Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Applications
    • Applications
    • Cloud
    • Cybersecurity
    • Database
    • IT Management

    Key Trends That Fuel Phishing Inside an Enterprise

    Written by

    Chris Preimesberger
    Published September 7, 2018
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      As we increasingly connect personal email addresses with access to cloud services, web apps and SaaS-based systems, the security of old-fashioned but “killer app” email has become more important than ever. For example, think about all the times you log into a web application of some kind and use your IDs from Facebook, Google, Yahoo or LinkedIn, which are usually email addresses.

      Despite the fact that enterprises have invested billions in cybersecurity training and point solutions, the problems aren’t going away anytime soon.

      The FBI reported that business email compromise (BEC) attacks enabled cybercriminals to steal more than $12 billion from October 2013 to May 2018. In 2017, that represented 48 percent of all internet crime-driven financial loss. Meanwhile, Verizon’s latest Data Breach Investigations Report showed that despite an emphasis on security training, one in 25 people will respond to any given phishing attack – not surprising as they have become both highly targeted and more sophisticated.

      In this eWeek Data Point article, using industry information and data from GreatHorn, which specializes in cloud-native email security, we identify key trends fueling phishing’s success within the enterprise.

      Data Point Trend No. 1:  The Email Perception Gap

      There is a stark difference in the average worker’s perception of email-based threats within the enterprise and the perception of security personnel. Two-thirds of non-security workers claim to never see any email threats besides spam, whereas 56 percent of security professionals see them at least weekly, in the form of impersonations, wire transfer requests, W2 requests, payload attacks/malware, business services spoofing, and credential theft.

      The biggest challenge businesses face in email security is trust. Workers are clearly dismissing all unwanted messages as spam, and often mistakenly believe that their work email systems are inherently secure which makes them highly susceptible to phishing and social engineering attacks, especially as those attacks become more and more sophisticated.

      Data Point Trend No. 2:  Different Infrastructure, Different Email Security Strategies

      The average business uses three separate email security solutions but there are some significant differences in security postures of businesses that use on-premises infrastructure versus cloud-first organizations.

      On-premises companies were far more likely to use stand-alone anti-virus/anti-spam solutions, user awareness training and firewalls than their cloud counterparts. Meanwhile, cloud companies were far more likely to either use nothing, or simply “native cloud-email features.” Google, Microsoft and other cloud providers have significantly improved their security features but outsourcing the entire email security responsibility to cloud providers is a dangerous proposition, because cybercriminals have proven themselves capable of bypassing email filters and other anti-phishing technology.

      Data Point Trend No. 3:  Basic Email Threats are Pervasive

      It’s not just ultra-sophisticated and personalized phishing attacks that reach workers: 1 in 6 see basic payload attacks bypassing their email security defenses, despite being arguably the most heavily guarded against threats. In addition, security professionals report the following:

      • 19 percent report that they have weak or no remediation capabilities if an email threat reaches an end user;
      • 21 percent believe their email security solution negatively impacts business operations (e.g. too many false-positives);

      So not only are rudimentary email threats successful, but the security strategies organizations use are impeding the business. Meanwhile, the lack of good remediation options built into email security strategies make it difficult to mitigate the damage.

      Data Point Trend No. 4:  Impersonations are Still Phishers’ Weapon of Choice

      Overall, nearly half (46 percent) of all business professionals see executive, internal, or external impersonations, with that number jumping to 65 percent among email security professionals. Business services spoofing was the second most prevalent email threat respondents experience, followed by wire transfers, credential theft, and payload/malware.

      Data Point Trend No. 5:  Phishing Overwhelms Security Pros

      Sixty-five percent of respondents reported fundamental technical issues with their existing email security solution. This figure, taken with the fact that two-thirds of email security professionals acknowledge that email threats make it past defenses and into inboxes, demonstrates the failure of the binary email security philosophy that has dominated the industry. It’s not reasonable to believe that enterprise can stop 100 percent of all potential threats while simultaneously delivering a low false positive rate. Enterprises should assume that some amount of malicious mail will always find a way to reach employees–regardless of the company’s security posture.

      Data Point No. 6:  Summary

      Cybercriminals’ window of opportunity becomes a barn door if IT and security professionals aren’t implementing basic email security hygiene. Forty percent of business professionals need to routinely take significant remediation actions – such as Powershell scripts, shutting down compromised inboxes, etc. – to counter basic attacks that are delivered to their inbox.

      A Sisyphean mindset has created complacency around how good email security can really be. Nearly half of all respondents (46 percent) were “less than satisfied” with their current email security solution, with only 10 percent indicating they were “very satisfied.”  Senior-level executives agreed and were much more likely to be actively “dissatisfied” or “very dissatisfied” by their email security solution (20 percent compared to 12 percent for the general population).

      If you have a suggestion for an eWEEK Data Point article, email [email protected].

      Chris Preimesberger
      Chris Preimesberger
      https://www.eweek.com/author/cpreimesberger/
      Chris J. Preimesberger is Editor Emeritus of eWEEK. In his 16 years and more than 5,000 articles at eWEEK, he distinguished himself in reporting and analysis of the business use of new-gen IT in a variety of sectors, including cloud computing, data center systems, storage, edge systems, security and others. In February 2017 and September 2018, Chris was named among the 250 most influential business journalists in the world (https://richtopia.com/inspirational-people/top-250-business-journalists/) by Richtopia, a UK research firm that used analytics to compile the ranking. He has won several national and regional awards for his work, including a 2011 Folio Award for a profile (https://www.eweek.com/cloud/marc-benioff-trend-seer-and-business-socialist/) of Salesforce founder/CEO Marc Benioff--the only time he has entered the competition. Previously, Chris was a founding editor of both IT Manager's Journal and DevX.com and was managing editor of Software Development magazine. He has been a stringer for the Associated Press since 1983 and resides in Silicon Valley.
      Linkedin Twitter

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.