Methods of protection against phishing attacks in corporate networks
| Authors: Dronov Yu.D., Glinskaya E.V. | |
| Published in issue: #4(105)/2026 | |
| DOI: | |
Category: Informatics, Computer Engineering and Control | Chapter: Methods and Systems of Information Protection, Information Security |
|
Keywords: phishing, corporate security, two-factor authentication, cyberliteracy, email threats, human factor, machine learning, information security incidents |
|
| Published: 24.08.2026 | |
This article examines the pressing issue of protecting corporate information systems from phishing attacks. Modern types of phishing are analyzed, including spear phishing and Business Email Compromise. Comprehensive countermeasures are described, combining technical tools (mail traffic filtering systems, antivirus software with behavioral analysis, and two-factor authentication) and organizational measures (regular employee training and training phishing campaigns). Particular attention is paid to the role of artificial intelligence and machine learning in predicting and preventing attacks. Based on a comparative analysis of the effectiveness of various methods, the need to implement a multilayered security system tailored to specific threats and the human factor is substantiated. The study emphasizes that only a combination of technologies and improved cyberliteracy among personnel can significantly reduce the risk of successful phishing attacks.
References
[1] Verizon. 2023 Data Breach Investigations Report. Alexandria, VA, Verizon, 2023, 89 p.
[2] Volodin, A.A., Glinskaya, E.V., Development and Challenges of Using Artificial Intelligence in Information Security. Polytechnic Youth Journal, 2024, No. 02 (91). (In Russ.). URL: https://ptsj.ru/catalog/icec/insec/969.html (accessed 15.10.2025).
[3] Proofpoint. State of the Phish Report 2024. Sunnyvale, Proofpoint, 2024, 29 p.
[4] Bochnev, N.A., Kharisov, A.R., Reliable Authentication Methods in Government and Corporate Information Systems: Principles, Technologies, and Prospects. Bulletin of Science, 2024, No. 12 (81), vol. 5, part 1. p. 642–649. (In Russ.).
[5] KnowBe4. Phishing Benchmarking Report 2023. Clearwater, KnowBe4, 2023, 35 p.
[6] Google. Phishing Activity Trends Report. Mountain View, Google, 2023.
[7] Mansfield-Devine S. The rise of AI-powered phishing. Computer Fraud & Security, 2021, vol. 2021, no. 5, pp. 10–15. https://doi.org/10.1016/S1361-3723(21)00050-5
[8] Silgado A.P. et al. Leveraging User Behavior Analytics for Early Phishing Detection. Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, 2022, pp. 543–556.
[9] ENISA. Cyber Security Culture in Organizations. Heraklion, European Union Agency for Network and Information Security, 2018, 78 p. URL: https://www.enisa.europa.eu/publications/cyber-security-culture-in-organisations (accessed 15.10.2025).
[10] Petersen R., Santos D., Smith M.C., Wetzel K.A., Witte G. Workforce Framework for Cybersecurity (NICE Framework). NIST Special Publication 800-181, Rev. 1. Gaithersburg, National Institute of Standards and Technology, 2020, 27 p.https://doi.org/10.6028/NIST.SP.800-181r1
