Story image

Beware the blind spot in phishing education

31 Jan 2017

A common blind spot in training corporate staff to identify and avoid cyber attacks is the targeted phishing attack.

Trained employees might diligently ignore links in the standard phishing emails we all receive daily, but what about targeted attacks by spies?

Spies will carefully research the individual, exploit what they can learn about him or her on social media, or about past or current business practices on sites like LinkedIn. The spy will then craft a ‘spearphishing’ email that seeks to recruit the employee without his/her knowledge.

The email may look like it comes from a best friend, talking about the running group they belong to and asking the targeted victim to log into a run tracker site. If the employee trusts the friend would send something like this, and does not understand that email addresses can be spoofed, or how to check, the spy will win.

Poor training can create overconfidence. Apathy toward cyber attacks can also contribute. Many of us won’t believe that we can be compromised until our entire accounts are published online. But does phishing awareness training always work, or can it create over-confident employees?

Phishing awareness training (and proper email hygiene techniques in general) are only as good as the instruction provided. A necessary component of that instruction often overlooked by trainers is the use of real-life phishing examples that caused significant breaches. However, there is an apathy over cyber security and the threat that cyber espionage and terrorism presents.

After the Sony Pictures Entertainment attack that destroyed systems and stole large quantities of personal and commercial data, every executive was placed on notice that a cyber spy could feasibly compromise an email account and not only use credentials to access an employer’s systems, but also place the entire contents of that email online for journalists to pick over.

The initial shock wore off and it wasn’t until John Podesta’s Gmail account was compromised through a simple phishing attack (not even a targeted, spearphishing attack) that the national consciousness was reminded of the importance of good email security practices.

Training also focuses on phishing attacks – those attacks that are broad spectrum and cast a wide net. These are your common email service provider, PayPal, eBay, bank, etc. “reset your password” emails (and others) that use normal business practices to trick an individual into linking to a spoofed website that either steals credentials or loads malware.

Yet the issue of over-confidence is a common one. The culture of how we use and abuse email needs to change. Email has become an impersonal means of communication, overladen with advertisements and suffering from an information deluge, which studies have shown increases stress instead of encouraging efficiency.

The common business person has multiple accounts for multiple email engagements – social, office, entrepreneurship, community, etc. Often, accounts are linked to a large number of places and share a common password. At some point, monitoring these accounts and carefully screening email and social media becomes a tedious chore. Spies are most successful when the target is mired in monotony and complacency.

Article by Eric O’Neill, national security strategist, Carbon Black.

Why SD-WAN is key for expanding businesses - SonicWall
One cost every organisation cannot compromise on is reliable and quick internet connection.
New threat rears its head in new malware report
Check Point’s researchers view Speakup as a significant threat, as it can be used to download and spread any malware.
Oracle updates enterprise blockchain platform
Oracle’s enterprise blockchain has been updated to include more capabilities to enhance development, integration, and deployment of customers’ new blockchain applications.
Used device market held back by lack of data security regulations
Mobile device users are sceptical about trading in their old device because they are concerned that data on those devices may be accessed or compromised after they hand it over.
Gartner names ExtraHop leader in network performance monitoring
ExtraHop provides enterprise cyber analytics that deliver security and performance from the inside out.
Symantec acquires zero trust innovator Luminate Security
Luminate’s Secure Access Cloud is supposedly natively constructed for a cloud-oriented, perimeter-less world.
Palo Alto releases new, feature-rich firewall
Palo Alto is calling it the ‘fastest-ever next-generation firewall’ with integrated cloud-based DNS Security service to stop attacks.
The right to be forgotten online could soon be forgotten
Despite bolstering free speech and access to information, the internet can be a double-edged sword, because that access to information goes both ways.