CLOSE

Specials

I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

Skip to: Curated Story Group 1
Life Sciences Review
US
EUROPE
APAC
CANADA

About Us

Conference

Partner With Us

  • US
    • EUROPE
    • APAC
    • CANADA
    • LATAM
  • Drug Discovery
    Antibodies
    BioTech
    Cell and Gene Therapy
    Clinical Trial
    Drug Discovery and Development
    Life Science AI
    Regenerative Medicine
    Therapeutics
  • Biomanufacturing
    Biomanufacturing
    Bioprocessing
    Blood Bank
    CDMO
    Clinical Laboratory
    CRO
    Life Science Testing
    Skin Care
    Supplements
  • Business Services
    Life Science Consulting
    Life Science Facility Service
    Life Science Financial Services
    Life Science Marketing
    Life Science Recruitment Firms
    Pharma Wholesale and Distribution
    Pharmacy Management
    Regulatory and Compliance
    Regulatory Services
  • Leadership Perspectives
  • Innovation Insights
  • Research
  • News
  • Magazines
  • CXO Awards
×
#

Life Science Review Weekly Brief

Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from Life Science Review

Subscribe

loading

Thank you for Subscribing to Life Science Review Weekly Brief

A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by our Life Sciences Review Advisory Board.

University of Minnesota Physicians

Michael Rockhold, Vice President, Information Technology & Information Security Officer

Phishing Simulation Tests: Low Tech, High Value

Michael Rockhold

Michael Rockhold

US. healthcare organizations were the victims of over 1400 cyberattacks per week, on average, in 2022, resulting in nearly 50 million people, or 1 in 7 Americans, whose healthcare records were compromised from data breaches. To put that in perspective, you are more likely to get your healthcare record compromised this year than you are to get the flu.


According to Deloitte, 91% of cyberattacks begin with a phishing email, and the reason cyber attackers leverage email is that it is easier to trick humans than it is to trick firewalls and identity management services. When it comes to reducing the risk of employees falling victim to phishing schemes and social engineering attacks, sometimes the most effective solutions are the simplest or more low-tech solutions, specifically, security awareness training through simulated phishing attacks.


Simulated phishing is a process where an organization sends deceptive emails that simulate malicious emails to its own employees to gauge how the workforce will respond to real email attacks. Industry-leading tools in this space, like KnowB4 and PhishGrid, also provide realtime training for users who fail the simulated tests.


Consider the risk your healthcare organization is currently facing without an effective phishing simulation process and platform. While email filtering and protection solutions, such as Proofpoint or Darktrace, are effective and necessary tools in all computing environments, they still have a conservative failure rate of 10%, meaning 10% of malicious emails sent to an organization with an email filtering tool in place are not detected and blocked by the tool. Here is a directionally accurate calculation of the phishing opportunity risk for a typical 1,000-employee healthcare organization:


• The average person receives about 140 emails a day;


• In an organization of 1,000 employees, that equals 140,000 emails a day, and at 260 working days, approximately 36,000,000 emails per year


• If 25% of those emails come from external domains, that is 9,000,000 emails that your email protection solution has to evaluate for safety


• According to Astra, the cybersecurity SaaS company, about 1.2% of emails sent are malicious, which means that in a 1,000-employee organization, approximately 108,000 a year are malicious


 • If even the best email protection tools do not identify 10% of those 108,000 as malicious, that means nearly 11,000 malicious emails have made their way into the email environment


 When you extrapolate numbers like this for larger organizations, the level of risk is sobering. Even more sobering is when you consider the difference between organizations that have a phishing simulation tool and process vs. those that do not.


Simulated phishing is a process where an organization sends deceptive emails that simulate malicious emails to its own employees to gauge how the workforce will respond to real email attacks

 


According to KnowB4, for a healthcare organization with more than 1,000 employees, the average phish-prone percentage score after running its first phishing simulation campaign is 47%, which is calculated as the percentage of employees who are prone to clicking on a phishing link. After implementing a standard, regular process of phishing simulation tests and dynamic training for failures for a full year, the average phish-prone percentage for that same-sized healthcare organization goes down to 5%.


In other words, if you are a healthcare organization that does not run phishing simulation tests with real-time training, you are nine times more likely to be at risk for an emailoriginated cybersecurity event than an organization that does. These are not just scare tactic statistics used to sell products, as first-hand experience with phishing simulation tests in my organization mirrored these numbers.


The benefits of phishing simulation tools are tangible. And though phishing simulation tools are not as difficult to implement as many other cybersecurity solutions, they do require thoughtful process and people considerations. Here are some important tips if you are considering a phishing simulation solution deployment:


• Remember that the goal of the phishing simulation exercises is to teach your employees, not punish them


• Commit to a regular cadence of phishing simulation exercises with content that is customized to your organization


• Choose a tool that provides immediate, educational feedback to employees who fall victim to the simulated attacks


 • Use the tool to gain a baseline understanding of your organization’s susceptibility to phishing attacks and set realistic improvement goals that target areas of weakness


So many organizations still view cyber security training as an annual event where the information security team is pressured to create content that can be clicked through rapidly, a “check the box” exercise deemed more of a nuisance than an educational opportunity. The phishing simulation tool changes  that dynamic by providing real-time education based on quantifiable organization weaknesses and is arguably one of the most undervalued tools in the crowded and complex landscape of cyber security technology solutions.


The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.
The Leadership Perspectives forum brings together voices shaping the future of life sciences. It features leaders who are advancing change across the industry through strategic leadership and applied insight.
EDITOR'S CHOICE
  • Willis Towers Watson

    ICON [NASDAQ: ICLR]

    The Significant Increase in Demand for Clinical Research Associates (CRAs)

    Helen Yeardley, Executive Vice President, ICON [NASDAQ: ICLR]

  • Willis Towers Watson

    PacBio [NASDAQ: PACB]

    The Talent - Culture Continuum: How to Manage an Innovation Culture Amid Growth and Change

    Alvin Hom, Head of Global Talent Acquisition, PacBio [NASDAQ: PACB]

  • Willis Towers Watson

    Repligen Corp [NASDAQ: RGEN]

    Gene Therapy-Therapeutic Viral Vectors; Manufacturing, Challenges, and Innovation

    Rachel Legmann, PhD, Senior Director of Technology, Gene Therapy, Repligen Corp

  • Willis Towers Watson

    Ionis Pharmaceuticals [NASDAQ: IONS]

    Bridging the Diversity Divide

    Victoria Sanjurjo, Medical Director, Clinical Development, Ionis Pharmaceuticals, Inc [NASDAQ: IONS]

Life Sciences Review
Follow on LinkedIn

About

  • Home
  • About Us
  • Partner With Us

Stay Connected

  • Subscribe
  • Newsletter
  • Sitemap

Contact Us

  • editor@lifesciencesreview.com
  • sales@lifesciencesreview.com
  • marketing@lifesciencesreview.com

Legal

  • Editorial Policy
  • Privacy Policy
  • Terms of Use

© 2026 Life Sciences Review. All rights reserved. Headquartered in Fort Lauderdale, FL, USA.

This content is copyright protected

However, if you would like to share the information in this article, you may use the link below:

https://biometric-fingerprint.lifesciencesreview.com/leadership-perspective/phishing-simulation-tests-low-tech-high-value-nwid-2305.html