A large healthcare organization recently experienced a ransomware attack that encrypted patient records (ePHI). The attack originated from a phishing email that bypassed the email security gateway. The security program includes annual security awareness training, but post-incident analysis reveals that employees often ignore suspicious emails. The CISO wants to revise the program to reduce the likelihood of similar incidents. Which course of action is most effective?
This directly modifies employee behavior through repeated testing and education.
Why this answer
Most effective because it directly addresses the human factor by increasing the frequency of phishing simulations and providing remedial training, which reinforces secure behavior. Option A improves technology but does not change employee behavior. Option B (next-generation email security gateway) may help block some phishing emails but does not address the root cause of employees ignoring suspicious emails.
Option C (EDR) can detect ransomware after execution but does not prevent the initial phishing compromise.