Channel players talk challenges of making C-level executives aware of phishing emails and capitalizing with value-added services
It’s no surprise that hackers are constantly looking for ways to access organizations’ information. We constantly hear that hackers purposely write poorly written emails in an effort to attract only ‘stupid’ people who won’t notice the glaring errors in the email.
What is surprising is when C-level executives become the target for these types of email. And what’s even more surprising is, despite the high stakes, it’s been reported that high-level executives are inept at identifying these scamming emails. And this is good news for the channel as it points to opportunities for partners to add services.
This is not without its challenges, however.
Last month, Intermedia and Intel Security released an eBook titled Harpooning Executives: How Phishing Evolved into the C-Suite, which included a survey finding that 100 percent of the time, 96 percent of executives failed to tell a phishing email from a real email.
According to Jonathan Levine, CTO at Intermedia, phishing, spear phishing and whaling call for companies to maintain a mentality seen in general cybersecurity: It’s not a matter of if you’ll be breached, but when. Therefore, resellers should focus on minimizing the damage, he says.
“It depends on the size of the partner and the customer, but I think it’s best for the helpers to try to help the customers reduce the attack surface of the possibility of breach,” Levine tells Channelnomics. “Think about the different avenues where breaching can come in and help the customers find adequate protection against those various different attack vectors”.
The assumption of a phishing breach is so large that Alex Markov, president of managed IT provider Red Key Solutions, tells Channelnomics that even non-healthcare organizations should use HIPAA compliance laws as guideline.
Convincing executives of the risk is not always easy, however.
Ed Correia, founder and CEO of MSP Sagacent Technologies, says C-suite ignorance creates “frustration”.
“Channel partners understand the risk. We’re very often pleading with these executives to meet with us so we can educate them a bit more about it, but it’s often the executives who want to make the least time to get educated,” he tells Channelnomics.
Correia points to phishing awareness trainings and luncheons that Sagacent offers to its managed clients that executives agree to attend but often end up being no-shows.
“I fear a lot of them don’t listen,” he says. “They keep believing it won’t happen to them”.
To get these company leads to listen, Markov recommends telling real stories of phishing emails reeling in money from “relatable” companies.
“We heard recently a general contractor somewhere in the middle country got into [a company’s] computers and managed to wire $400,000 out of their account,” Markov says. “That resonates much better with people…because when it’s Target or Home Depot, that doesn’t resonate as much with a lot of companies as more real stories”.
Sagacent meanwhile, has found monthly letters and newsletters fail because C-level executives are “barraged” with information, according to Correia. Instead, he finds simple one-page emails sent out once a month with two to three very short comments updating executives on the world of IT to be effective.
“They don’t have a lot of attention span, so if I can get something just to whet their appetite, I find some of them will reach out,” he says. “You have to create a special communication just for them”.
Markov agrees that the power is in the message. He says Red Key Solutions sends out email blasts when they hear of a large threat.
“A lot of it is about cascading messages and continual reinforcement,” he says. “People are very quick to forget that we’re living in different times nowadays with threats coming from every potential direction. So I’d say continuing to reinforce the message…is especially crucial in today’s world”.
Although it may be a challenge for channel partners to convince the C-suite of the size of the risk, phishing obliviousness provides opportunity in the form of value-added services via “direct contact”, Levine says.
“It’s not only a technology client, it’s also a training education client,” he explains. “The channel partners can provide a value-added service where they get an opportunity to get in front of the customer on a regular basis and try to help them think through how to change their internal processes to make themselves more secure against these attacks”.
Levine says executives may be “embarrassed”, but this is where resellers come in.
“It’s also important for channel partners to be thinking about how to advise their customers on implementing multi-layered security,” he says. “There are things that partners can help the customers think through that’s not a technology solution but definitely a value added they can provide.”
When it comes to actually advising on these threats, Correia says he gives executives limited access to the network, treating them like “regular” employees. This is especially useful when considering Harpooning Executives: How Phishing Evolved into the C-Suite‘s statistic of 95 percent of all attacks on enterprise networks being the result of successful spear phishing, he adds.
“They get access to what they need access to but nothing else,” Correia explains. “If you’re going to have individuals who are going to not be widely aware, than I think their access to things has to be locked down such as if their account or credentials were compromised, hackers aren’t going to be able to get into everything”.
Levine says cloud-based spam-checking providers and cloud-based services, such as that of McAfee, are worth noting because they bring the kind of technology that used to be limited to enterprises to small businesses.
“There are a lot of choices in the market for these services, so it’s important for the partners to be helping their customers select the best ones,” he says.
Cloud-based solutions are also good against phishing emails considering how rapidly hackers and their methods change, Levine adds.
Finally, he recommends resellers promote two-factor authentication processes.
“Another thing to think about is how to set up systems that protect against what happens if you have been breached,” Levine says.
“The second factor can be based on a physical token, text messages or applications that involve executives’ smartphones. Even if the whaling email manages to trick the executive into revealing his or her password, the password alone doesn’t get you into the banking or sensitive internal systems”.
Ultimately, it’s about making sure your C-level executive remains “skeptical” and “aware”, Correia says.
“Our big message to the world is be vigilant, use critical thinking and put procedures in place to avoid potential losses, because it’s happening. We see it multiple times affecting many clients, and it’s only been going up,” Markov adds.
