WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships Reports: Social Engineering & Ransomware Rank as Biggest Threats to Small Organizations
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Reports: Social Engineering & Ransomware Rank as Biggest Threats to Small Organizations

Author: Chase Snow

Created: Thursday, March 14, 2024 - 18:16

Categories: Cybersecurity, Security Preparedness

The 2024 Sophos Threat Report published this week highlights how cybercrime disproportionally targets small businesses and hits them the hardest. Small organizations are typically more vulnerable to cyber attacks and thus suffer more from the impact of an attack. According to the report, ransomware, followed by business email compromise (BEC), continues to be the greatest threat to smaller organizations and also packs the biggest punch. Likewise, the Mimecast State of Email & Collaboration Security 2024 (SOECS) report indicates that social engineering is today’s biggest cybersecurity gap and continues to remain largely unaddressed. Social engineering tactics are also becoming more sophisticated generally, with attackers being more likely to actively engage using a thread of emails and responses making their lures more convincing. In addition, BEC attacks nearly doubled in 2023 according to Mimecast.

Both reports provide a common theme present in the current state of cyber threats affecting smaller organizations – while attackers are using more sophisticated social engineering tactics coupled with ransomware, smaller organizations are less likely to have proper cybersecurity defenses in place leaving them substantially more vulnerable.

Data is the prime target.

The reports also show that cybercriminals are chiefly interested in data. The Sophos report indicates that more than 90% of attacks reported by customers involved data or credential theft in one way or another. Attacks will almost always begin with some form of social engineering tactic, which is usually phishing, which will then deploy some form of malware to steal data– often ransomware. Stolen data/credentials can then be sold to other criminals with additional malicious intent. To help increase user awareness of the social engineering tactics designed to trick them, members may wish to consider having employees participate in this upcoming event hosted by the Small Business Administration on “Combatting Social Engineering Attacks.”

For additional insight into the Sophos and Mimecast reports, access Help Net Security and IT Security Guru. 

Additional Resources:

  • 10 Tips for Security Awareness Training that Hits the Target | WaterISAC
  • Cyber-Physical Security Awareness – Effective Social Engineering Tricks that Still Work  | WaterISAC
  • Avoiding Social Engineering and Phishing Attacks | CISA

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 1, 2026)

May 1, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Tip of the Week – April 30, 2026

Apr 30, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) Cyber Readiness Institute Joins WaterISAC as a Community Partner to Strengthen Cyber Readiness Across the Water Sector

Apr 30, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar