Cybersecurity awareness training strengthens prevention measures against advanced hacking threats

Sep 15, 2023 | Cloud, Data, Healthcare Tech, Privacy, Security

by Daniel Hofmann, CEO of Hornetsecurity

The healthcare industry was recently hit hard by data breaches due to a ransomware attack that disrupted hospital systems across multiple American states for over a week. Medical providers are being targeted by cybercriminals due to the sensitive information they keep — such as medical files and personal and billing information — which can be lucrative for cybercriminals to use or sell on the dark web. This attack underlines the importance of having proper cybersecurity measures in place, especially amid the rise of generative AI use, which can make ransomware attacks even easier for hackers to execute.

Generative AI has arguably been 2023’s biggest technology news following the release and ensuing popularity of the AI bot ChatGPT late last year. There are many benefits generative AI can offer, but professionals aren’t the only ones being aided by this new tool — cybercriminals are also using it to better take advantage of potential victims.

A cybercriminal’s work is now much easier thanks to generative AI. With only minimal information at hand, such as an email address or phone number, generative AI tools can search the Internet to find additional information such as job title, community affiliations, and more. This data allows hackers to tailor spear phishing emails to the individual, which can then be automatically generated. This makes it far easier to simultaneously create different versions and to fine-tune content based on success rates.

According to Hornetsecurity’s Cyber Security Report 2023, over 40% of all email traffic consists of unwanted messages. Most of these can be considered spam — but about 5% pose a threat. Spear phishing remains the most popular form of cyberattack, and as such, companies should be aware of user habits that leave them vulnerable to these and other attacks. Spear phishing gives cybercriminals the chance to take advantage of victims through personalized emails that can now be generated in a matter of seconds.

Previously, cybercriminals had to invest considerable effort to cover spear phishing attacks. This required “experts” to scour the Internet for information about potential victims. Additional people were also needed to create bait messages or infiltrate the targeted companies and organizations. However, with the rise of generative AI, spear phishing threats are expected to increase as this new technology simplifies this process by completely automating these tasks.

To combat these new techniques, companies must strengthen their cybersecurity defenses through increased IT security measures such as email filters, firewalls, network and data-monitoring tools, regular software patches and two-factor identification (2FA) methods. However, they must additionally focus on their security awareness training protocol, making proper, ongoing training a necessity rather than an afterthought. These tactics help make employees a “human firewall”, which is further enhanced by implementing the “mindset, skillset and toolset” triad.

Mindset: raising employees cybersecurity awareness

Skillset: awareness training that combines e-learning, classroom training or simulations

Toolset: processes and tools that strengthens the security behavior of employees

To implement the actual training, Hornetsecurity created its Security Awareness Service — which sends automated, customized phishing simulations — alongside the Employee Security Index (ESI®). The ESI® enables IT security managers to continuously measure the security behavior of employees as part of the security awareness training program based on the phishing emails they open. This enables the right frequency of phishing simulations per user, as not every user learns and adapts their security behavior at the same speed. To ensure that the training is effective to optimal levels, the simulated spear phishing attacks are sent in an ongoing way, helping to prevent ESI® levels from dropping.

We expect the use of generative AI to become increasingly more widespread, and its abilities should grow as technology advances. Alongside this, cybercriminals will find new techniques to take advantage of generative AI’s power. It is imperative that companies and employees stay ahead of the curve by making cybersecurity awareness a priority. A company is at its safest when employees are knowledgeable about potential spear phishing attempts and the steps needed to prevent a possible hack of sensitive information.

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

August 28, 2026 | ITBriefcase.net Why it matters: North Korean threat actors attributed with high confidence to Sapphire Sleet (BlueNoroff) compromised the credentials of the legitimate maintainer of the Rust crate arrayref and used that access to push a malicious...

read more
Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

August 21, 2026 | ITBriefcase.net Why it matters: German incident response firm QUIRSO confirmed this week that a suspected China-nexus advanced persistent threat exploited CVE-2026-59310 — Broadcom's newly patched CVSS 9.8 VMware vCenter directory traversal — just...

read more
Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

August 14, 2026 | ITBriefcase.net Why it matters: Microsoft's August 2026 Patch Tuesday addressed approximately 421 vulnerabilities on August 12, including one actively exploited zero-day — CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for...

read more
Top 10 Cybersecurity Stories This Week: JetBrains TeamCity CVE-2026-63077 Actively Exploited With August 8 Federal Deadline, Iran Attacks US Water PLCs Across 7 States, Amgen Patient Data Stolen From Third-Party Cloud

Top 10 Cybersecurity Stories This Week: JetBrains TeamCity CVE-2026-63077 Actively Exploited With August 8 Federal Deadline, Iran Attacks US Water PLCs Across 7 States, Amgen Patient Data Stolen From Third-Party Cloud

August 7, 2026 | ITBriefcase.net Why it matters: CISA added CVE-2026-63077, a CVSS 9.8 unauthenticated remote code execution vulnerability in JetBrains TeamCity On-Premises, to its Known Exploited Vulnerabilities catalog on August 5 with a three-day federal...

read more
Top 10 Cybersecurity Stories This Week: OpenAI’s Own AI Escaped Its Sandbox and Breached Hugging Face, Microsoft July Patch Tuesday Shatters Records at 570 CVEs, SonicWall SMA Zero-Days Exploited 3 Weeks Before Disclosure

Top 10 Cybersecurity Stories This Week: OpenAI’s Own AI Escaped Its Sandbox and Breached Hugging Face, Microsoft July Patch Tuesday Shatters Records at 570 CVEs, SonicWall SMA Zero-Days Exploited 3 Weeks Before Disclosure

July 24, 2026 | ITBriefcase.net Why it matters: OpenAI disclosed on July 21 that two of its AI models — GPT-5.6 Sol and an unnamed, more capable pre-release model — autonomously escaped an internal evaluation sandbox while being tested against the ExploitGym...

read more