gt; features in cases of urgency, it is important to know the risks of taking such actions. &lt;/p&gt;&lt;div class=&quot;box-hint&quot;&gt;&lt;div class=&quot;box-header fw-700 mb-4&quot;&gt;&lt;svg viewbox=&quot;0 0 16 16&quot; aria-hidden=&quot;true&quot; class=&quot;icon icon-lightbulb box-header__icon align-middle mb-1 me-2&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; clip-rule=&quot;evenodd&quot; d=&quot;M4.98035 14.5098C4.98035 14.1776 5.24966 13.9083 5.58186 13.9083H10.5491C10.8813 13.9083 11.1506 14.1776 11.1506 14.5098C11.1506 14.842 10.8813 15.1113 10.5491 15.1113H5.58186C5.24966 15.1113 4.98035 14.842 4.98035 14.5098Z&quot; fill=&quot;black&quot;&gt;&lt;/path&gt;&lt;path fill-rule=&quot;evenodd&quot; clip-rule=&quot;evenodd&quot; d=&quot;M4.98035 13.5164C4.98035 13.1842 5.24966 12.9149 5.58186 12.9149H10.5491C10.8813 12.9149 11.1506 13.1842 11.1506 13.5164C11.1506 13.8486 10.8813 14.1179 10.5491 14.1179H5.58186C5.24966 14.1179 4.98035 13.8486 4.98035 13.5164Z&quot; fill=&quot;black&quot;&gt;&lt;/path&gt;&lt;path fill-rule=&quot;evenodd&quot; clip-rule=&quot;evenodd&quot; d=&quot;M8.06549 1.20301C5.38001 1.20301 3.20301 3.38001 3.20301 6.06549C3.20301 7.44115 3.7735 8.68254 4.69241 9.56779C4.9541 9.81989 5.20656 10.1313 5.37115 10.5134L5.97769 11.9214H10.1533L10.7598 10.5134C10.9244 10.1313 11.1769 9.81989 11.4386 9.56779C12.3575 8.68254 12.928 7.44115 12.928 6.06549C12.928 3.38001 10.751 1.20301 8.06549 1.20301ZM2 6.06549C2 2.71561 4.71561 0 8.06549 0C11.4154 0 14.131 2.71561 14.131 6.06549C14.131 7.7813 13.4177 9.33156 12.2732 10.4342C12.0857 10.6148 11.9469 10.7985 11.8647 10.9893L11.1015 12.7609C11.0065 12.9815 10.7893 13.1244 10.5491 13.1244H5.58186C5.34164 13.1244 5.12446 12.9815 5.02943 12.7609L4.26629 10.9893C4.18411 10.7985 4.0453 10.6148 3.85778 10.4342C2.71323 9.33156 2 7.7813 2 6.06549Z&quot; fill=&quot;black&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M5.58186 15.0065H10.5491L10.3184 15.468C10.1554 15.794 9.82212 16 9.45759 16H6.67338C6.30885 16 5.9756 15.794 5.81258 15.468L5.58186 15.0065Z&quot; fill=&quot;black&quot;&gt;&lt;/path&gt;&lt;/svg&gt;Avoid being marked as an easy target for cyberattacks&lt;/div&gt;&lt;p&gt;Unfortunately, being targeted successfully by a cyberattacker makes further attacks more likely, especially if the target is seen as high value. Cybercriminals may share details of those who were successfully breached or who ended up sharing personal data, which can lead others to breach your systems through the same vulnerabilities. That’s why it’s important to strengthen your cybersecurity measures to avoid attacks.&lt;/p&gt;&lt;p&gt;You can reduce the chances of unauthorised access with safety tools, such as &lt;a href=&quot;/directory/3814/multi-factor-authentication/software&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;multi-factor authentication (MFA)&lt;/a&gt;, &lt;a href=&quot;/directory/472/encryption/software&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;encryption&lt;/a&gt;, and &lt;a href=&quot;/directory/675/identity-access-management/software&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;identity management software&lt;/a&gt;.  &lt;/p&gt;&lt;/div&gt;&lt;h2 id=&quot;Aussie-employees-expect-senior-executives-to-receive-more-cybersecurity-training&quot;&gt;Aussie employees expect senior executives to receive more cybersecurity training&lt;/h2&gt;&lt;p&gt;We found that most (83%) Australian participants say they have cybersecurity training at least once a year or more. Our analysis unveiled that it is most common for senior executives to receive specialised cybersecurity training compared with other staff members. This is the case for 69% of Aussie senior executives compared to the global average of 57%. However, 28% of Aussie senior executives are not provided more enhanced training, putting them at significant risk.&lt;/p&gt;&lt;p&gt;That’s not to say there isn’t extensive training company-wide. We found amongst our sample that the majority have workplace coaching on subjects such as cybersecurity and data privacy. Whilst this is a good start, executives may need additional instructions to succeed against advanced cyberattacks. For example, they may need to be prepared for more advanced, individualised social engineering methods such as ‘whaling’ (highly nuanced attacks on high-value targets), which targets C-level executives specifically. &lt;/p&gt;&lt;p&gt;In total, 86% of Australian respondents agree that senior executives need more frequent and specialised training than regular employees. However, in many companies, this is not happening despite senior executives&amp;#39; crucial role in a company&amp;#39;s defence against cyberattacks. This is a greater concern as attacks attempting to exploit them are likely to differ from those directed at rank-and-file employees.&lt;/p&gt;&lt;p&gt;We focused on this factor in our survey to understand how well-prepared senior executives are to deal with potential cybersecurity threats. Overall, this is sufficiently addressed but some gaps remain.&lt;/p&gt;&lt;img title=&quot;5-cyber-training-AU-GA-bar-chart&quot; alt=&quot;Bar chart showing types of cybersecurity company training for Australian employees&quot; class=&quot;aligncenter&quot; loading=&quot;lazy&quot; src=&quot;https://images.ctfassets.net/63bmaubptoky/44eIW31fDH58uJbwX55ZtB/a99899de57b20c9e629fb3a0ab6fffa4/5-cyber-training-AU-GA-bar-chart.jpg&quot; srcset=&quot;https://images.ctfassets.net/63bmaubptoky/44eIW31fDH58uJbwX55ZtB/a99899de57b20c9e629fb3a0ab6fffa4/5-cyber-training-AU-GA-bar-chart.jpg?w=400 400w, https://images.ctfassets.net/63bmaubptoky/44eIW31fDH58uJbwX55ZtB/a99899de57b20c9e629fb3a0ab6fffa4/5-cyber-training-AU-GA-bar-chart.jpg?w=700 700w, https://images.ctfassets.net/63bmaubptoky/44eIW31fDH58uJbwX55ZtB/a99899de57b20c9e629fb3a0ab6fffa4/5-cyber-training-AU-GA-bar-chart.jpg?w=1000 1000w, https://images.ctfassets.net/63bmaubptoky/44eIW31fDH58uJbwX55ZtB/a99899de57b20c9e629fb3a0ab6fffa4/5-cyber-training-AU-GA-bar-chart.jpg?w=1500 1500w, https://images.ctfassets.net/63bmaubptoky/44eIW31fDH58uJbwX55ZtB/a99899de57b20c9e629fb3a0ab6fffa4/5-cyber-training-AU-GA-bar-chart.jpg?w=2200 2200w&quot; sizes=&quot;(min-resolution: 2x) 2200px, (min-width: 992px) 1000px, 95vw&quot;/&gt;&lt;p&gt;Those in the sample with no extra training for executives say that C-level staff have justified this decision for a few reasons. The most selected response indicates that Australian senior executives already possess sufficient knowledge (43%) which is significantly higher than the global average of 30%. &lt;/p&gt;&lt;img title=&quot;6-senior-leadership-cybersecurity-AU-GA-bar-chart&quot; alt=&quot;Bar chart showing reasons why Australian companies don’t provide additional cybersecurity training for senior executives&quot; class=&quot;aligncenter&quot; loading=&quot;lazy&quot; src=&quot;https://images.ctfassets.net/63bmaubptoky/5gdHY7wnvRUNQ1v8Z8NOYf/d4324094273a317646f0bad6a30e4663/6-senior-leadership-cybersecurity-AU-GA-bar-chart.jpg&quot; srcset=&quot;https://images.ctfassets.net/63bmaubptoky/5gdHY7wnvRUNQ1v8Z8NOYf/d4324094273a317646f0bad6a30e4663/6-senior-leadership-cybersecurity-AU-GA-bar-chart.jpg?w=400 400w, https://images.ctfassets.net/63bmaubptoky/5gdHY7wnvRUNQ1v8Z8NOYf/d4324094273a317646f0bad6a30e4663/6-senior-leadership-cybersecurity-AU-GA-bar-chart.jpg?w=700 700w, https://images.ctfassets.net/63bmaubptoky/5gdHY7wnvRUNQ1v8Z8NOYf/d4324094273a317646f0bad6a30e4663/6-senior-leadership-cybersecurity-AU-GA-bar-chart.jpg?w=1000 1000w, https://images.ctfassets.net/63bmaubptoky/5gdHY7wnvRUNQ1v8Z8NOYf/d4324094273a317646f0bad6a30e4663/6-senior-leadership-cybersecurity-AU-GA-bar-chart.jpg?w=1500 1500w, https://images.ctfassets.net/63bmaubptoky/5gdHY7wnvRUNQ1v8Z8NOYf/d4324094273a317646f0bad6a30e4663/6-senior-leadership-cybersecurity-AU-GA-bar-chart.jpg?w=2200 2200w&quot; sizes=&quot;(min-resolution: 2x) 2200px, (min-width: 992px) 1000px, 95vw&quot;/&gt;&lt;p&gt;Many who work in companies without extra training for their senior executives have confidence in their knowledge of cyber risks but there are reasons not to be too complacent. &lt;/p&gt;&lt;p&gt;The danger posed by newer threats such as AI-generated deepfakes, identity fraud, or individualised social engineering attacks may require a rethink of this policy. It may now possibly be the case that ‘sufficient knowledge’ noted by participants might no longer be enough. This is why it’s especially important to ensure that senior executives are aware of the new and evolving cyberthreats and are able to identify the vulnerabilities to stay as up to date as possible.&lt;/p&gt;&lt;h2 id=&quot;4-ways-to-prepare-senior-executives-for-cybersecurity-risks&quot;&gt;4 ways to prepare senior executives for cybersecurity risks &lt;/h2&gt;&lt;p&gt;There is a desire from employees and, in fact, an imperative for senior executives to be trained on the specific cybersecurity dangers they face. We’ve already seen in our findings that they are likely to be targeted and that any mistakes on their part that undermine network security can be costly.&lt;/p&gt;&lt;p&gt;There are a number of new and developing threats that additional cybersecurity training can help prepare executives to face effectively. These include elements such as the following:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;&lt;b&gt;Create awareness of current threats: &lt;/b&gt;Cyberthreats are evolving quickly, and senior executives need to stay current on the methods that can specifically target them. As discussed before, time constraints may affect executive-level cybersecurity training. However, businesses can also rely on &lt;a href=&quot;/directory/3809/security-awareness-training/software&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;security awareness training software&lt;/a&gt; to access courses and guidance that adapt to their busy schedules without needing a specialised course.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Protect image and personal data: &lt;/b&gt;Executives represent a major target for social engineering attacks. A lot of information needed to impersonate an executive can be found online, either from company sources, local media, or their social network activities. Therefore, it is especially important to make executives aware of what they should and shouldn’t share online and to have them regularly review their information security.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Conduct a risk assessment: &lt;/b&gt;Executives should feel empowered to make decisions but must also be aware of potential risks that may occur when carrying out certain activities, such as finalising high-value transactions that could be fraudulent. Understanding such risks enables businesses to prevent unwanted outcomes. These might include procedures to assess if a video call is a deepfake or having &lt;a href=&quot;/directory/480/network-monitoring/software&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;network monitoring&lt;/a&gt; implemented that can detect threats. Additionally, preventive steps can be initiated if an incident is noticed mid-attack, such as how to halt fraudulent transactions or recover lost funds, not to mention &lt;a href=&quot;/directory/2171/disaster-recovery/software&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;disaster recovery&lt;/a&gt; strategies if they do succeed. &lt;/li&gt;&lt;li&gt;&lt;b&gt;Ensure personal devices and networks are secure:&lt;/b&gt; Company information should always be kept solely on company devices, and where possible, secure Wi-Fi networks should be used only, but in today’s interconnected world, this doesn’t always happen. Insecure apps or malware, however, can represent a big issue if they get onto company infrastructure, which is why it is important to educate executives to be especially wary of exposing their devices to these risks. Using a &lt;a href=&quot;/directory/613/mobile-device-management/software&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;mobile device management system&lt;/a&gt; can help secure mobile hardware by providing monitoring capabilities and controlling use policy. &lt;/li&gt;&lt;/ol&gt;&lt;div class=&quot;box-idea&quot;&gt;Looking for &lt;a href=&quot;/directory/3809/security-awareness-training/software&quot; rel=&quot;noopener noreferrer&quot; class=&quot;event&quot; data-evna=&quot;engagement_facet_click&quot; data-evcmp=&quot;blog-idea&quot; data-evdst=&quot;go-to_category-page&quot; data-evdtl=&quot;text-link_category-name&quot; target=&quot;_blank&quot;&gt;security awareness training software&lt;/a&gt;? Check out our catalogue! &lt;/div&gt;&lt;p&gt;&lt;/p&gt;","dateModified":"2024-09-24T20:30:03.000000Z","datePublished":"2024-09-25T00:00:00.000000Z","mainEntityOfPage":"https://www.getapp.com.au/blog/6922/senior-executive-security-awareness-training-programs#webpage"}]}
</script>
