Is spear phishing a threat to your business security?

Mar 22, 2016

As the end of the financial year looms, many of us are looking at budgets and earmarking areas in our businesses that require spending in the next tax year. IT is one function that I know can cause some sleepless nights for CFOs looking to balance spending with positive ROI.

[see_also]

IT security is one area that doesn’t appear to offer any real return on investment. It’s just something you need to have in place to protect your business from cyberattack, prevent data breaches, and ensure business continuity.

IT security threats

While you can barricade your business against cyberthreats with firewalls, anti-virus, email filtering, anti-spam, encryption, UTM etc., there is one major threat to your business that is often overlooked by senior managers. In fact, sometimes they are guilty themselves of lowering cybersecurity defences as this threat comes from within: your staff.

I’m not talking about disgruntled employees deliberately attacking your systems or allowing access to those with criminal intent, nor am I thinking about absentminded staff leaving sensitive data in full view on a crowded train – although these are also security risks that must be addressed. Instead, I’m focusing on a sophisticated threat that can dupe even senior members of staff: ‘spear phishing’ or ‘whaling’.

Spear phishing has been associated with some of the worse cyberattacks in recent years: eBay, Target, TalkTalk, Sony, to name but a few. In a recent survey conducted by Vanson Bourne and sponsored by Cloudmark, eighty four per cent of respondents said that a spear phishing attack had penetrated their organisation’s security defences. Respondents also said that approximately twenty eight per cent of spear phishing attacks are getting through their security defences.

Before delving into what this kind of attack looks like, the good news is that it’s one area of IT security that you can address without spending large sums of money. Raising awareness, robust IT security policies, and staff training are your best line of defence when it comes to phishing scams, which will be reassuring if you were wondering how to stretch next year’s IT budget.

What is spear phishing?

Phishing is a technique where scammers send emails to individuals with attachments that contain malicious code, or a link to an infected site, request login details fraudulently or, as is becoming increasingly common, request bank transfers to fraudulent accounts. Most people are aware of this type of scam and are well versed in deleting suspicious looking emails both at home and at work. Often these will use poor grammar and come from unknown senders, who hope that a proportion of emails sent will land in the inboxes of a soft target.

However, they become harder to spot when the scammer has more information about the target. For example, some victims of the TalkTalk data breach were targeted in this way even before the data breach hit the news headlines, with emails and telephone calls from individuals who seemed to be legitimate employees of TalkTalk.

This more targeted approach is the difference between phishing and spear phishing, and when used in the business environment, scammers will single out individuals who fit certain criteria.

Instead of an email from an unknown sender, your employees could receive an email from someone purporting to work for your organisation. The email itself may look legitimate with company logos and contact information. Your employee may already have had correspondence with this individual, and feel that they’re a trusted source. Then once that trust has been established they hit the recipient with malware and your employee happily opens that attached document or clicks on the link…

It’s all about the social engineering

Spear phishing uses social engineering principals and is highly targeted. Instead of casting the net wide and hoping that they catch a few fish, the scammers go after a big fish who will deliver exactly what they want. Employees are first identified as likely channels and then nurtured over a period of time with several emails or messages.

Online forums provide an ideal place for scammers to identify targets. Here they can monitor support requests, find individual’s contact details, and then email them offering a solution to whatever problem they have. They may start the process in the actual forum, commenting on your employee’s request and suggesting solutions, all the time building trust. This leads on to email communications with the scammer and a spear phishing attack.

Defending your business from spear phishing

As stated before, protecting your business from spear phishing will not require your entire IT budget. Instead you can reduce the risk of phishing attacks by helping your employees protect your business.

This can be done in two ways:

1. Raising awareness of security risks through training and awareness campaigns
2. Providing the tools to detect these attacks

If spear phishing is a new phrase for you, then it’s likely that many of your employees won’t have heard of it either. It’s therefore important to educate them about these kinds of security risks and the consequences of a phishing attack of this type. As these attacks are constantly evolving and becoming more sophisticated, especially those using social engineering, it is worthwhile asking an IT security professional or your IT service provider to deliver this training.

With a more knowledgeable workforce it becomes easier for them to adhere to security guidelines and use techniques that protect your business systems. In brief these include:

Protecting passwords and logins

Employees should never send logins via email, should not click on URLs shared in emails (instead enter them manually or search for websites online), should look for inconsistencies in emails headers, suspicious email addresses and odd looking URLs, and should verify website and email addresses independently.

Protecting against malware

Employees should never open or download unsolicited attachments without first double-checking their authenticity, and employers should have clear procedures on how documents are shared within the organisation – for example by using a file sharing system.

Proper authorisation procedure

Ensure that any online banking systems have authorisation procedures in place to ensure a single person, not matter how senior, cannot make a bank transfer without a second person verifying.

[see_also]

Diverting some of next year’s IT security budget into staff training and awareness campaigns could be money well spent, protecting your business long term from phishing attacks.


Bruce Penson, MD at Pro Drive IT

Image Credit: Shutterstock/bluebay




Author: Bruce Penson
View the original article here.
Published under license from ITProPortal.com

https://lifeinsys.com/user/david01
https://app.roll20.net/users/14015474/david-s
https://www.quia.com/profiles/dasmith469
https://www.divephotoguide.com/user/david01
https://photoclub.canadiangeographic.ca/profile/21326904
https://starity.hu/profil/471349-david01/
https://www.facer.io/user/fcuA6R3PWA
https://swaay.com/u/dubaimetro01/about/
https://bootstrapbay.com/user/David02
https://www.trovagas.com/author/david02/
https://mycableengineering.com/activity-feed/userId/11883
https://slideslive.com/david02?tab=about
https://outof.games/members/david02/
https://mentorship.healthyseminars.com/members/david02/
https://onlinevetjobs.com/author/david02/
http://jobboard.piasd.org/author/david02/
https://rnstaffers.com/author/david02/
https://www.bitsdujour.com/profiles/ZKxOus
https://hanson.net/users/david02
http://fid101.ldd.go.th/Activity-Feed/My-Profile/UserId/430
https://cyprus.com/author/david02/
https://ca-riverside-acr.publicaccessnow.com/ActivityFeed/MyProfile/tabid/24/UserId/21065/Default.aspx
https://www.openrec.tv/user/david02/about
http://www.in-almelo.com/User-Profile/userId/2408692
https://www.metaculus.com/accounts/profile/198168/
https://homment.com/fujScGVD3slgtJSo2Hmt
https://www.dnnsoftware.com/activity-feed/my-profile/userid/3207527
https://www.showmethesite.us/lazychicken/ActivityFeed/MyProfile/tabid/2622/UserId/552473/Default.aspx
https://buyandsellhair.com/author/davidmerchant02/
http://aldenfamilydentistry.com/UserProfile/tabid/57/userId/864985/Default.aspx
https://postgresconf.org/users/david-merchant
http://www.worldchampmambo.com/UserProfile/tabid/42/userId/391127/Default.aspx
https://www.pearltrees.com/davidmerchant02
https://useum.org/myuseum/David%2015
https://employbahamians.com/author/david02/
https://www.lotusforsale.com/author/david02/
https://guidetoiceland.is/traveler-profiles/dubaimetro01
https://medibang.com/author/26628380/
https://www.provenexpert.com/david02/
https://independent.academia.edu/DavidMerchant8
https://www.mixcloud.com/davidmerchant02/
https://public.tableau.com/app/profile/david.smith4458/vizzes
https://fitinline.com/profile/david02/
https://www.guiafacillagos.com.br/author/david02/
https://aboutcasemanagerjobs.com/author/david02/
https://www.reddit.com/user/According-Pipe-4349/
https://hfonline.org/members/david02/
https://edgeforscholars.org/author/David02/
https://boersen.oeh-salzburg.at/author/david02/
https://www.allmyusjobs.com/author/david02/
https://medium.com/@dubaimetro01/about
https://conifer.rhizome.org/david02
https://maltajobs.com.mt/author/david02/
https://solo.to/david02
https://olderworkers.com.au/author/dubaimetro01proton-me/
https://www.nieveaventura.com/author/david02/
https://fast-mag.com/author/david02/
https://therealblackfriday.com/author/david02/
https://my.djtechtools.com/users/1428921
https://allmynursejobs.com/author/david02/
https://producerbox.com/users/david02
https://willysforsale.com/author/david02/
https://maactioncinema.com/archives/author/david02
https://aboutnursinghomejobs.com/author/davidsmith02/
https://aboutdirectorofnursingjobs.com/author/davidsmith02/
https://divisionmidway.org/jobs/author/davidsmith02/
https://rndirectors.com/author/davidsmith02/
https://aboutnursernjobs.com/author/davidsmith02/
https://www.diversityofficermagazine.com/diversityjobs/author/davidsmith02/
https://worldranksite.com/author/david02-20618/
https://topbilliondirectory.com/author/david02-19255/
https://microlinksite.com/author/david02-18397/
https://schoolido.lu/user/David02/
https://crypto-potential.com/user/david-smith2
https://www.phraseum.com/user/39572
https://blog.rackons.in/profile/david02
https://blatini.com/profile/David02
http://www.fanart-central.net/user/David02/profile
https://www.zerohedge.com/user/UugyBpExMQaJ1PEunfLJLgRCuDh2
https://www.thebostoncalendar.com/user/84389
https://www.lingvolive.com/en-us/profile/5affccd8-53c7-481c-8163-1e6a751ee318/translations
https://www.pressregister.com/user/public-profile/62355
https://orangelifemagazine.com/author/david02/
https://www.adproceed.com/author/david02/
https://read-blogs.com/author/david02/
https://www.ziparticle.com/author/david02/
https://www.outlived.co.uk/author/david02/
https://classifieds.villages-news.com/author/david02
https://wayranks.com/author/david02-718065/
https://www.mangalorean.com/author/david02/
https://www.tumblr.com/davidsmith-02/758144649588293632/david
https://confengine.com/user/david-smith-3-1
https://handyclassified.com/profile/david02
https://etwinningonline.eba.gov.tr/author/david02/
https://www.vtforeignpolicy.com/author/david02/
https://shareresearch.us/profile/David02
https://www.rafabasa.com/author/david02/
https://www.flowcode.com/page/david02
https://linkpop.com/david02-slug-david02
https://fashonation.com/members/david02/profile/
https://hpad.dataone.org/s/NEZhn8JFX
https://trabajo.merca20.com/author/davidsmith02/
http://amabilis.com/?bbp_user=44909
https://start.me/u/19K1Qj/david
https://arzookanak112.xobor.de/u81_david.html
https://www.sonicbids.com/band/david02/
https://log.concept2.com/profile/2388919
https://activepages.com.au/profile/david02
https://www.popdaily.com.tw/user/459272
https://petites-annonces.commeuncamion.com/author/davidsmith02/
https://linkingdirectory.com/author/david02-17831/
https://blognow.co.in/profile/david02
https://glamorouslengths.com/author/david02/
https://www.sabahjobs.com/author/david02/
https://mercadodinamico.com.br/author/david02/
https://www.sitiosecuador.com/author/davidsmith02/
https://rnmanagers.com/author/david02/
https://progresspond.com/members/david02/
https://toparticlesdirectory.com/author/david02/
https://topacted.com/author/david02-15327/
https://my.archdaily.com/us/@david-smith-38
https://gwar.net/a/bohabs/users/163621
https://www.evtv.me/author/david02/
https://hinative.com/profiles/8234548
https://www.bigoven.com/user/davidsmith02
https://jobs.motionographer.com/employers/3225567-david
https://suzuri.jp/David02
https://maxternmedia.com/author/david02/
https://my.desktopnexus.com/davidsmith02/
https://www.kniterate.com/community/users/david02/
https://cars.yclas.com/user/david-smith-6
https://www.workathomejobsboard.com/employers/3225596-david
https://www.herlypc.es/community/profile/david02/
https://www.deviantart.com/davidsmith02/about
https://jobs.siliconflorist.com/employers/3225646-david-smith
https://eternagame.org/players/394815
https://soundcloud.com/dubaimetro01
https://list.ly/David02/lists
https://slides.com/davidsmith02
https://www.komoot.com/user/4337847745084
https://myanimelist.net/profile/davidsmith02
https://www.mountainproject.com/user/201889914/david-smith
https://www.stem.org.uk/user/1369736
https://www.anobii.com/en/011cdc68c654c023a8/profile/activity
https://foro.kechollazo.com/members/david02.14643/#about
https://yellowfever.co.nz/users/davidsmith02
https://jobs.tdwi.org/employers/3225740-david-smith
https://profile.hatena.ne.jp/davidsmith02/profile
https://bandori.party/user/209596/david02/
https://jobs.employabilitydallas.org/employers/3225755-david-smith
https://jobs.nefeshinternational.org/employers/3225758-david-smith
https://akniga.org/profile/david02/
https://desksnear.me/users/david-smith-ae9110
https://app.impactplus.com/users/david-smith-fe6a3ba6-8c79-4208-a383-7e2d9b0e950a
https://losangeles.bubblelife.com/users/dubaimetro01_b60719
https://www.diigo.com/item/note/b5rx6/8irk?k=92c94fd58c81a79c32216d80ef8b9154
https://www.rafabasa.com/author/diana01/
https://fashonation.com/members/diana01/profile/
http://amabilis.com/?bbp_user=45540
https://trabajo.merca20.com/author/diana01/
https://hpad.dataone.org/s/3i4B21VcZ
https://www.sonicbids.com/band/diana01/
https://participedia.net/user/428445
https://mikropragmata.lifo.gr/meli/23267/
https://petites-annonces.commeuncamion.com/author/diana01/
https://linkingdirectory.com/author/diana01-25276/
https://www.quora.com/profile/Diana-Walker-262
https://www.kniterate.com/community/users/diana01/
https://gravesales.com/author/diana01/
https://www.inspireglobalsolutions.com/profile/Diana8
https://www.letsknowit.com/diana25241
https://glamorouslengths.com/author/Diana01/
https://www.sitiosecuador.com/author/diana01/
https://www.beatstars.com/realdoctorsnotes/about
https://rnmanagers.com/author/diana01/
https://progresspond.com/members/diana01/
https://certified.heartmath.com/user/diana-walker/
https://profile.pmc.org/DW0282
https://bumpy-hope-641.notion.site/Diana-a518233dc6b04ab3a369f97336d420c4?pvs=25
https://www.stampstampede.org/society-stampers/members/DI01/
https://blogzone.hellobox.co/6976396/diana
https://econarticle.com/profile/Diana01
https://www.makerist.de/users/realdoctorsnotes
https://businessleed.com/author/Diana01/
https://next.nexusmods.com/profile/Dianawalker01/about-me
https://generalmagazine.org/author/diana01/
https://theduran.com/author/diana01/
https://dictanote.co/n/1065634/
https://www.fbtb.net/author/diana01/
https://www.polywork.com/diana_walker
https://utahsyardsale.com/author/diana01/
https://www.slmath.org/people/72373
https://speakerdeck.com/dianawalker01
https://www.niftygateway.com/@dianawalker1511/
https://pantip.com/profile/8384071#topics
Geeta
19/09/2024 11:43

Comment

 

Understanding the risks and rewards of public sector cloud 

Download the Whitepaper now

Partner

24Newswire
Sign up to receive latest news