{"id":141577,"date":"2016-10-28T08:33:30","date_gmt":"2016-10-28T06:33:30","guid":{"rendered":"http:\/\/businesstech.co.za\/news\/?p=141577"},"modified":"2016-10-28T08:33:30","modified_gmt":"2016-10-28T06:33:30","slug":"expert-tips-to-protect-your-organisation-from-people-hacking","status":"publish","type":"post","link":"https:\/\/businesstech.co.za\/news\/industry-news\/141577\/expert-tips-to-protect-your-organisation-from-people-hacking\/","title":{"rendered":"Expert tips to protect your organisation from \u2018people hacking\u2019"},"content":{"rendered":"<p>91% of Cyber-attacks <a href=\"http:\/\/tracker.mybroadband.co.za\/track.php?page=aHR0cDovL2luZm8ubWltZWNhc3QuY29tL3NuYXAtb3V0LW9mLWl0LXNlY3VyaXR5Lmh0bWw_dXRtX21lZGl1bT1EaXNwbGF5QWR2ZXJ0aXNpbmcmdXRtX3NvdXJjZT1NeUJyb2FkYmFuZCZ1dG1fY2FtcGFpZ249MzcwMDE0MzQ?source=Article%201%20of%201\">start with an email<\/a>, and the people in your organisation are your weakest link.<\/p>\n<p>Companies are being attacked by malicious cyber criminals with more frequency and sophistication than ever before, said Jenny Radcliffe &#8211; aka \u2018The People Hacker\u2019.<\/p>\n<p>Speaking that the Mimecast 2016 event, Radcliffe explained that these attackers are becoming more adept at getting people in organisations to help them circumvent security controls.<\/p>\n<p>\u201cSecurity technologies are becoming more and more effective, and as a result, social engineering attacks are becoming more complex than ever before,\u201d she said.<\/p>\n<p>Social engineering is aimed at exploiting people as the weakest link in the information security chain.<\/p>\n<p>\u201cPeople are easier to hack than technology is, and we are seeing a new breed of attackers who appear to be trained in psychology.<\/p>\n<p>\u201cThey are using that to get people in organisations to help them circumvent security controls.\u201d<\/p>\n<p>This approach can take many forms, including physical access to buildings, email phishing and telephone calls to engage insiders and build trust relationships.<\/p>\n<h3 class=\"my-4\"><strong>How social engineering endangers your security<\/strong><\/h3>\n<p>Social engineering attack planning typically involves building a profile of the target organisation and its employees.<\/p>\n<p>Hackers use sources such as corporate websites, industry forums and social media sites, including Facebook, Twitter and LinkedIn to gather information.<\/p>\n<p>\u201cAttackers will then seek to build a trust relationship with an individual or individuals within the organisation over a longer period \u2013 even up to six months,\u201d said Radcliffe.<\/p>\n<p>This makes it possible for attackers to identify the easiest way in and to manipulate employees of an organisation to help them gain access to the information they seek.<\/p>\n<p>\u201cBecause it is not a technical attack, attackers don\u2019t even necessarily need technology to hack a person,\u201d Radcliffe added.<\/p>\n<p>\u201cIn some cases, hackers will bump into your employees in the real world, by tracking where they socialise after hours, for example, and build a relationship with them in person.\u201d<\/p>\n<h3 class=\"my-4\"><strong>Tips to protect your people and your organisation<\/strong><\/h3>\n<p>These attacks can cause huge financial losses and could cost you your reputation and your business, so Radcliffe\u2019s first tip is to admit that your organisation is vulnerable.<\/p>\n<p>\u201cIt can happen to your company too,\u201d she warned. \u201cIf you deny that this could affect you, you have painted a huge target on your back.\u201d<\/p>\n<p>She adds that the human element has always been a major vulnerability, and people have always been the quickest way in.<\/p>\n<p>\u201cFor this reason, people need training and they need to understand that the attack will be personal to them.\u201d<\/p>\n<p>Most staff do not consider security to be their problem, rather believing that the IT team is protecting them from cybercrime.<\/p>\n<p>\u201cBut each employee is a conduit and a way in, so you need to drop the culture of blame and instead create a culture of awareness,\u201d she explained.<\/p>\n<p>\u201cCulture will determine the type of attack you will get, and if you have a culture of blame, fear will be used to get into your organisation.\u201d<\/p>\n<p>Radcliffe advises having \u2018security moments\u2019 in meetings where people can bring their own stories and start a narrative, as this will engage them in the process.<\/p>\n<p>\u201cYou will get a lot of complaining, reluctant feedback and false positives, but it is a good start and this costs nothing to implement,\u201d she said.<\/p>\n<p>Also ensure that employees are wary of any new acquaintances who attempt to build trust very rapidly.<\/p>\n<p>\u201cTrain your employees to be wary of anyone who seems particularly easy to talk to and who seems particularly interested in them, their jobs and their organisation,\u201d she added.<\/p>\n<p>\u201cThey should be trained to be careful about what they disclose and how they co-operate with outsiders.\u201d<\/p>\n<p>Employees should even be wary of job offers from unknown people who are keen to discuss their current role, experience and areas of expertise.<\/p>\n<p>This is one way attackers can use to engage employees of an organisation to find out what kinds of information security systems are deployed.<\/p>\n<h3 class=\"my-4\"><strong>Protecting your email from phishing<\/strong><\/h3>\n<p>Considering that 91% of hacking attacks begin with phishing or spear-phishing, are your defenses ready?<\/p>\n<p>It can take 229 days before your business realizes it\u2019s been breached, and that\u2019s a dangerously long time for cybercriminals to have access to your customer\u2019s private information.<\/p>\n<p>Your organization can&#8217;t afford a disruption to business operations \u2014 breaches cost millions and destroy reputations.<\/p>\n<p>Even with training, 23% of phishing emails are still opened, so protecting the company against human error is a top priority.<\/p>\n<p><a href=\"http:\/\/tracker.mybroadband.co.za\/track.php?page=aHR0cDovL2luZm8ubWltZWNhc3QuY29tL3NuYXAtb3V0LW9mLWl0LXNlY3VyaXR5Lmh0bWw_dXRtX21lZGl1bT1EaXNwbGF5QWR2ZXJ0aXNpbmcmdXRtX3NvdXJjZT1NeUJyb2FkYmFuZCZ1dG1fY2FtcGFpZ249MzcwMDE0MzQ?source=Article%201%20of%201\">Mimecast Email Security services<\/a> are a critical defense to protect against advanced threats and data loss.<\/p>\n<p>Mimecast solves critical email security issues with:<\/p>\n<ul>\n<li>Targeted threat protection<\/li>\n<li>Spam and multi-layered malware protection<\/li>\n<li>Secure messaging and encryption<\/li>\n<li>Data leak prevention<\/li>\n<li>Secure large file sharing<\/li>\n<\/ul>\n<p>The Mimecast cloud-based service means always-on, always up-to-date protection without the complexity and cost of traditional offerings.<\/p>\n<p>Added benefits of email cloud services provided by Mimecast include flexible and granular email security controls.<\/p>\n<p>For more information, visit the <a href=\"http:\/\/tracker.mybroadband.co.za\/track.php?page=aHR0cDovL2luZm8ubWltZWNhc3QuY29tL3NuYXAtb3V0LW9mLWl0LXNlY3VyaXR5Lmh0bWw_dXRtX21lZGl1bT1EaXNwbGF5QWR2ZXJ0aXNpbmcmdXRtX3NvdXJjZT1NeUJyb2FkYmFuZCZ1dG1fY2FtcGFpZ249MzcwMDE0MzQ?source=Article%201%20of%201\">Mimecast website<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>91% of Cyber-attacks start with an email, and the people in your organisation are your weakest link.<\/p>\n","protected":false},"author":46,"featured_media":141579,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10459],"tags":[26,11528,11526],"class_list":["post-141577","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industry-news","tag-headline","tag-mimecast","tag-mimecast-south-africa"],"_links":{"self":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/141577","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/users\/46"}],"replies":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/comments?post=141577"}],"version-history":[{"count":1,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/141577\/revisions"}],"predecessor-version":[{"id":141581,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/141577\/revisions\/141581"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/media\/141579"}],"wp:attachment":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/media?parent=141577"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/categories?post=141577"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/tags?post=141577"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}