David Bish - Behavioural Insights Analyst€¦ · Today’s session Introduction to cybercrime •...

Post on 08-Aug-2020

1 views 0 download

transcript

Dr Debra Malpass - Head of Research and AnalysisDavid Bish - Behavioural Insights Analyst

Risk update: Cybercrime

Today’s session

Introduction to cybercrime

• What is the risk posed by cybercrime?

Behavioural aspects of cybercrime

• Results from cyber email trials

The solicitors and law firm market

10,400Firms

185,000Individuals

750ABS

Across England and Wales we regulate:

Introduction to cybercrime

Widespread within the UK

Attacks can threaten firms

operations and/or reputation

Law firms targeted for

money and/or information

Cybercrimes and scams

Hacking CEO Fraud Email modification

Malware Identity theft

Impact on the legal market

£6.2m

client money lost to

cybercrime

164

reports to us about

cybercrime

2018 2018

Email modification fraud - more than 80% of

all cybercrime reports to us

Email fraud reports to us

up by23%

(since 2017)

Why do people fall prey to cyber attacks?

There are a number of behavioural and environmental factors that influence whether we fall prey to cyber attacks

Context Time Behaviour

Cybercrime email trial: Day of the week

Key facts

• 7,295 firms involved

– C2,400 in each group

• 6 week trial period

Results

Does the timing of the messages affect how firms engage with the communications?

0

100

200

300

400

500

Wed 1 Fri 1 Wed 2 Fri 2 Wed 3 Fri 3 Wed 4 Fri 4 Wed 5 Fri 5 Wed 6 Fri 6

Engagement rate over the trial period

Help the SRA!

Could you be next?

You wouldn’t fall for this, but…

Key facts

• 10k firms involved– 3,300 in each group

• 3 month trial period – 3 end of month emails

Cybercrime email trial: Subject line

Initial results

0

5000

10000

15000

20000

25000

30000

First day One month later

Engagement with different email tones

Positive message Fear factor Illusory Superiority

Does the tone of the messages affect how firms engage with the communications?

What does this mean for you?

• Stay aware– It’s a matter of when, not if…

• Complete appropriate checks– A little time now can save a lot of time later

• Raise awareness– Consider how you communicate with your firm

Thank you

Find out more:

Risk Outlook IT Security paper Technology and

legal services paper