Riaan Badenhorst | General Manager | Kaspersky Lab | mail me |
Mimecast’s latest Email Security Risk Assessment (ESRA) report has found a 269% increase in Business Email Compromise (BEC) attacks. Furthermore, the FBI recently indicated that worldwide losses from such attacks amounted to approximately $26 billion over the last three years.
Email attacks compromise business or personal email accounts through social engineering or computer intrusion and, through this, the aim is either to facilitate a transfer of funds or to derive confidential data from the business entity.
Sensitive information getting into the wrong hands
It is a business risk that, in today’s age, one can’t afford. Imagine sensitive client information, business strategy and confidential employee data getting into the wrong hands. It is a reputational disaster that will certainly break relational trust with a business.
It’s stats like the ones above that are a stark reminder to businesses that while email is not the newest form of communication, it is certainly one that is easily attacked by cybercriminals – given its ability to slip through traditional security systems and the fact that human error plays a central role to the success of email based attacks.
What’s more, spam and phishing can often seem like an outdated type of threat, while in fact social engineering schemes keep becoming more and more elaborated. For instance, past year highlights included a case where fraudsters targeted corporate Microsoft accounts with fake e-mail notifications of voicemails in online-messengers.
However, even less sophisticated schemes have chances for successful attacks, as missing an important message is a constant fear for employees of large companies as it can affect vital business processes.
Driving IT security education within the organisation
As the year progresses, we are likely to see continued growth in email-based attacks and spam, resulting from more sophisticated fraudsters and a growing number of cybercrime syndicate networks across the globe.
Considering this, it is critical that businesses are focused on not only identifying areas of weakness within their IT infrastructure, but that they also drive IT security education within the organisation around email business compromise, including training on the basic of security hygiene for employees of all ranks.
The reality is that it is quite easy to forget about email as a security risk, as employees routinely use them their day-to-day work, yet this is one area that simply can’t be ignored, as for many businesses, it is often the entry point of compromise.
It must also be noted that this rings true for businesses with cloud-based email too! With many businesses moving their email to the cloud with the aim of centralising security and feeding their data through strong algorithms to reduce and remove the risk around mass mail, spam and malware, the perception is that the business is safe but, it is certainly not.
Filling the gap
While cloud does offer a much stronger solution to avoiding such attacks, it is not failproof and therefore, a sound security solution is required to ‘fill the gap’.
We encourage businesses to review their email security measures, identify potential gaps and weak areas and take the necessary steps to avoid falling victim to the growing threat of BEC.
Some valuable tips to consider include:
- Cyber security: Protect corporate mail accounts with phishing protection at the mail server level – this is a critical starting point. Use a reliable security solution with behavior-based anti-phishing technologies. Kaspersky Total Security for Business is one of such solutions. It provides security for mail servers by filtering out incoming streams of spam and blocking malicious emails of all types.
- Education: Train employees around the key aspects to remaining cyber-secure. Introduce security awareness initiatives, including gamified training with repetition of simulated phishing attacks. Educate your employees to always check the address of a link in emails or messages that have come from an unfamiliar sender. In addition, advice checking the sender’s email address before clicking anything or opening links or attachments. Show employees how to recognise fake or insecure websites and to never enter their credentials before checking a website’s credibility.
- Reminders: Issue regular communication to staff to remind them of new email scams identified, as well as how to detect if an email is spam, if an email account has been hacked or sharing insights into the latest tactics being used by cybercriminals.
- Funds transfer policy: Ensure there is a clear funds transfer policy where no payments can be made to a third party account without the authorisation of a number of managers.
In conclusion
Businesses and individuals are very focused around protecting themselves and their data online when it comes to social media and other digital platforms, that very often email is forgotten.
However, it is critical that email security becomes a central focus for each business and that it is taken seriously, as a leading security risk, otherwise the business could be left hung out to dry.




























