Title:Ozaveščenost zaposlenih o napadih z izvabljanjem gesel
Authors:ID Schweiger, Til (Author)
ID Brezavšček, Alenka (Mentor) More about this mentor... New window
Files:.pdf UN_Schweiger_Til_2024.pdf (2,26 MB)
Work type:Bachelor thesis/paper
Typology:2.11 - Undergraduate Thesis
Organization:FOV - Faculty of Organizational Sciences in Kranj
Abstract:V diplomskem delu smo predstavili najpogostejše kibernetske napade, motive, metode in tehnike, s katerimi izvedejo napad na informacijski sistem. Na kratko smo predstavili tudi finančno organizacijo, v kateri smo izvedli raziskavo. Raziskava je bila izvedena v dveh fazah. Najprej smo izvedli simulacijo napada z izvabljanjem, da bi ugotovili, koliko zaposlenih bo lažnemu napadu nasedlo. V drugi fazi pa smo izvedli anketo, katere namen je bil ugotoviti, kako učinkoviti so zaposleni pri prepoznavanju lažnih in avtentičnih elektronskih sporočil. Rezultati so pokazali, da trenutni ukrepi v organizaciji ne zadoščajo, saj preveliko število zaposlenih še vedno ne prepozna napadov. Za izboljšanje stanja smo organizaciji predlagali nekaj ukrepov, ki bodo pripomogli k doseganju višje stopnje ozaveščenosti zaposlenih.
Keywords:kibernetska varnost, socialni inženiring, napad z izvabljanjem, finančna organizacija
Place of publishing:Maribor
Year of publishing:2024
PID:20.500.12556/DKUM-87968 New window
COBISS.SI-ID:196954627 New window
Publication date in DKUM:28.05.2024
License:CC BY-SA 4.0, Creative Commons Attribution-ShareAlike 4.0 International
Description:This Creative Commons license is very similar to the regular Attribution license, but requires the release of all derivative works under this same license.
Licensing start date:03.04.2024

Secondary language

Title:Employee awareness of phishing attacks
Abstract:In the thesis, we presented the most common cyber attacks, motives, methods and techniques used to attack the information system. We also briefly presented the financial organization in which we conducted the research. The research was conducted in two phases. First, we ran a phishing attack simulation to see how many employees would fall for the fake attack. In the second phase, we conducted a survey, the purpose of which was to determine how effective employees are in identifying fake and authentic electronic messages. The results showed that the current measures in the organization are not sufficient, as too many employees still do not recognize the attacks. In order to improve the situation, we proposed some measures in the organization that would help to achieve a higher level of employee awareness.
Keywords:cyber security, social enginering, phishing, financial organization


