{"id":206328,"date":"2017-10-19T14:19:22","date_gmt":"2017-10-19T12:19:22","guid":{"rendered":"https:\/\/businesstech.co.za\/news\/?p=206328"},"modified":"2017-10-23T09:10:02","modified_gmt":"2017-10-23T07:10:02","slug":"why-phishing-attacks-are-so-effective","status":"publish","type":"post","link":"https:\/\/businesstech.co.za\/news\/industry-news\/206328\/why-phishing-attacks-are-so-effective\/","title":{"rendered":"Why phishing attacks are so effective"},"content":{"rendered":"<p>An alarming 91% of hacking attempts today begin with some kind of phishing attack, which uses email and social-engineering to gain access to confidential data.<\/p>\n<p>Hackers attempt to dupe recipients into opening an attachment, clicking on a link, divulging confidential information or even wiring money to a fraudulent account.<\/p>\n<p>&#8220;What makes these attacks so effective is that social engineering, effectively hacking the human brain, is actually quite easy to do,&#8221; Dr Bright Gameli Mawudor, Head of Cyber Security Solutions\u00a0\u2013 Internet Solutions, Kenya.<\/p>\n<p>Mawudor was speaking about\u00a0<em>Social Engineering &#8211; how it works and how it gets used<\/em> at the <em>Mimecast: Anatomy of an Email-Bourne Attack<\/em> presentation at the 2nd Annual AfriSecure Cyber Security Summit in Johannesburg.<\/p>\n<p>&#8220;As human beings, we are very open especially on social media, and all this information is incredibly valuable to hackers,&#8221;\u00a0Mawudor said. &#8220;We are the problem. People are the problem.&#8221;<\/p>\n<p>Essentially, it is human nature that makes us so vulnerable &#8211; we desire to be helpful, have a tendency to trust people we don&#8217;t know, and have a fear of getting into trouble, which are all traits that social engineers are able to capitalise on.<\/p>\n<p>Social engineers are able to create confidence that they are who they say they are and that they are legitimately seeking information.<\/p>\n<p>Even people who don&#8217;t consider themselves to be trusting by nature are vulnerable when presented with\u00a0the right story, the right voice, the right speech pattern, the right body language, and so forth.<\/p>\n<p>The reason phishing attacks are often successful is because it usually appears to come from a known or trusted source, often impersonating a C-level executive.<\/p>\n<p>As such, phishing email attacks can be remarkably difficult to identify, and even when employees are trained how to spot a possible phishing attack or CEO Fraud, 23% of phishing emails are still open.<\/p>\n<p>With the potential for phishing scams to cause disruption to business operations, damage to reputation and loss of business costing millions of dollars, organizations urgently need a sophisticated solution for preventing a phishing attack.<\/p>\n<p>&#8220;It&#8217;s not just about potential monetary loss, as this can often be recovered &#8211; it is reputational damage that is very difficult to recover from,&#8221; warned\u00a0Brandon Bekker, Mimecast South Africa MD.<\/p>\n<p>&#8220;The world is changing and email has become a successful place for cybercriminals to operate as it is far easier to hack a person than a system.&#8221;<\/p>\n<p>Mimecast Targeted Threat Protection provides a highly effective solution for preventing a phishing attack.<\/p>\n<p>It defends against malicious links in email, weaponised attachments and social-engineering attacks to protect users and organizations from the dangers of advanced threats.<\/p>\n<p>Mimecast improves phishing email and spear security by scanning all inbound emails in real-time, providing three levels of protection:<\/p>\n<ul>\n<li>URL Protect scans all URLs within incoming and archived emails, identifying websites that are potential risks before opening a clicked link in the user\u2019s browser.<\/li>\n<li>Attachment Protect opens attachments in a virtual environment or sandbox that is isolated from the corporate email system, and enables employees to access it only once it passes security checks.<\/li>\n<li>Impersonation Protect scans incoming email to identify potential malware-less attacks that use social-engineering to spoof employees into making fraudulent wire transfers.<\/li>\n<\/ul>\n<p>&#8220;We believe it is very important to have a layered approach to email security, as this is how even physical security systems work,&#8221; explained Bekker.<\/p>\n<p>&#8220;Your business most likely has multi-layered security, with guards or access control, electric fencing, alarms, CCTV, and more. When it comes to security, a multi-layered approach simply makes sense.&#8221;<\/p>\n<p>With Mimecast Targeted Threat Protection, organisations can prevent a phishing attack, spear phishing attack or whale phishing threat without the need for additional infrastructure or IT overhead.<\/p>\n<p>You can also add instant protection for all devices with no disruption to end-users, activate the service quickly through Mimecast\u2019s cloud platform, and improve insight with end-to-end, real-time threat analysis and granular reporting.<\/p>\n<p>&#8220;It actually only takes one person to be compromised in a network to compromise the entire organisation,&#8221; concludes\u00a0Mawudor.<\/p>\n<p>&#8220;Because employees are so vulnerable, education is essential, but you can&#8217;t rely on that alone &#8211; you also need a system in place, such as what Mimecast offers, to keep your network and organisation safe.<\/p>\n<p>Learn more about stopping a phishing attack or CEO Fraud and about Mimecast\u2019s solution for <a href=\"http:\/\/tracker.mybroadband.co.za\/\/track.php?page=aHR0cHM6Ly93d3cubWltZWNhc3QuY29tL2NvbnRlbnQvc3BhbS1lbWFpbC1wcm90ZWN0aW9u?source=Article%202%20of%206\" target=\"_blank\" rel=\"noopener\"><strong>spam email protection<\/strong><\/a> and <a href=\"http:\/\/tracker.mybroadband.co.za\/\/track.php?page=aHR0cHM6Ly93d3cubWltZWNhc3QuY29tL2NvbnRlbnQvcmFuc29td2FyZS1kZXRlY3Rpb24?source=Article%202%20of%206\" target=\"_blank\" rel=\"noopener\"><strong>ransomware detection<\/strong><\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>An alarming 91% of hacking attempts today begin with some kind of phishing attack, which uses email and social-engineering to gain access to confidential data.<\/p>\n","protected":false},"author":46,"featured_media":206350,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10459],"tags":[26,11528,11526],"class_list":["post-206328","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industry-news","tag-headline","tag-mimecast","tag-mimecast-south-africa"],"_links":{"self":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/206328","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/users\/46"}],"replies":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/comments?post=206328"}],"version-history":[{"count":2,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/206328\/revisions"}],"predecessor-version":[{"id":206737,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/206328\/revisions\/206737"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/media\/206350"}],"wp:attachment":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/media?parent=206328"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/categories?post=206328"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/tags?post=206328"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}