{"id":31879,"date":"2020-02-10T13:11:01","date_gmt":"2020-02-10T13:11:01","guid":{"rendered":"https:\/\/www.intelligentcio.com\/africa\/?p=31879"},"modified":"2020-02-13T12:43:55","modified_gmt":"2020-02-13T12:43:55","slug":"new-cybersecurity-realities-require-that-brands-protect-customers","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/africa\/2020\/02\/10\/new-cybersecurity-realities-require-that-brands-protect-customers\/","title":{"rendered":"New cybersecurity realities require that brands protect customers"},"content":{"rendered":"\n<p>Over the\npast 12 months, South African public and private sector organisations have\nfallen victim to a range of sophisticated cyberattacks that have disrupted\nbusiness operations and resulted in reputational damage, loss of productivity\nand finances.<\/p>\n\n\n\n<p>Most\norganisations have to protect against a growing list of attacks including\nphishing, ransomware, impersonation fraud and insider threats. IT security\nteams are often overwhelmed and under-resourced, making it increasingly\ndifficult to detect and defend against cyberattacks. That many end-users remain\nunaware of how to identify and stop incoming threats only adds fuel to the\nfire.<\/p>\n\n\n\n<p><strong>Looking\nbeyond the perimeter to protect customers<\/strong><\/p>\n\n\n\n<p>But beyond\nprotecting their own organisations from these attacks, security leaders need to\ntake an expanded view that protects their customers too. <\/p>\n\n\n\n<p>Heino\nGevers, Cybersecurity Specialist at Mimecast, warns that organisations can no\nlonger rely on their customers being cyber aware when it comes to malicious\nmails exploiting their brand. <\/p>\n\n\n\n<p>\u201cIn the\npast, service providers tended to pass the buck when their customers fell\nvictim to a scam impersonating them,\u201d he said.<\/p>\n\n\n\n<p>\u201cIt was\neasy to blame the individual\u2019s misfortune on their own poor cyber awareness.\nBut as cyberattacks have become more sophisticated, the buck now stops with the\nbrand.\u201d <\/p>\n\n\n\n<p>Gevers adds\nthat organisations are no longer excused from looking beyond their own security\nperimeter to protect customers and partners. <\/p>\n\n\n\n<p>\u201cIt\u2019s\nsurprisingly easy for attackers to impersonate a brand on the Internet. Even an\nunsophisticated attacker can register a domain similar to a well-known brand\nand draw customers, partners and the public to it. Because there\u2019s an\nunderlying level of trust in the brand they are impersonating, there is an\nelevated risk of customers clicking on a link that deploys malware to their\ndevice or sharing personal information that is used later for financial gain.\u201d<\/p>\n\n\n\n<p><strong>Holistic\nprotection and resilience is essential<\/strong><\/p>\n\n\n\n<p>Gevers says\nnine out of ten cyberattacks globally use email as the primary attack channel.<\/p>\n\n\n\n<p>\u201cBusiness\nemail can be used to give criminals access to confidential information, gain\ncontrol over an organisation\u2019s IT assets and disrupt business operations,\u201d he\nsaid.<\/p>\n\n\n\n<p>\u201cEffective\nsecurity controls must include protection from external threats at the email\nperimeter and internal threats within the network and organisation. They then\nneed to look beyond the perimeter to ensure their brand isn\u2019t being\nimpersonated to target external email users like customers.\u201d<\/p>\n\n\n\n<p>While it\nmight seem obvious, there are still some organisations that aren\u2019t protecting\nthemselves from emails containing malicious links or malware within\nattachments. <\/p>\n\n\n\n<p>\u201cFirst and\nforemost, organisations need to implement effective controls at the perimeter\nto detect phishing, spear-phishing and malware attacks,\u201d said Gevers.<\/p>\n\n\n\n<p>\u201cBut it\ndoesn\u2019t stop there. Criminals often try to bypass perimeter security by using a\ncompromised employee\u2019s account or social engineering to transmit email from an\ninternal network, which can then expose organisations to immense risk. All it\ntakes is for one employee to click on a malicious link or open a compromised\nattachment to put the entire network at risk. Regular awareness training should\nbe the norm for South African organisations to ensure their employees have the\nknowledge to identify and avoid risky behaviour.&#8221;<\/p>\n\n\n\n<p>Protecting\nan organisation from brand impersonation is then the third and often overlooked\nstep to ensuring pervasive protection. <\/p>\n\n\n\n<p>\u201cOrganisations\nshould look at tools such as DMARC to protect the domains owned by the\norganisation from impersonation and fraud,\u201d said Gevers. <\/p>\n\n\n\n<p>\u201cThis\nshould be supported by the ability to proactively hunt for domain and brand\nabuse and the power to take down fraudulent sites aiming to exploit customers\nand partners. <\/p>\n\n\n\n<p>\u201cUnfortunately,\ncyberattacks like this leverage and can ultimately destroy value and trust that\na brand owner may have taken years or decades to build.&nbsp; So, it\u2019s really\nin the interest of the brand to take the correct measures to prevent this from\nhappening.&#8221;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Over the past 12 months, South African public and private sector organisations have fallen victim to a range of sophisticated cyberattacks that have disrupted business operations and resulted in reputational damage, loss of productivity and finances. Most organisations have to protect against a growing list of attacks including phishing, ransomware, impersonation fraud and insider threats. [&hellip;]<\/p>\n","protected":false},"author":25,"featured_media":31880,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[4950,5,275,399,262],"tags":[859,5440,1142,484,1415,277,453],"class_list":["post-31879","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-analysis","category-enterprise-security","category-intelligent-technology-newsletter","category-more-news","category-used","tag-cyberattacks","tag-impersonation-fraud","tag-insider-threats","tag-mimecast","tag-phishing","tag-ransomware","tag-south-africa"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/31879","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/users\/25"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/comments?post=31879"}],"version-history":[{"count":3,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/31879\/revisions"}],"predecessor-version":[{"id":31883,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/31879\/revisions\/31883"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media\/31880"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media?parent=31879"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/categories?post=31879"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/tags?post=31879"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}