{"id":49196,"date":"2020-06-11T11:57:49","date_gmt":"2020-06-11T10:57:49","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/?p=49196"},"modified":"2020-06-11T11:57:52","modified_gmt":"2020-06-11T10:57:52","slug":"mimecast-report-reveals-60-of-uae-organisations-expect-to-suffer-email-borne-attack","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2020\/06\/11\/mimecast-report-reveals-60-of-uae-organisations-expect-to-suffer-email-borne-attack\/","title":{"rendered":"Mimecast report reveals 60% of UAE organisations expect to suffer email-borne attack"},"content":{"rendered":"\n<p><strong><em>The fourth annual report from Mimecast finds greatest new concern is email and web spoofing. \u00a0<\/em><\/strong><\/p>\n\n\n\n<p>Mimecast, a leading email and data security company, has unveiled its fourth-annual State of Email Security 2020 report. This report summarises details from 1,025 global IT decision makers on the current state of cybersecurity.<\/p>\n\n\n\n<p>Providing year-over-year comparisons, along with Mimecast\u2019s analysis from the first 100-day period of the Coronavirus public health crisis, the report is designed to both offer valuable insights into recent attack trends organisations are challenged with and to serve as a guide to drive continuous improvement to any organisation\u2019s cyber-resilience strategy.<\/p>\n\n\n\n<p>The findings in this year\u2019s State of Email Security report demonstrate that despite high levels of confidence in respondents\u2019 cyber-resilience strategies, there is a clear need for improvement. The large majority (77%) of global respondents say they have or are actively rolling out a cyber-resilience strategy.<\/p>\n\n\n\n<p>In the United Arab Emirates, 80% of respondents are doing the same. Yet an astounding 60% of respondents in the UAE, and globally believe it is inevitable or likely they will suffer from an email-borne attack in the coming year. UAE respondents cite data loss (54%), a decrease in employee productivity (40%) and business downtime (24%) due to a lack of cyber-resilience preparedness.<\/p>\n\n\n\n<p>\u201cWe\u2019re seeing the same threats that organisations have faced for years playing out with tactics matched to world events to evade detection. The increases in remote working due to the global pandemic have only amplified the risks businesses face from these threats, making the need for effective cyber-resilience essential,\u201d said Joshua Douglas, Vice President of Threat Intelligence.<br>\u201cIt\u2019s likely that cyber-resilience strategies are lacking key elements, or don\u2019t have any at all, depending on the organisation\u2019s maturity in cybersecurity. Security leaders need to invest in a strategy that builds resilience moving at the same pace as Digital Transformation. This means organisations must apply a layered approach to email security, one that consists of attack prevention, security awareness training, roaming web security tied to email efficacy, brand exploitation protection, threat remediation and Business Continuity.\u201d<\/p>\n\n\n\n<p>Times are Changing: The threats you can\u2019t see impacting your brand<br>This latest research comes at a time when organisations across the globe have been forced to adopt remote work policies for employees in response to the Coronavirus pandemic. Threat actors have seized this opportunity and evolved the ways they are targeting their victims. Domain-spoofing and email-spoofing have become mainstream attack vectors, according to the report.<\/p>\n\n\n\n<p>Over half of organisations (54%) surveyed, report anticipating an increase in web or email spoofing and brand exploitation in the next 12 months, and it is a rising concern. In fact, 74% of respondents in the UAE feel concerned about a web domain, brand exploitation, or site spoofing attack, and 80% are concerned about an attack that directly spoofs their email domain.<\/p>\n\n\n\n<p>It is critical for organisations to look beyond their email perimeters to determine how cyberthreat actors may be using and damaging their brands online.<\/p>\n\n\n\n<p>Yesterday\u2019s threats are unwavering year over year<br>Similar to years past, impersonation attacks, phishing attempts and ransomware continue to be a major problem, according to the research. Seventy percent of UAE report participants said phishing attacks remained flat or increased in the last 12 months and 68% report the same of impersonation attacks. This indicates that phishing is potentially becoming more difficult to stop or prevent due to more advanced tactics like spear-phishing.<\/p>\n\n\n\n<p>Ransomware also continues to wreak havoc, two-thirds of UAE respondents (66%) said ransomware attacks impacted their organisation, citing data loss, downtime, financial loss and loss of reputation or trust among customers.<\/p>\n\n\n\n<p>The need for a strong human defence<br>The State of Email Security 2020 report also shines a light on the urgent need for a more cyber aware workforce. Encouragingly, 100% of the respondents\u2019 organisations offer security awareness training at varying frequencies and formats. However, 74% of those surveyed reported having been hit by malicious activity spread from employee to employee, pointing to the fact that the format or frequency of these trainings could be the problem.<\/p>\n\n\n\n<p>With frequent, consistent, engaging content that humanizes security, security awareness training is an effective way to reduce risk inside the network and organisation.<br>Download the full State of Email Security 2020 report.<\/p>\n\n\n\n<p><strong>Top 10 takeaways from the State of Email Security 2020 report \u2013 United Arab Emirates<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>Leaders are beginning to understand the email perimeter is constantly under attack. The magnitude and scale of possible attacks at the email gateway is of concern to most; 66% of respondents believe it\u2019s inevitable or likely they will suffer from an email-borne attack in the coming year.<\/li><li>Impersonation, phishing and business email compromise are increasing at a concerning clip. 70% of respondents reported the same or increasing phishing at their organisations, and due to the global pandemic, threat actors are broadly using impersonation and BEC to steal from unsuspecting users. The Mimecast Threat Centre corroborated this assessment \u2013 researchers saw a staggering 30% jump in impersonation globally from January to April 2020.<\/li><li>The effects of ransomware still aren\u2019t improving year over year. More than two thirds of respondents experienced a ransomware attack this year and an average of two days of downtime.<\/li><li>Monthly security awareness training is the best way to train employees. Encouragingly, 36% of respondents receive training monthly, but many aren\u2019t educating employees according to best practices.<\/li><li>In the absence of security awareness training, unsafe URL clicks and data leaks will ensue. Mimecast Threat Centre found that employees from companies not using Mimecast Awareness Training were more than 5X more likely to click on malicious links than employees from companies that did utilise the training. The risk these clicks pose is significant: 74% of respondents were hit by malicious activity spread from employee to employee.<\/li><li>Looking beyond your email perimeter towards online brand protection is a business issue that can no longer be ignored. There\u2019s high awareness of the need to protect your online brand and maintain customer trust, but just because the attacks aren\u2019t visible to you, doesn\u2019t mean they\u2019re not happening. 98% of respondents already use or are planning to roll out a DMARC strategy, but it\u2019s just one piece of the brand protection puzzle.<\/li><li>Budget ownership for online brand protection may shed light on how quickly an organisation can respond to an attack. Nearly all organisations \u2013 98% &#8211; have a dedicated budget for email spoofing, exploitation and impersonation. Who manages the budget, whether it\u2019s the CIO, CISO, CFO, CMO, can vary; what\u2019s critical is the partnership between the budget owner and a savvy cybersecurity leader that leads to the right knowledgebase and tools investment to detect and respond to brand exploit.<\/li><li>You\u2019re right to have growing concern about web and email spoofing. On average, there are six web or email spoofing attacks per organisation each year \u2013 and that\u2019s just what they know about. 54% of respondents anticipate an increase in web or email spoofing in 2020, and around 77% are concerned about direct brand exploitation or email domain spoofing attacks.<\/li><li>If there\u2019s one thing we all agree on, it\u2019s that cyber-resilience strategies are necessary but still incomplete. The majority (80%) have a cyber-resilience strategy or are actively rolling one out, and respondents told us their strategies are stacked with email security, network security, web security, and data backup and recovery solutions. But respondents are still experiencing data loss (54%), a negative impact to employee productivity (40%) and business downtime (24%) due to a lack of cyber-resilience preparedness.<\/li><li>When it comes to delivering world-class security, Office 365 needs more cyber-resilience. While 92% of respondents use Office 365 for email delivery, the impact to their organisations following an outage or other security event created a lasting impression of the need to build in greater resilience with components like email security.<\/li><\/ol>\n","protected":false},"excerpt":{"rendered":"<p>The fourth annual report from Mimecast finds greatest new concern is email and web spoofing. \u00a0 Mimecast, a leading email and data security company, has unveiled its fourth-annual State of Email Security 2020 report. This report summarises details from 1,025 global IT decision makers on the current state of cybersecurity. Providing year-over-year comparisons, along with [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":49197,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,36,809,54,185],"tags":[],"class_list":["post-49196","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-intelligent-technology","category-more-news","category-research","category-uae"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/49196","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=49196"}],"version-history":[{"count":3,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/49196\/revisions"}],"predecessor-version":[{"id":49200,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/49196\/revisions\/49200"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/49197"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=49196"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=49196"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=49196"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}