Following a recent data breach caused by a phishing email, a hospital recognized the urgent need to train staff on identifying and reporting phishing attempts. With healthcare infrastructure remaining a prime target for cyberattacks, the goal is to increase phishing email reports to IT by 30% by the end of Q4.

This branched scenario is a demo designed to test your ability to identify red flags in suspicious emails and determine whether they're legitimate or phishing attempts.

Target group

5.000 hospital staff members at St. John's Medical Centre working with their email system.

Goal

Phishing email reports to IT increase by 30% by the end of Q4 as hospital staff consistently identify and report suspicious emails through the ticketing system.

Tools used

Didactic methods

Background

In 2021, the Health Service Executive (HSE) of Ireland suffered a devastating ransomware cyber attack that began with a phishing email. A staff member opened a malicious Microsoft Excel file attached to the phishing email, which allowed hackers to gain access to the HSE network. The attackers operated undetected for eight weeks before launching their ransomware attack on May 14th, 2021, causing all HSE IT systems nationwide to shut down and disrupting healthcare services across Ireland. (more information: Health Service Executive)

As this incident is a real life scenario, I thought of ways how a team could respond in this situation. One way to protect companies from cyber attacks is to have trained staff. I therefore came up with the fictional hospital St. John's Medical Centre. In my scenario, it is a large hospital located in the centre of Dublin, Ireland and provides various services to its patients, ranging from critical care, diagnostics, surgical areas and rehabilitation services. It's renowned for its neurology unit which stands at the forefront of stroke treatment and brain health. The hospital has about 5.000 staff members with a work email.

After a recent data leak caused by a phishing email, the hospital decided it was time to take action.

That's where I come in! As an Instructional Designer, I've been brought on board to train staff who handle emails, and guide them to successfully spot and report phishing emails before they become a threat.

Approach

These are the steps I would take if I was hired by the hospital as an Instructional Designer to solve the issue.