Why are we still talking about email security?

By : Krishna Anindyo | Thursday, February 27 2020 - 14:08 IWST

CloudGuard SaaS (Images by Check Point Software)
CloudGuard SaaS (Images by Check Point Software)

INDUSTRY.co.id - It was 1971 when Roy Tomlinson sent the first email across a network. Almost 40 years ago, he used the sign for the first time to denote a separation between the recipient’s name and their machine name when he sent his message.

Since then, with the rapid adoption of the internet and then the mobile internet, the email security market matured as enterprises understood that accessing proprietary information via the network exposed them to cyber security risks.

It might therefore seem surprising that almost 40 years since the world’s first networked electronic mail was sent, Verizon’s 2019 Data Breach Investigations Report called out phishing as the main cyber security threat facing enterprises in the digital world.

Gartner’s findings support this - in their Fighting Phishing Report, they found that 90% of cyber threats against enterprises start with email, making email the attack threat vector against enterprises. That’s right, phishing has been identified as one of the main mechanisms used to execute the delivery phase of the attack kill chain.

Enterprise email security is a mature market, which poses the obvious question of why cyber criminals are still using emails as an attack vector, and how it’s possible in a mature market for these schemes to reach such a high success rate. Are email security solutions ineffective, or are the adversaries just very smart at circumventing email security controls?

Recent years have seen a rapid shift to cloud based email providers – whether that’s moving existing office suite capabilities to the equivalent cloud based office suites (think an on-prem Microsoft Office and Exchange moving to Office 365), or new organizations starting with a cloud installation.

Private end users don’t spend any time worrying about the risks involved in relying on the default security built into cloud email providers but there are inherent vulnerabilities in cloud office suite solutions which could keep any CISO up at night.

And what of the small to medium sized organisations who don’t have a CISO or security team, but leave email security to the IT administrator?

Are the IT managers giving a thought to the risks posed to the organisation once their email and file storage are both moved to the cloud? Multi factor log-ins won’t defend their end users from the phishing schemes which are seeing so much success that cyber criminals are continually increasing their phishing efforts.

The risks to organisations who move their office suites to the cloud are partially addressed by CASB solutions, but these don’t address the dangers associated with mailboxes in the cloud.

So what’s a cloud native organisation to do? How can you make sure that you don’t fall victim to the ‘clickbait’ which is responsible for 90% of enterprise breaches? As the new decade dawns, IT managers and CISOs have an array of email security options to choose from, but picking the right one can be a daunting prospect.

 

 

News Comment

Today's Industry

World Bank Group (Images by ITU)

Kamis, 05 Maret 2020 - 07:23 WIB

World Bank Group Announces Up to $12 Billion Immediate Support for Covid-19 Country Response

As Covid-19 reaches more than 60 countries, the World Bank Group is making available an initial package of up to $12 billion in immediate support to assist countries coping with the health and…

Association of International Certified Professional Accountants (Images by Irish Times Executive Jobs)

Rabu, 26 Februari 2020 - 12:48 WIB

Global Accounting Leaders Call on Profession to Help Address Climate Change

As part of The Prince’s Accounting for Sustainability Project (A4S) Accounting Bodies Network, which collectively represents over 2.5 million accountants and students worldwide, 14 major accounting…

HackerOne (Images by Tekno Tempo.co)

Selasa, 25 Februari 2020 - 16:00 WIB

Hacking as a Career Soars in Popularity According to HackerOne’s 2020 Hacker Report

HackerOne, hacker-powered pen-test & bug bounty platform, today announced findings from the 2020 Hacker Report, which reveals that the concept of hacking as a viable career has become a reality,…

Google Play Store (Images by Brands of the World)

Selasa, 25 Februari 2020 - 13:05 WIB

Is the Google Play Store Safe? Not Yet.

Over recent years, there has been a lot of activity on Google’s part to improve the security of its Google Play app store. Why? Because millions of users have inadvertently downloaded thousands…

Cyber Attack (Images by IDN Times Jabar)

Jumat, 21 Februari 2020 - 09:09 WIB

Cyber Attack Fears are Delaying Business Innovation

Survey conducted by bug bounty and pentesting platform, HackerOne, has revealed that IT projects are being stifled due to security concerns. More than 80% of UK CISOs and CTOs who were interviewed…