{"id":129116,"date":"2016-07-05T08:57:20","date_gmt":"2016-07-05T06:57:20","guid":{"rendered":"http:\/\/businesstech.co.za\/news\/?p=129116"},"modified":"2016-07-05T08:57:20","modified_gmt":"2016-07-05T06:57:20","slug":"cyber-security-is-a-battle-of-the-people-versus-email-scammers","status":"publish","type":"post","link":"https:\/\/businesstech.co.za\/news\/industry-news\/129116\/cyber-security-is-a-battle-of-the-people-versus-email-scammers\/","title":{"rendered":"Cyber security is a battle of the people versus email scammers"},"content":{"rendered":"<p>The \u2018Nigerian Prince\u2019 or \u2018419\u2019 email scams we\u2019ve all seen take advantage of the age-old premise: people can be greedy and gullible.<\/p>\n<p>Or to put it more positively \u2013 people are intrinsically positive about the motives of others and are not on the lookout for scammers and criminals in every email exchange.<\/p>\n<p>But the sad truth is we all need to wake up to the threat in our email. To heighten our security awareness.<\/p>\n<p>The world has moved on and despite significant security efforts and new technologies in recent years, there remains a prolific and lucrative cybercrime industry attacking people and organizations alike.<\/p>\n<p>Today the weakest link in any security defenses are people, so protecting data and systems also means protecting people.<\/p>\n<p>The recent history of cyber security shows that all too often it is the employee that opens an organisation up to attack.<\/p>\n<p>In most cases (despite high profile insider attacks like Snowden in the US) employees are not willingly participating in an attack.<\/p>\n<p>They may not even know they are the unwelcome target of a hacker\u2019s attention and that their online behaviour might be risky.<\/p>\n<p>Employees have limited knowledge of the cyber security risks they face (or create).<\/p>\n<p>Email scams take advantage of this lack of security knowledge.<\/p>\n<p>The cost to an organisation of this knowledge gap is an increased security threat.<\/p>\n<p>Cyber security is a constant game of cat and mouse.<\/p>\n<p>As people woke up to the threat from simple email scams like the \u2018Nigerian Prince\u2019 its effectiveness declined so the attackers moved onto new techniques.<\/p>\n<p>Phishing in its many forms has grown in popularity.<\/p>\n<p>Here the attacker sends email to lots of people with a malicious web link to steal credentials for logins or a malware-laden attachment to infect a machine.<\/p>\n<p>They know that someone will click through and activate their attack.<\/p>\n<p>Then there is spear-phishing, where targets are more carefully targeted to improve effectiveness and a new, and damaging, variant of this called CEO Fraud or whaling where social engineering is used to really target a specific individual within a target organisation.<\/p>\n<p>Individual emails are created that look legitimate, they often even get into a conversation with the target pretending to be their boss, before hitting them up for fraudulent wire transfers of cash or confidential data.<\/p>\n<p>These attacks on email are on the rise and are a significant concern.<\/p>\n<p><a href=\"https:\/\/www.mimecast.com\/email-threat-report-2016\" target=\"_blank\">Recent research from Mimecast<\/a> showed that 83% of IT security pros consider email to be the most common source of the attack and 64% believing the attacks to pose a high or extremely high threat.<\/p>\n<p>These attacks also work. Sad but true.\u00a0 People are being duped every day.<\/p>\n<p>The FBI reported recently in the U.S. that losses from whaling or CEO fraud attacks alone grew by 270 percent from January to August 2015 with reported losses of $800 million in just six months from August 2015.<\/p>\n<p>Mimecast&#8217;s <a href=\"https:\/\/www.mimecast.com\/blog\/2016\/04\/today-technology-can-help-stop-whaling-email-attacks\/\" target=\"_blank\">own research<\/a> showed that in the first three months of 2016, 67% of organisations had seen an increase in attacks designed to extort fraudulent payments and 43% saw an increase in attacks specifically asking for confidential data like HR records or tax information.<\/p>\n<p>Clearly investing in up-to-date technology to defend your organisation is critical but remember that employees are the first line of defense and educating them regularly about potential cyberattacks is vital.<\/p>\n<p>As is telling them what to do when they spot a problem or feel they many have been duped.<\/p>\n<p>A culture that encourages and supports employees in being open (and fast to act) when they have made a mistake is important.<\/p>\n<p>So in the battle of organizations versus the email scammers, it will be employees armed with great technology that will make the difference.<\/p>\n<p><em>By Brandon Bekker, MD of Mimecast South Africa.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In the battle of organizations versus the email scammers, it will be employees armed with great technology that will make the difference.<\/p>\n","protected":false},"author":46,"featured_media":129118,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10459],"tags":[1320,4070,4426,26,3015,11528,11526],"class_list":["post-129116","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industry-news","tag-cyber-security","tag-cybersecurity","tag-data-security","tag-headline","tag-it-security","tag-mimecast","tag-mimecast-south-africa"],"_links":{"self":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/129116","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/users\/46"}],"replies":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/comments?post=129116"}],"version-history":[{"count":1,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/129116\/revisions"}],"predecessor-version":[{"id":129120,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/129116\/revisions\/129120"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/media\/129118"}],"wp:attachment":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/media?parent=129116"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/categories?post=129116"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/tags?post=129116"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}