Site navigation

Report: Overconfident Security Execs Blind to Mobile Threats

Tom Quinn

,

mobile threat, phishing
“Today’s threat actors are increasingly sophisticated, and they understand that mobile endpoints have historically been an afterthought in many enterprise security strategies,” said Jim Dolce, CEO of Lookout.

Security leaders are alarmingly overconfident in the ability of employees to spot modern mobile threats, leaving businesses significantly more exposed than they realise, according to new research from Lookout.

The mobile endpoint security specialist’s latest report, The Mobile Security Mirage, found that 96% of security executives believe their employees can recognise phishing attempts that come via their mobile devices, despite over half reporting incidents where workers fell victim to impersonation scams, leading to financial loss or sensitive data exposure.

Polling more than 700 security leaders around the world, Lookout discovered that 58% of companies have experienced incidents due to executive impersonation scams via text or voice, while more than three-quarters (77%) have been the victim of one or more mobile phishing attacks in the past six months.

Rather than understanding the scope of the threat, however, security leaders are too often left in the dark. 

Lookout said that over half of social engineering incidents involving mobile devices go either unnoticed or unreported, creating a ‘massive’ security blind spot, with only half of respondents saying they are concerned about such risks.

A major part of the problem is that although organisations feel ready for threats, in reality, they are underprepared.


Recommended reading


Even with constant security training efforts, ‘lack of training’ remains the top reason cited for employees clicking suspicious links, while traditional security solutions often lack visibility into mobile-centric social engineering attempts.

Lookout said that the findings show security awareness and training isn’t evolving fast enough to keep up with a rapidly changing threat landscape, fuelled by ever more innovative uses of AI by malicious actors.

“Today’s threat actors are increasingly sophisticated, and they understand that mobile endpoints have historically been an afterthought in many enterprise security strategies,” said Jim Dolce, CEO of Lookout. 

“Attackers are aggressively targeting employees on their iOS and Android devices, using highly effective social engineering tactics delivered via SMS, voice, and messaging apps to compromise credentials and gain quiet access to enterprise data.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data