{"id":32687,"date":"2019-01-15T10:07:15","date_gmt":"2019-01-15T10:07:15","guid":{"rendered":"http:\/\/www.intelligentcio.com\/me\/?p=32687"},"modified":"2019-01-15T10:08:13","modified_gmt":"2019-01-15T10:08:13","slug":"cofense-expert-on-how-the-human-firewall-helps-stop-phishing-attacks","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2019\/01\/15\/cofense-expert-on-how-the-human-firewall-helps-stop-phishing-attacks\/","title":{"rendered":"Cofense expert on how the human firewall helps stop phishing attacks"},"content":{"rendered":"<p><em>Phishing attacks remain a source of anguish for CISOs and security professionals. But those who choose to just throw technology at the problem are overlooking a vital component of their defence \u2013 the \u2018human firewall\u2019. Kamel Tamimi, Principal Security Consultant, Cofense Inc, tells us more&#8230;<\/em><\/p>\n<p>Until human nature changes (don\u2019t hold your breath) phishing attacks that target unwary people will be a headache. Two recent headlines show the Middle East and Africa are not being spared.<\/p>\n<p>Last November, a leading regional bank issued a customer alert about a phishing email dangling a value-added tax refund. Naturally, the email purported to come from the bank. Whose pulse wouldn\u2019t quicken at the thought of getting some money back?<\/p>\n<p>The following month, Amnesty International warned of several credential phishing campaigns, likely from the same attackers, targeting Middle Eastern and North African organisations. In one campaign, the threat actors took aim at accounts on \u2018secure\u2019 emails services like Tutanota and ProtonMail.<\/p>\n<p>It would be nice if automation could solve the problem completely. But while automated systems, Machine Learning and AI can help, malicious emails are still getting past the perimeter. Just ask the regional bank and Amnesty International.<\/p>\n<p><strong>Here\u2019s what organisations tell us about the human factor.<\/strong><\/p>\n<p>You could also ask organisations in the region and across the globe. At Cofense, we talk to them every day about effective phishing defence. Following are some of their insights on thwarting attacks on humans by empowering them with the right expertise and tools.<\/p>\n<p>Let\u2019s start with the head of information security at a Middle Eastern university. A few years ago, after large-scale attacks by nation-state actors on other regional targets, he made human-vetted phishing defence his number one priority, anchored by a rigorous phishing simulation program.<\/p>\n<p>When he launched the program, users \u2013 students, faculty, administrators and anyone else using the network \u2013 fell for simulated phish 55% of the time. That number has now dropped to close to 10%, with the number of users reporting bad emails up to 50%.<\/p>\n<p>(FYI, Cofense data shows that the energy industry leads the region in phishing reporting \u2013 on average, over 16 users report a simulated phish to every user that falls susceptible.)<\/p>\n<p>\u201cMy mandate was to do everything necessary to protect the university community,\u201d the head of information security reported.<\/p>\n<p>\u201cWe invested in technological solutions, but with 30 years of IT experience, I know that you need to invest in people, not just processes and technology. You need to make them human firewalls.\u201d<\/p>\n<p>He added: \u201cLook at it this way. You can put five locks on your door, but if you leave the keys under the doormat, the locks don\u2019t do much good. Fortifying the human firewall is my utmost priority. The human element is the most important part of your defence.\u201d<\/p>\n<p><strong>\u201cHey, is this the right payment?\u201d<\/strong><\/p>\n<p>The cyber-program director of a multinational utility echoed these remarks.<\/p>\n<p>\u201cMy CISO often states that if he had to cut all of his budget, down to the bare bones, all that he would choose to spend on would be awareness and response,\u201d he said.<\/p>\n<p>\u201cWe had a scenario where, all the way up to the CEO, they were ready to make a treasury payment until somebody finally picked up the phone and said, \u2018hey, is this the right payment to be made?\u2019 And it was blocked.\u201d<\/p>\n<p>Referring to constant changes in attack techniques and the need for defensive adjustments, he added, \u201cI\u2019m reminded of a quote from Alice in Wonderland, when the White Queen was saying, \u2018In order to keep up, you have to run as fast as you can.\u2019\u201d<\/p>\n<p><strong>Removing phishing emails \u2018sometimes in five or 10 minutes\u2019.<\/strong><\/p>\n<p>An operational risk consultant with a global financial company shared with us an example of employees helping the SOC stop phishing threats in minutes.<\/p>\n<p>\u201cI don\u2019t think security is going to be improved by the next best technology we put in place, whether it\u2019s an appliance or a firewall or something that blocks at the proxy,\u201d she said.<\/p>\n<p>\u201cFor example, we had a Word document with macros slip through our filters, so we just need to teach the humans that own our email addresses to be extra-vigilant.\u201d<\/p>\n<p>She continued: \u201cWe see some departments reporting as high as 60 percent in phishing simulations, but they also report [real] malicious emails that go to our cyberdefence teams \u2013 and they get them out of the network sometimes in five or 10 minutes.\u201d<\/p>\n<p><strong>\u201cThat\u2019s a return on investment.\u201d<\/strong><\/p>\n<p>Noting the futility of investing in technology while users remain untrained, a cybersecurity awareness evangelist at one of California\u2019s largest companies said: \u201cIn one corner you\u2019ve got 10 million dollars in defence perimeter equipment and on the other side, of course, you\u2019ve got \u2018Dave.\u2019<\/p>\n<p>\u201cA machine cannot apply a non-linear approach to a problem. A machine is just conditioned to do one thing. But a human-being with instinct can make decisions that are a lot more intricate.\u201d<\/p>\n<p>His company too relies on employees to report actual phishing threats.<\/p>\n<p>\u201cLast month, we saw 33 reported threats come into our IR inbox,\u201d he said. \u201cWhen you consider that a breach could cost six million dollars, that\u2019s a return on investment.\u201d<\/p>\n<p><strong>\u201cWhat did you do to prevent this?\u201d<\/strong><\/p>\n<p>The last word comes from another global financial company:<\/p>\n<p>\u201cTo not focus on phishing would be pretty negligent on any company\u2019s part,\u201d said the company\u2019s operational risk consultant.<\/p>\n<p>\u201cAt the end of the day, if we have a breach it\u2019s probably going to have stemmed from some sort of phishing attack. When our regulators or clients are asking us, \u2018What did you do to prevent this?\u2019 it\u2019s important to feel confident that we have an anti-phishing program in place.\u201d<\/p>\n<p>She noted that inbox behaviour is \u2018easily measurable\u2019. It\u2019s not hard to sustain a phishing defence program because the metrics are simple to gather and use to demonstrate success.<\/p>\n<p>In fact, automation makes it even easier, allowing program managers to schedule a year\u2019s worth of simulations in a matter of minutes. Other automated systems enable SOC teams to filter and analyse reported emails quickly, plus remove them from users\u2019 inboxes when verified as threats.<\/p>\n<p>Those are smart uses of technology. After all, machines are great at saving time and handling repetitive tasks, saving human brains and intuition for critical decision-making. But if you\u2019re placing all your bets on tech and neglecting the human factor, it\u2019s going to be a long, and very phishy, year.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Phishing attacks remain a source of anguish for CISOs and security professionals. But those who choose to just throw technology at the problem are overlooking a vital component of their defence \u2013 the \u2018human firewall\u2019. Kamel Tamimi, Principal Security Consultant, Cofense Inc, tells us more&#8230; Until human nature changes (don\u2019t hold your breath) phishing attacks [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":32693,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,6,13],"tags":[1063,6609,7591,7248,562,587,7249],"class_list":["post-32687","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-insights","category-top-stories","tag-africa","tag-cofense","tag-cofense-inc","tag-kamel-tamimi","tag-middle-east","tag-phishing","tag-principal-security-consultant"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/32687","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=32687"}],"version-history":[{"count":2,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/32687\/revisions"}],"predecessor-version":[{"id":32692,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/32687\/revisions\/32692"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/32693"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=32687"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=32687"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=32687"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}