WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Security Awareness – Higher than Average Critical Infrastructure Employees Correctly Report Phishing Attempts
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Security Awareness – Higher than Average Critical Infrastructure Employees Correctly Report Phishing Attempts

Author: April Zupan

Created: Tuesday, July 25, 2023 - 18:46

Categories: Cybersecurity, Research

Hoxhunt has released its Human Cyber-Risk Report: Critical Infrastructure, with a key finding that 66% of critical infrastructure employees have correctly reported at least one malicious phishing attempt. Hoxhunt’s researchers state that this statistic is 20% higher than the averages for other industries they’ve done phishing studies for.

This report breaks things down further by analyzing phishing statistics within an organization. Hoxhunt finds that spoofed internal organizational communications are the most effective type of phishing attack and critical infrastructure organizations have an 11.4% higher failure rate to these types of attacks. This suggests members should consider emphasizing the topic of impersonation attacks of internal staff during employee awareness training. The report did find that phishing training produced real-life behavior change and critical infrastructure employees participate at higher rates than other sectors. On a departmental level, marketing and communications were found to have the highest phishing failure rates. Read more at Dark Reading.

Related Resources

Members Only

(TLP:AMBER) New IOCs (Stryker) and Malware Analysis Report (F5 BIG-IP)

Jun 5, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) EPA to Conduct 2026 National Cyber Drill Focused on Operating Without Telecommunications and Internet Connectivity

Jun 4, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) CISA and Partners Urge Hardening Automatic Tank Gauge Systems

Jun 4, 2026 in Cybersecurity, Federal & State Resources, OT-ICS Security

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar