Email is something we use every day for productivity. We use it to connect with our colleagues internally, our suppliers and customers externally, and we rely on it for 95% of all our communications.
But our most-used tool in our day-to-day work has become the biggest attack surface, with Sophos reporting that 93% of all attacks originate from email. With email being the biggest attack surface, we need to protect it at all costs, but users are still our weakest link. Ninety-nine percent of people in your organization receive emails daily. Who is skilled enough to spot a phishing email?
With the rise of AI, phishing emails aren’t as obvious to spot anymore. They have become more sophisticated than a simple misspelled word or a typo in the body of the email. Most phishing emails look legitimate, raising the stakes. Where most users fail the test is when there are suspicious links, documents, or instructions in the email. The email looks legitimate, the domain might look similar, and the request seems like it is coming from the finance department or procurement. Why should we question it? Some of these phishing emails can get past even the more cyber-aware individuals.
In a recent case, the finance department of a high-profile company received an email with an instruction to pay a new supplier $2 million. Being quite cyber-aware, the finance employee questioned the sender and the email. She demanded a Teams call to confirm the identity of the sender. Shortly after, they were on a Teams call, but the sender refused to turn on their camera, claiming they had a bad signal. The voice was put through software and matched the person who “sent” the email. The finance employee still had a gut feeling and questioned it further. The voice on the other end assured her that everything was above board. After the call, she logged a ticket with her IT department to investigate. The investigation led to an email compromise from another employee in the company. If the finance employee had not been cyber-aware, the company would have lost $2 million. This is an enormous amount for any company. Most insurers do not cover this kind of loss either.
Many customers we deal with daily who experience these kinds of threats always have the same question: where did it come from? They often argue that they have policies in place, etc., but what many customers don’t realize is that there are third-party leaks into the dark web. It’s not always your fault. Your supplier might have been breached, and the adversaries might have gotten hold of their address book. Someone in your organization might have been part of that address book. Address books are usually sold on the dark web to the highest bidder. Cybercrime organizations use these to put together their “prospect lists”. Yes, they have a sales department, HR department, directors, and executives, just like we do. Once you are part of their “prospect list”, it’s time to review your cybersecurity measures and controls.
When it comes to email security, we need to stop the threat before it reaches the user’s inbox. Email security comes in all shapes and sizes, but we need to understand the protection we have. I like using the comparison of our home security. We can padlock the door, but if the padlock is cheap and flimsy, are we really protected? The second thing we need to look at when choosing a vendor for our email security is whether they offer user awareness training. Lastly, do we have a DMARC product in place to protect senders?
But how do we choose the best vendor? Where do we start looking? We need to look for a product that has multi-layered protection, preventing phishing emails from getting to the user’s inbox in the first place. We need to equip users with the skills to spot phishing emails. Then, we need to look at your existing infrastructure and how we can use what you already must strengthen security.
If you are in doubt, reach out to the Streamline team for a free Threat Profile Assessment.