This project presents a simulated threat analysis of a phishing attack targeting a small healthcare organization.
The objective is to identify attack methods, evaluate potential impact, and recommend mitigation strategies.
To analyze a phishing attack scenario, assess the risks, and propose actionable controls to prevent similar incidents.
- Simulate a phishing email targeting staff
- Analyze potential vulnerabilities exploited
- Evaluate impact and likelihood
- Recommend preventive controls and awareness measures
| Attack Vector | Target | Exploited Vulnerability | Likelihood | Impact | Risk Level |
|---|---|---|---|---|---|
| Phishing Email | Staff Email System | Lack of awareness training | High | Medium | High |
| Credential Harvesting | Staff Email | Weak password policies | Medium | High | High |
| Malware Attachment | Staff Devices | No endpoint protection | Medium | Medium | Medium |
- Staff are susceptible to phishing due to low security awareness
- Weak passwords increase risk of account compromise
- Lack of endpoint protection allows malware spread
- Conduct regular phishing awareness training
- Implement multi-factor authentication (MFA)
- Deploy endpoint protection and email filters
- Regularly review user access rights
- NIST Cybersecurity Framework (CSF)
- CIS Critical Security Controls
Mercy Christopher
Cybersecurity Analyst | GRC & Threat Analysis
LinkedIn: www.linkedin.com/in/mercy-christopher-24bb17350
Email: mercychrispearly@outlook.com