{"id":20912,"date":"2022-11-10T12:11:27","date_gmt":"2022-11-10T12:11:27","guid":{"rendered":"https:\/\/www.intelligentcio.com\/apac\/?p=20912"},"modified":"2022-11-21T14:31:19","modified_gmt":"2022-11-21T14:31:19","slug":"editors-question-what-can-be-done-to-fight-back-against-phishing","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/apac\/2022\/11\/10\/editors-question-what-can-be-done-to-fight-back-against-phishing\/","title":{"rendered":"Editor\u2019s Question: What can be done to fight back against phishing?"},"content":{"rendered":"\n<p><em><strong>We asked industry experts what can be done to fight back against increasingly sophisticated phishing techniques? Here are their responses:<\/strong><\/em><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignleft size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.intelligentcio.com\/apac\/wp-content\/uploads\/sites\/44\/2022\/11\/Anthony-Daniel-w.png\" alt=\"\" class=\"wp-image-20913\" width=\"237\" height=\"227\" srcset=\"https:\/\/www.intelligentcio.com\/apac\/wp-content\/uploads\/sites\/44\/2022\/11\/Anthony-Daniel-w.png 500w, https:\/\/www.intelligentcio.com\/apac\/wp-content\/uploads\/sites\/44\/2022\/11\/Anthony-Daniel-w-300x287.png 300w\" sizes=\"auto, (max-width: 237px) 100vw, 237px\" \/><figcaption class=\"wp-element-caption\"><strong>Anthony Daniel, Regional Director \u2013 Australia, New Zealand and Pacific Islands, WatchGuard Technologies<\/strong><\/figcaption><\/figure><\/div>\n\n\n<p><strong>Anthony Daniel, Regional Director \u2013 Australia, New Zealand and Pacific Islands, WatchGuard Technologies<\/strong><\/p>\n\n\n\n<p><em>What can be done to fight back against increasingly sophisticated phishing techniques?<\/em><\/p>\n\n\n\n<p>It\u2019s often said that the only certainties in life are death and taxes. These days, a third items needs to be added to the list: phishing attacks.<\/p>\n\n\n\n<p>These targeted attempts to illicit personal details from unsuspecting users are growing in both number and sophistication. Cybercriminals are mounting them with the aim of either causing disruption to an organization\u2019s IT infrastructure or securing a financial gain.<\/p>\n\n\n\n<p>When they first emerged as an attack type, phishing attempts were relatively easy to spot. The poorly written nature of the emails, often riddled with spelling mistakes and grammatical errors, made recipients regard them with suspicion and avoid any associated attachments or links.<\/p>\n\n\n\n<p>However, cybercriminals have become much better at their craft. Today, many phishing emails are almost impossible to distinguish from real ones. They often appear to have come from a legitimate source and can be difficult to spot amid a daily email deluge.<\/p>\n\n\n\n<p><strong>Be ever vigilant<\/strong><\/p>\n\n\n\n<p>Thankfully, there are some practical steps individuals can take to reduce their chances of falling victim to a phishing attack. They include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong><em>Don\u2019t trust unusual requests:<\/em><\/strong><br>Some phishing emails can appear to have come from a trusted colleague or manager which can make opening them tempting. Always keep an eye out for requests that seem out of the ordinary or arrive at odd times of the day or night. If in doubt, confirm veracity of the message with the apparent sender by phone.<br><\/li>\n\n\n\n<li><strong><em>Watch for poor grammar:<\/em><\/strong><br>While phishing emails have become more sophisticated, many still contain misspellings and errors. If a received message has glaring errors in the text, proceed with caution.<br><\/li>\n\n\n\n<li><strong><em>Check the sender\u2019s email address:<\/em><\/strong><br>Some phishing emails can be spotted by checking the address from which they were sent. It might be similar to a legitimate address, but slightly different. If something doesn\u2019t look quite right, avoid opening the message and double check with the apparent sender.<br><\/li>\n\n\n\n<li><strong><em>Avoid clicking on embedded links:<br><\/em><\/strong>Many phishing emails contain links that take recipients to websites that contain malicious code. Think very carefully before clicking on any links in emails unless you are confident they have come from a legitimate source.<br><\/li>\n\n\n\n<li><strong><em>Never download files from an unknown source:<\/em><\/strong><br>Attaching infected files to phishing emails is a popular tactic among cybercriminals. Resist the temptation to download files if they have come from an unknown sender.<br><\/li>\n\n\n\n<li><strong><em>Check with your security team:<\/em><\/strong><br>If and when you receive what appears to be a phishing email, forward it to your organization\u2019s IT department for closer inspection.<\/li>\n<\/ul>\n\n\n\n<p>By taking these steps, the chances of falling victim to a phishing attack can be significantly reduced. This means disruption can be avoided and legitimate workflows can continue.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignleft size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.intelligentcio.com\/apac\/wp-content\/uploads\/sites\/44\/2022\/04\/Mark-Lukie-HR2-w.jpg\" alt=\"\" class=\"wp-image-12890\" width=\"236\" height=\"240\" srcset=\"https:\/\/www.intelligentcio.com\/apac\/wp-content\/uploads\/sites\/44\/2022\/04\/Mark-Lukie-HR2-w.jpg 500w, https:\/\/www.intelligentcio.com\/apac\/wp-content\/uploads\/sites\/44\/2022\/04\/Mark-Lukie-HR2-w-295x300.jpg 295w\" sizes=\"auto, (max-width: 236px) 100vw, 236px\" \/><figcaption class=\"wp-element-caption\"><strong>Mark Lukie, Director of Solution Architects \u2013 APAC, Barracuda Networks<\/strong><\/figcaption><\/figure><\/div>\n\n\n<p><strong>Mark Lukie, Director of Solution Architects \u2013 APAC, Barracuda Networks<\/strong><\/p>\n\n\n\n<p><em>What can be done to fight back against increasingly sophisticated phishing techniques?<\/em><\/p>\n\n\n\n<p>Phishing has become a favored tactic for cybercriminals because it delivers results. By crafting emails so they appear to have come from a legitimate source, recipients can be tricked into opening attachments or clicking on links that result in systems becoming compromised. Indeed, <a href=\"https:\/\/www.barracuda.com\/the-state-of-cyber-resilience-au\" target=\"_blank\" rel=\"noreferrer noopener\"><em>The State of Cyber-resilience in Australia 2022<\/em><\/a><em> <\/em>report revealed that 60% of employees assume links in emails are safe to click on if the message came through the corporate email system, and 22% download and install unapproved software on to devices used for work.<\/p>\n\n\n\n<p>Recent global analysis by Barracuda of millions of business emails served to shine a spotlight on the problem. The <a href=\"https:\/\/www.barracuda.com\/spearphishing-vol7\" target=\"_blank\" rel=\"noreferrer noopener\">research<\/a> found that 51% of social engineering attacks are phishing attacks and small businesses are far more likely to fall victim than larger enterprises.<\/p>\n\n\n\n<p>Thankfully, there are a range of initiatives that organizations can undertake to reduce the likelihood they will fall victim to a phishing attack. The initiatives fall into two distinct categories: technology and human.<\/p>\n\n\n\n<p><strong>Technological initiatives<\/strong><\/p>\n\n\n\n<p>There are a range of ways technology can be used to thwart attacks and they include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong><em>Deploying AI-powered email protection:<\/em><br><\/strong>When it comes to technology, one of the most effective ways to use it against phishing attacks is to deploy some of the sophisticated Artificial Intelligence tools now on the market. These tools help to combat the fact that cybercriminals are adapting their tactics to bypass gateways and spam filters such as account takeover or business email compromise (BEC).<br><\/li>\n\n\n\n<li><strong><em>Monitoring suspicious logins:<br><\/em><\/strong>Tools can be used to identify suspicious network activity such as logins from unusual locations and IP addresses as this can be a sign of a compromised account. It\u2019s important to also monitor email accounts for malicious inbox rules, as these are often used as part of account takeovers.<br><\/li>\n\n\n\n<li><strong><em>Making use of MFA:<\/em><br><\/strong>Multi-factor authentication (MFA) provides an additional layer of security beyond simple username\/password combinations. Additional factors can include authentication codes, thumb prints and retinal scans.<br><\/li>\n\n\n\n<li><strong><em>Automating incident response:<\/em><\/strong><br>An automated incident response solution will help an organization quickly clean up any threats found in user inboxes which, in turn, will make remediation more efficient for all messages in the future.<\/li>\n<\/ul>\n\n\n\n<p><strong>Human initiatives<\/strong><\/p>\n\n\n\n<p>There are also a range of \u2018human\u2019 initiatives that can help with the problem. They include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong><em>Conducting regular training:<\/em><\/strong><br>Staff must be trained to recognize and report phishing and spear-phishing attacks. They need to understand their fraudulent nature and know how to respond. A phishing simulation can help train users to identify cyberattacks and evaluate the users most vulnerable to attacks.<br><\/li>\n\n\n\n<li><strong><em>Reviewing internal policies:<\/em><\/strong><br>It\u2019s also important to help employees avoid making costly mistakes by putting procedures in place that determine how all incoming email-based requests are handled.<br><\/li>\n\n\n\n<li><strong><em>Ensuring data-loss prevention:<br><\/em><\/strong>Put in place the right technologies and business policies to ensure emails with sensitive information are blocked and never leave the organization.<\/li>\n<\/ul>\n\n\n\n<p>By following these initiatives, an organization can significantly reduce the likelihood it will experience disruption and losses as the result of a successful phishing attack.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignleft size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.intelligentcio.com\/apac\/wp-content\/uploads\/sites\/44\/2022\/11\/Martin-BitDefender-w.jpg\" alt=\"\" class=\"wp-image-21431\" width=\"239\" height=\"239\" srcset=\"https:\/\/www.intelligentcio.com\/apac\/wp-content\/uploads\/sites\/44\/2022\/11\/Martin-BitDefender-w.jpg 500w, https:\/\/www.intelligentcio.com\/apac\/wp-content\/uploads\/sites\/44\/2022\/11\/Martin-BitDefender-w-300x300.jpg 300w, https:\/\/www.intelligentcio.com\/apac\/wp-content\/uploads\/sites\/44\/2022\/11\/Martin-BitDefender-w-150x150.jpg 150w\" sizes=\"auto, (max-width: 239px) 100vw, 239px\" \/><figcaption class=\"wp-element-caption\"><strong>Martin Zugec, Technical Solutions Director, Bitdefender<\/strong><\/figcaption><\/figure><\/div>\n\n\n<p><strong>Martin Zugec, Technical Solutions Director, Bitdefender<\/strong><\/p>\n\n\n\n<p>The Coronavirus outbreak and the work-from-home \u2018new normal\u2019 served as a catalyst for the evolution of phishing emails. Traditionally, phishing emails were easy to spot because of typos, poor wording, and the lack of authenticity. Only spear phishing emails, which directly targeted specific individuals and organizations, were sophisticated enough to create a sense of legitimacy. All that changed when the pandemic hit, as cybercriminals started focusing on creating mass phishing emails that lack typos, use reader-specific jargon, and even abuse the legitimate logos of the organizations or companies that they\u2019re impersonating. More than that, these new phishing attacks quickly leverage popular topics in the media and exploit the way users have started to engage with financial and delivery companies in a work-from-home context.<\/p>\n\n\n\n<p>The social engineering component of these new phishing campaigns has reached new heights of sophistication, with attackers focusing more on increasing the success rate of their campaigns, rather than boosting the volume of spam sent. This increase in efficacy and sense of legitimacy in phishing campaigns makes it more difficult for the untrained eye to discern fake from real.<\/p>\n\n\n\n<p>Here are some tips on how to fight back:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Be aware of lookalike websites. Check the address bar for typos and look for poor grammar. If anything seems off, leave the website immediately<\/li>\n\n\n\n<li>Don\u2019t use public Wi-Fi to make purchases or do your banking. If you do need to connect to a public network, use a VPN to make sure that no malicious individuals can intercept your sensitive info<\/li>\n\n\n\n<li>Use a protected browser designed to keep your online banking, e-shopping and any other type of online transaction private and secure<\/li>\n\n\n\n<li>Install a security solution on your PC and smart devices to locally protect your data and ward off e-threats including fraudulent websites, malware and phishing attempts that could ruin your holiday<\/li>\n\n\n\n<li>Monitor your accounts and credit card statements for suspicious activity so you can put a stop to fraud and limit the chances of becoming an identity theft victim<\/li>\n<\/ul>\n\n\n\n<p>While these are general cyber hygiene tips that anyone can start implementing immediately, there are technologies available that offer even greater protection. When these online best practices are combined with technologies that protect your passwords with a password manager, offer an integrated virtual keyboard that makes it impossible for hackers to monitor keystrokes, or built-in hotspot protection to protect your device when connected to unsecured Wi-Fi networks, you can defend yourself against even the most advanced phishing campaigns.<\/p>\n\n\n\n<p>Security solutions with integrated threat intelligence offer great protection against these modern phishing campaigns. Every day, we collect data from hundreds of millions of endpoints, analyze it, identify malicious sites, and use this centralized feed to protect various devices, from laptops, through network routers, to smartphones. We are seeing more cases where spoofing sites are indistinguishable from the legitimate ones, and the machine is better at detecting these malicious sites than the human eye and brain. These security controls were traditionally deployed on the network perimeter \u2013 but with work-from-home and mobile workstyle, threat intelligence needs to be available to every device.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignleft size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.intelligentcio.com\/apac\/wp-content\/uploads\/sites\/44\/2022\/11\/DavidArthur.jpg\" alt=\"\" class=\"wp-image-21433\" width=\"236\" height=\"236\" srcset=\"https:\/\/www.intelligentcio.com\/apac\/wp-content\/uploads\/sites\/44\/2022\/11\/DavidArthur.jpg 450w, https:\/\/www.intelligentcio.com\/apac\/wp-content\/uploads\/sites\/44\/2022\/11\/DavidArthur-300x300.jpg 300w, https:\/\/www.intelligentcio.com\/apac\/wp-content\/uploads\/sites\/44\/2022\/11\/DavidArthur-150x150.jpg 150w\" sizes=\"auto, (max-width: 236px) 100vw, 236px\" \/><figcaption class=\"wp-element-caption\"><strong>David Arthur, Security Practice Lead \u2013 Australia and New Zealand, for multi-cloud security and application delivery company F5<\/strong><\/figcaption><\/figure><\/div>\n\n\n<p><strong>David Arthur, Security Practice Lead \u2013 Australia and New Zealand, for multi-cloud security and application delivery company F5<\/strong><\/p>\n\n\n\n<p>The tactics employed by cybercriminals are not only becoming more sophisticated, but increasingly aggressive. The tactics have advanced considerably to now include impersonation and emotional manipulation. So, what can be done to fight back?<\/p>\n\n\n\n<p><strong>Learn to spot the tell-tale signs<\/strong><\/p>\n\n\n\n<p>If it looks suspicious, it probably is. So often these scams are full of grammatical and spelling errors, unrealistic but tempting offers, and questionable links. However, they can also be incredibly well-crafted and difficult to identify as fraudulent. It\u2019s best to open a new browser tab and search for the website, promotion or content referenced.<\/p>\n\n\n\n<p>One of the most important things to remember is that phishing attacks don\u2019t only occur via email. Growing in popularity is phishing via SMS, known as smishing, which is proving successful as a means for criminals to lure victims into clicking on dangerous links. These must be viewed with the same level of skepticism. Search for the company and promotion in a separate browser link, and never click on the link from a text message.<\/p>\n\n\n\n<p><strong>Visibility over your information<\/strong><\/p>\n\n\n\n<p>It\u2019s almost impossible these days to do anything online without your data being collected and stored, and that problem is only going to intensify as expectations for digital experiences continue to grow. Given the breadth of personal information to which hackers can now gain access, more accurately targeted phishing attacks, known as Spear Phishing, are a growing concern. By using sensitive information, attackers can convincingly trick people into believing the legitimacy of these scams.<\/p>\n\n\n\n<p>While it\u2019s easy to dismiss necessary action on the part of the individual, relying instead on organizations to prioritize security and have measures in place to protect your information and data, maintaining full awareness and visibility over your personal information is critical.<\/p>\n\n\n\n<p><strong>The best defense is a good offense<\/strong><\/p>\n\n\n\n<p>The entire cyber landscape is evolving at an unprecedented rate. We\u2019ve seen this across every element of cybercrime, and phishing is no different. Cybercriminals regularly adapt and update their tactics to out-pace mitigation efforts and stay ahead of the game.<\/p>\n\n\n\n<p>Keeping as well-informed as possible on the latest tactics and trends is fundamental to ongoing protection, as it is adapting your approach to managing the potential risks. Ensuring that the security software is continually (preferably, automatically) updated is easy to overlook, but crucial.<\/p>\n\n\n\n<p>An adjustment to mindset is arguably the most important step in fighting back. As the quest for connectivity and digital acceleration increases, security must remain front-of-mind to guide our online movements.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignleft size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.intelligentcio.com\/apac\/wp-content\/uploads\/sites\/44\/2022\/11\/Abigail-Showman.png\" alt=\"\" class=\"wp-image-21432\" width=\"237\" height=\"284\" \/><figcaption class=\"wp-element-caption\"><strong>Abigail Showman, Senior Intelligence Analyst, Flashpoint<\/strong><\/figcaption><\/figure><\/div>\n\n\n<p><strong>Abigail Showman, Senior Intelligence Analyst, Flashpoint<\/strong><\/p>\n\n\n\n<p>Phishing attacks are commonly launched against both individuals and organizations, with the potential for devastating consequences to both. Therefore, fighting back against these attacks requires team and individual-driven efforts.<\/p>\n\n\n\n<p>Two of the most commonly used phishing techniques are:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Sending fraudulent emails impersonating organizations or administrators and asking potential victims for credentials<\/li>\n\n\n\n<li>Creating fraudulent websites impersonating a target website that then harvests a victim\u2019s login information<\/li>\n<\/ul>\n\n\n\n<p>Differing from the cyberattacks that target an organization\u2019s systems, phishing attacks target individuals, making it much more difficult for security teams to oversee and prevent them.<\/p>\n\n\n\n<p>Phishing attacks can appear in a number of different forms, from shipment tracking notifications to newsletters and promotional material. These can be generic or specifically customized to the target. Threat actors often leverage significant events, such as natural disasters or global news events\/crises, to lend legitimacy to the phishing campaign. This often compels users to respond out of sympathy.<\/p>\n\n\n\n<p>People should avoid clicking on any link within an unsolicited email or text message. Threat actors have become adept at making phishing campaigns appear legitimate by incorporating an organization\u2019s real contact details, website information, or commonly used messaging.<\/p>\n\n\n\n<p>Checking web domains to verify they are authentic should be common cybersecurity practice, especially if a site is asking a user to enter login credentials or other sensitive information.<\/p>\n\n\n\n<p>Another important step is to limit the amount of publicly available personal information. Threat actors will use this information to create highly customized and personalized messages that appear believable, making it easier to trick the victim into providing sensitive information they may not otherwise provide. Threat actors are adapting and updating their methods, so it\u2019s important to take extra care scrutinising unsolicited emails or messages.<\/p>\n\n\n\n<p>Anti-phishing add-ons should be installed to company devices and browsers to notify employees of a suspicious email or text. Additionally, password rotation should be enforced, requiring employees to change passwords after a given time period. Firewalls should also be installed to shield devices from attempted attacks and prevent infiltration by threat actors.<\/p>\n\n\n\n<p>It is critical organizations have a strong threat intelligence program to alert security teams to suspicious activity that could predict an imminent phishing threat.<\/p>\n\n\n\n<p>Perhaps the most important element in mounting a defense against phishing attacks is education. Organizations should educate employees on the signs of a phishing attack and work to instil the messages of precautionary methods throughout the entire company. Good threat intelligence boosts an organization\u2019s ability to educate, providing real-life examples and the most up-to-date information to guarantee individuals have a thorough understanding of the threat landscape.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We asked industry experts what can be done to fight back against increasingly sophisticated phishing techniques? Here are their responses: Anthony Daniel, Regional Director \u2013 Australia, New Zealand and Pacific Islands, WatchGuard Technologies What can be done to fight back against increasingly sophisticated phishing techniques? It\u2019s often said that the only certainties in life are [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":20914,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[47,55,44],"tags":[2327,1549,1859,3195,340,1860],"class_list":["post-20912","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-editors-choice","category-oceania","category-top-stories","tag-anthony-daniel","tag-barracuda","tag-editors-question","tag-mark-lukie","tag-phishing","tag-watchguard"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/posts\/20912","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/comments?post=20912"}],"version-history":[{"count":5,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/posts\/20912\/revisions"}],"predecessor-version":[{"id":21434,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/posts\/20912\/revisions\/21434"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/media\/20914"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/media?parent=20912"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/categories?post=20912"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/tags?post=20912"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}