Site icon bbrief

Is lack of email security hanging businesses out to dry?


Riaan Badenhorst | General Manager | Kaspersky Lab | mail me


Mimecast’s latest Email Security Risk Assessment (ESRA) report has found a 269% increase in Business Email Compromise (BEC) attacks. Furthermore, the FBI recently indicated that worldwide losses from such attacks amounted to approximately $26 billion over the last three years.

Email attacks compromise business or personal email accounts through social engineering or computer intrusion and, through this, the aim is either to facilitate a transfer of funds or to derive confidential data from the business entity.

Sensitive information getting into the wrong hands

It is a business risk that, in today’s age, one can’t afford. Imagine sensitive client information, business strategy and confidential employee data getting into the wrong hands. It is a reputational disaster that will certainly break relational trust with a business.

It’s stats like the ones above that are a stark reminder to businesses that while email is not the newest form of communication, it is certainly one that is easily attacked by cybercriminals – given its ability to slip through traditional security systems and the fact that human error plays a central role to the success of email based attacks.

What’s more, spam and phishing can often seem like an outdated type of threat, while in fact social engineering schemes keep becoming more and more elaborated. For instance, past year highlights included a case where fraudsters targeted corporate Microsoft accounts with fake e-mail notifications of voicemails in online-messengers.

However, even less sophisticated schemes have chances for successful attacks, as missing an important message is a constant fear for employees of large companies as it can affect vital business processes.

Driving IT security education within the organisation

As the year progresses, we are likely to see continued growth in email-based attacks and spam, resulting from more sophisticated fraudsters and a growing number of cybercrime syndicate networks across the globe.

Considering this, it is critical that businesses are focused on not only identifying areas of weakness within their IT infrastructure, but that they also drive IT security education within the organisation around email business compromise, including training on the basic of security hygiene for employees of all ranks.

The reality is that it is quite easy to forget about email as a security risk, as employees routinely use them their day-to-day work, yet this is one area that simply can’t be ignored, as for many businesses, it is often the entry point of compromise.

It must also be noted that this rings true for businesses with cloud-based email too! With many businesses moving their email to the cloud with the aim of centralising security and feeding their data through strong algorithms to reduce and remove the risk around mass mail, spam and malware, the perception is that the business is safe but, it is certainly not.

Filling the gap

While cloud does offer a much stronger solution to avoiding such attacks, it is not failproof and therefore, a sound security solution is required to ‘fill the gap’.

We encourage businesses to review their email security measures, identify potential gaps and weak areas and take the necessary steps to avoid falling victim to the growing threat of BEC.

Some valuable tips to consider include:

In conclusion

Businesses and individuals are very focused around protecting themselves and their data online when it comes to social media and other digital platforms, that very often email is forgotten.

However, it is critical that email security becomes a central focus for each business and that it is taken seriously, as a leading security risk, otherwise the business could be left hung out to dry.


 

Exit mobile version