December 07, 2012
—
CSO
—
Most of us have clicked on an email that seemed legitimate, but wasn’t. I am embarrassed to say it, but I recently clicked on a malicious link myself, and I should know better considering that I preach to people every day about the importance of protecting your organization against such tactic. But, the phishing email caught me at the wrong time when I was half paying attention to what I was doing, and it enticed me with right authentic looking message.
When we first started trying to educate employees about email security, I sent a sampling of 140 employees a fake phishing email. The results were jaw dropping; Seventy-two percent opened the email. Of those, 85 percent clicked on the “malicious” link. But the most concerning to me was that 65 percent gave their username and password —and that number would have been higher if word didnt get around about the fake email in social circles.
[Phishing: The basics]
Each employee, who clicked on the malicious link were then trained as we explained the dangers of malicious emails and how to catch them in the future.
Ive spoken with hundreds of CIOs and CISOs worldwide, and many of them have impressive programs. In those discussions I also got to hear how the top organizations are protecting themselves from the risk of spear phishing to a very high degree of effectiveness. Below are the top 11 tips I’ve heard for best technology practices, employee education and social media smarts.
3 ways to stop 95-99 percent of spear-phishing attempts:
1. Inbound email sandboxing:
Deploy a solution that checks the safety of an emailed link when a user clicks on it. This protects against a new phishing tactic that I’ve seen from cybercriminals. Bad guys send a brand new URL in an email to their targets to get through the organization’s email security. The other tactic is when they inject malicious code into the website right after delivery of the email URL. This URL will get past any standard spam solution.
2. Real-time analysis and inspection of your web traffic:
First, stop malicious URLs from even getting to your users’ corporate inboxes at your gateway. Even if you have inbound email sandboxing for your corporate email, some users might click on a malicious link through a personal email account, like Gmail. In that case, your corporate email spear-phishing protection is unable to see the traffic. Bottom line: your web security gateway needs to be intelligent, analyze content in real time, and be 98 percent effective at stopping malware.
