{"id":30810,"date":"2019-12-10T14:18:01","date_gmt":"2019-12-10T14:18:01","guid":{"rendered":"https:\/\/www.intelligentcio.com\/africa\/?p=30810"},"modified":"2019-12-13T11:06:43","modified_gmt":"2019-12-13T11:06:43","slug":"what-can-organisations-do-to-prevent-the-rise-of-phishing-attacks","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/africa\/2019\/12\/10\/what-can-organisations-do-to-prevent-the-rise-of-phishing-attacks\/","title":{"rendered":"What can organisations do to prevent the rise of phishing attacks?"},"content":{"rendered":"\n<p>We asked a number of industry experts what advice they have for organisations in the battle to prevent the rise of phishing attacks. Here is what they had to say. <\/p>\n\n\n\n<p><strong><em>Jurgen Sorton, Senior Product Manager for Security at Vox<\/em><\/strong>&nbsp;&nbsp;<\/p>\n\n\n\n<p>Phishing attacks are on the rise and show no signs of slowing down. According to the latest <em>Mimecast State of Email Security 2019<\/em> report, we have witnessed an increase in phishing attacks globally, with 94% of organisations having experienced attacks in the last 12 months.&nbsp;<\/p>\n\n\n\n<p>There are various forms of\nphishing attacks but essentially all attacks attempt to gain sensitive,\nconfidential information such as usernames, passwords, credit card information,\nnetwork credentials and more, by posing as a legitimate individual or\ninstitution.<\/p>\n\n\n\n<p>These attacks are becoming\nmore sophisticated in order to get around security solutions that are being put\nin place across most organisations. The most common form of phishing is not\ntypically targeting specific individuals, but rather popular sites such as\nPayPal, which are cloned. Emails are then sent to many individuals instructing\nthem to click on the malicious link to resolve account discrepancies in the\nhope of obtaining their credentials.<\/p>\n\n\n\n<p>With spear phishing, the\nfraudsters apply a more targeted approach to their craft. While this requires a\nlittle more effort as fraudsters need to acquire information about the targeted\nindividuals, their task is made easier by using social media websites, such as\nLinkedIn, which has a wealth of information about the targeted individual.\nWhaling is a form of spear fishing where executives such as CEOs are targeted.\nGaining access to a CEO\u2019s email account allows criminals to target individuals\nin the organisation\u2019s accounts department instructing them to release payments\nto the criminal\u2019s account.&nbsp;<\/p>\n\n\n\n<p>Criminals are not only using\nemail as an attack for phishing. Vishing is a form of phishing where criminals\nuse the telephone to obtain personal information through social\nengineering.&nbsp;<\/p>\n\n\n\n<p>So what can organisations do\nto prevent these attacks? A holistic approach is required, one that includes\nsecurity specific solutions, awareness training as well as changes to internal\naccounting controls. The first step is to implement security solutions that\nprotect the company\u2019s email environment. Managed service providers, such as\nVox, offer a range of best of breed security solutions which are specifically\ndesigned to mitigate the risk of phishing attacks.&nbsp;<\/p>\n\n\n\n<p>While these solutions will\nsignificantly reduce the risk of such attacks, it is important to remember that\nimplementing a security solution is not enough. Security solution providers are\nconstantly innovating new features to meet the increasing sophistication of\nthese attacks. This means that the solution requires constant management by\ncertified security specialists who understand the relationship between product\nand skills and offer fully managed security services to ensure that the\nbusiness remains protected.&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>In addition to the security solution and managed services, organisations need to institute security awareness training for their staff. This educates employees to the dangers of phishing or other online scams. In the case of Vishing, security awareness training provides the only line of defence. Lastly, companies need to improve internal controls to mitigate the risk of whaling attacks as previously mentioned. In the event of a successful whaling attack, improved internal accounting controls ensure that payments are not made to the criminal\u2019s account.<\/p>\n\n\n\n<p><strong>MJ Strydom, Managing Director, DRS <\/strong><\/p>\n\n\n\n<p>In spite of the fact that phishing is one of the oldest tricks in the cyberthreat book &#8211; mitigating the risk of phishing breaches is still today, easier said than done.<\/p>\n\n\n\n<p>Phishing is still the front-line attack method by cybercriminals wanting to infiltrate businesses. Staff awareness programmes can certainly assist to some degree but they only lessen risk slightly \u2013 a layered approach is required if you want to achieve greater success against this scourge.<\/p>\n\n\n\n<p>Hackers are increasingly sophisticated and knowledgeable;\nand are deploying new techniques aimed at bypassing email security filters.\nEven the most security conscious staff members can fall foul of a cleverly\nconstructed phishing attack.<\/p>\n\n\n\n<p>Phishing attack prevention is still a work in progress for cybersecurity specialists. Technical professionals must understand the end user\u2019s role in phishing detection and the human role of the incident responders during phishing response. Emerging technologies support users and incident responders with phishing detection and response.<\/p>\n\n\n\n<p>A well-crafted phishing email is virtually identical to\nan authentic email, with unsuspecting victims sitting just a click away from\nletting an intruder into their employer\u2019s systems or onto their own devices.\nThe results are the same \u2013 in the case of the individual \u2013 usually the loss of\nidentity credentials through downloads of malware or ransomware.&nbsp; In the\ncase of businesses, loss of reputation; customers and long-term damage to the\nenterprise. <\/p>\n\n\n\n<p>Training alone can\u2019t protect from phishing. According to Forrester, one of the most influential research companies in the world \u2013 phishing prevention requires a multifaceted approach that combines technical controls augmented by user education. Each layer in this strategy acts as a safety net in case the layer on top of it fails. <\/p>\n\n\n\n<p>Companies need to kick off with the implementation of\ntechnical controls aimed at protecting end users. Email security solutions must\nbe deployed and should include: content filers; authentication and threat level\nintelligence tools that are designed to reduce the likelihood of malicious\nemails ending up in your employees\u2019 inboxes. <\/p>\n\n\n\n<p>That is not to say that continuous staff education is not\nrequired. Quite the opposite \u2013 staff need to learn how to recognise phishing\nattempts. This can be considered the last line of defence as malicious mails\nwill already have broken through the technical controls. Mechanisms need to be\nput in place that assist staff to report and test for phishing attempts. Staff\nperformance in this regard also needs to be measured. Be wary of naming and\nshaming users who become attack victims.&nbsp; Public admonishment of staff may\nmake them less likely to report phishing attempts.&nbsp; <\/p>\n\n\n\n<p>One thing is certain \u2013 despite your best efforts your staff will be successfully phished. Planning for that event and factoring in both technical and human failure\/error are essential parts of a well thought out anti-phishing strategy. It is essential to have an incident response plan in place as well as the deployment of technologies such as browser isolation and multifactor authentication, in order to limit the impact of an attack. All of these measures will combine to assist with the speed and quality of recovery from these attacks.<\/p>\n\n\n\n<p><em><strong>Zaheer Ibrahim, Cybersecurity Practice Lead for Sub-Saharan Africa at Trend Micro Sub Saharan Africa<\/strong> <\/em><\/p>\n\n\n\n<p>Phishing is essentially a form of an attack that tricks users into thinking that the email is from a legitimate source. Thereafter, once the user is &#8216;phished&#8217; they will then proceed to provide critical, personal information such as their credit card details, account numbers, identification details etc. to what they believed to be a trusted source. <\/p>\n\n\n\n<p>However, when captured by the hackers, the data allows access to the recipient&#8217;s\nbanking information, which can be potentially very dangerous with detrimental\neffects. If the phisher is planning to coordinate another attack, they evaluate\nthe successes and failures of the completed scam and begin the entire cycle\nagain.<\/p>\n\n\n\n<p>There are several\nphishing scams out there, namely: <\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Vishing &#8211; Phishing done over a voice call<\/li><li>Smishing &#8211; Phishing done through an SMS<\/li><li>Spear Phishing &#8211; This type is essentially the same as traditional phishing, with the only difference being that this method is targeted at a specific user in an organisation<\/li><li>Whaling &#8211; Almost identical to spear phishing, this type is targeted at a particular target audience, such as C-level executives<\/li><\/ul>\n\n\n\n<p>As per the Trend Micro mid-year report, we have seen a decline in phishing activities on the whole from the first half of 2018 to 2019. Despite there being an evident decrease, the statistics uncovered are still astronomical, with their impact being detrimental and far-reaching in any organisation they penetrate. With the decline of phishing, we have seen a huge effort made to increase business\u2019 email compromise attacks which could include CEO and board member fraud.<\/p>\n\n\n\n<p>Offerings such as the Worry-Free Services we offer, powered by XGen Security, uses Machine Learning with other detection techniques for the broadest protection against ransomware and advanced attacks. It protects devices on or off the network and optimises performance by applying the right protection technique at the right time.<\/p>\n\n\n\n<p>What\u2019s more, our Hosted Email Security protects against Business Email Compromise (BEC) with enhanced Machine Learning, combined with expert rules, analyses the header as well as the content of an email to protect the user. This ultimately ensures the authenticity and reputation of the email sender, as well as making it possible to screen out malicious senders.<\/p>\n\n\n\n<p>Now that we have\nunderstood the various methods of phishing attacks and what they are exactly,\nas well as their impact on companies, let us look at how best these can be\navoided:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>As these attacks are targeted at the end user, the most important safety technique is education and an awareness of what the best response would be <\/li><li>Think before you click any unknown, undetected source or item to open<\/li><li>Ensure that your software on your PC is up-to-date<\/li><li>Never give out your personal information unless it is to a verified source<\/li><li>Emails received should continually be examined for grammatical errors and spelling mistakes<\/li><li>One should give the email sender\u2019s display name a closer look to inspect the email\u2019s legitimacy<\/li><li>Be cautious of emails from individuals or organisations that ask for personal information from the onset<\/li><li>Emails that call on a sense of urgency or have an alarmist tone should not be hastily acted upon, with this being a decoy to trick people<\/li><li>An embedded URL may seem perfectly valid, but hovering above it may show a different website address that gives the attackers away<\/li><\/ul>\n\n\n\n<p><strong>How can Trend Micro\nassist in this fight against phishing?<\/strong><\/p>\n\n\n\n<p>For effective source\nverification and authentication, we use Sender Policy Framework (SPF),\nDomainKeys Identified Mail (DKIM), and Domain-Based Message Authentication,\nReporting and Conformance (DMARC).<\/p>\n\n\n\n<p>The Trend Micro Cloud App Security solution enhances the security of Microsoft Office 365 and other cloud services by taking advantage of sandbox malware analysis for ransomware, BEC, and other advanced threats. It also protects cloud file sharing from threats and data loss by controlling sensitive data usage and protecting file sharing from malware. In short, we cover you from the endpoint to the cloud. <\/p>\n\n\n\n<p><strong><em>Selina Bieber, Regional Director for Turkey and MENA at GoDaddy EMEA<\/em><\/strong><\/p>\n\n\n\n<p>The impacts of phishing emails are a pervasive security\nrisk you face as a small business owner or a solo entrepreneur. Phishing scams\nare attempts by hackers to get users to hand over sensitive information, like\npasswords and credit card information. &nbsp;It often involves sending spam email that looks like it&#8217;s\ncoming from a trusted source, like a bank (this is the bait), that then links\nto a fraudulent website impersonating the trusted source (this is the trap).\nThe unsuspecting target then enters the information the attacker is looking\nfor, thinking it is actually on a site they trust.<\/p>\n\n\n\n<p>It usually works with you being enticed to click a link in an email to update information, which then takes you to a fraudulent phishing trap site instead that looks like your bank\u2019s portal, or to a social media site, PayPal or even a SARS eFiling website. You\u2019ll be asked to punch in your user name and password, which will then be captured by the scammer, who then uses it to compromise the account, ransack a bank account, or even sell it to other hackers to cause further damage. &nbsp;<\/p>\n\n\n\n<p>According to the 2019 Security Threats and Trends Survey by KnowBe4, 96% of organisations believe that email phishing is the biggest security risk facing their business over the next year. <\/p>\n\n\n\n<p>Here are a few good practices to help beat the\nscammers: <\/p>\n\n\n\n<p><strong>Recognise the tell-tale signs<\/strong><\/p>\n\n\n\n<p>Some phishing emails are obvious because they are\nbadly written and formatted that no real bank, as an example, would send them\nout. Others are more carefully put together and could fool the average user who\njust takes a casual look at the format and the content. Either way, there are\nsome tell-tale signs that can indicate that an email you receive is not legit: <\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Generic email greeting, such as \u2018Dear customer\u2019. Your bank has your full name on record<\/li><li>A link of a url that you do not recognise or looks suspicious \u2013 check the link source before you click on it, often by hovering over the link<\/li><li>Unexpected attachments<\/li><li>Grammar and spelling mistakes<\/li><li>Urgent calls to action \u2013 \u2018Log in within the next 48 hours, or your account will be closed\u2019, \u2018Your account has been breached&#8217;, or &#8216;To receive your refund, you must login in the next 24 hours\u2019. <\/li><\/ul>\n\n\n\n<p><strong>Educate your team<\/strong><\/p>\n\n\n\n<p>Educate your team about the dangers of phishing emails and the signs that an email might be a scam. Consider introducing policies that forbid them from opening attachments they are not expecting or clicking on a link in an email they do not recognise. You may also consider making it company policy not to use the same password for different websites. Ask employees to alert you when they see emails that seem random or suspicious. <\/p>\n\n\n\n<p><strong>Enable two-factor authentication <\/strong><\/p>\n\n\n\n<p>Two-factor authentication is about using something\nyou know (your password) and something you have (a one-time pin received on\nyour phone, your thumbprint, or a token) to sign into an online service. Even\nif you accidentally give your banking login and password to a scammer, they\nwill not be able to do much with it if they don\u2019t have access to your phone. It\ncan be an essential extra layer of security for your sensitive data. <\/p>\n\n\n\n<p><strong>Install anti-virus and anti-malware software <\/strong><\/p>\n\n\n\n<p>There are a lot of scams and malware variants on the Internet, and installing anti-virus or anti-malware software can help to keep your devices and data safer. When it comes to phishing, up-to-date security software can help by catching the virus or malware and quarantining it, should a user click on a phishing email.&nbsp; Also, check with your service provider to see if they offer security monitoring solutions to help block suspicious emails before they enter your inbox. <\/p>\n\n\n\n<p><strong>Get SSL for your website <\/strong><\/p>\n\n\n\n<p>If the email passes all of the steps above, and you click a link to visit a website, there are two more checks to do: check to make sure you are on the company\u2019s actual website; and, check the website url address bar to see it has an SSL certificate. With South Africans growing more savvy about the importance of online security and more concerned about potential cybercrime, no small business can overlook the importance of installing an SSL Certificate for their website. The reassuring presence of the familiar padlock symbol in the URL bar as a sign of SSL security, protecting the transmission of personal information, shows online visitors and shoppers that you take security seriously and that your website has additional security protections in place. <\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>We asked a number of industry experts what advice they have for organisations in the battle to prevent the rise of phishing attacks. Here is what they had to say. Jurgen Sorton, Senior Product Manager for Security at Vox&nbsp;&nbsp; Phishing attacks are on the rise and show no signs of slowing down. According to the [&hellip;]<\/p>\n","protected":false},"author":25,"featured_media":21253,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[4950,843,5,328,136,6,13,262],"tags":[3388,3390,394,11994,11995,11993,11986,3681,11868,6781,11990,11015,1123,392,101,2178,484,11985,174,1415,11997,11867,11991,1618,5442,6010,409,11996,8075,5372,11984,11988,11989,11987],"class_list":["post-30810","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-analysis","category-editors-choice","category-enterprise-security","category-features","category-industry-expert","category-insights","category-top-stories","category-used","tag-bec","tag-business-email-compromise","tag-cyberthreat","tag-dkim","tag-domain-based-message-authentication","tag-domainkeys-identified-mail","tag-drs","tag-forrester","tag-godaddy","tag-hackers","tag-hosted-email-security","tag-jurgen-sorton","tag-linkedin","tag-machine-learning","tag-malware","tag-microsoft-office-365","tag-mimecast","tag-mj-strydom","tag-paypal","tag-phishing","tag-ranswomware","tag-selina-bieber","tag-sender-policy-framework","tag-smishing","tag-spear-phishing","tag-state-of-email-security","tag-trend-micro","tag-trend-micro-cloud-app-security","tag-vishing","tag-vox","tag-whaling","tag-worry-free-services","tag-xgen-security","tag-zaheer-ibrahim"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/30810","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/users\/25"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/comments?post=30810"}],"version-history":[{"count":7,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/30810\/revisions"}],"predecessor-version":[{"id":30895,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/30810\/revisions\/30895"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media\/21253"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media?parent=30810"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/categories?post=30810"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/tags?post=30810"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}