Certified Information Security Manager (CISM)Information Security ProgramMedium

A CISO is reviewing the quarterly operational security metrics. The report indicates a consistent increase in phishing attempts blocked at the perimeter, but also a slight rise in successful internal credential compromises linked to social engineering. The CISO has a limited budget for new initiatives. Which of the following actions should the CISO prioritize to address this trend effectively?

  1. AInvest in a more advanced email filtering solution to block a higher percentage of phishing attempts.
  2. BConduct a penetration test specifically targeting social engineering vulnerabilities.
  3. CLaunch a targeted security awareness campaign focused on identifying social engineering tactics.
  4. DImplement multi-factor authentication (MFA) across all critical internal systems.
Show answer & explanation

Correct answer: C. Launch a targeted security awareness campaign focused on identifying social engineering tactics.

The problem states that phishing attempts are blocked at the perimeter, but internal compromises are rising due to social engineering. This indicates a human vulnerability that advanced filtering alone won't solve. A targeted awareness campaign directly addresses the root cause (human susceptibility to social engineering) and is generally more cost-effective than widespread MFA deployment as a first response to this specific problem, especially with a limited budget.

Why the other options are wrong

  • A. This addresses perimeter blocking but not the internal human element causing successful compromises.
  • B. While useful for identifying vulnerabilities, a penetration test doesn't directly solve the problem; it only identifies it. A campaign is an active solution.
  • D. MFA is effective but can be costly and complex to implement across all systems, especially with a limited budget, and may not fully prevent all social engineering tactics like phone-based vishing or pretexting if users are tricked into providing MFA codes.

Targeted Security Awareness

Security awareness training designed to address specific, identified human vulnerabilities or prevalent threats within an organization.

  • Addresses root causes of human-centric security incidents.
  • Cost-effective for specific behavioral issues.
  • Focuses on relevant threats (e.g., social engineering, phishing).

Memory trick: When the mind is tricked, the message must stick.

More Information Security Program questions