Skip to content
The Cyber Security Place

Expert Articles

Its Time to Address Emails Security Gaps

Reported by zivver.com

By Steve Lloyd, Regional Director UKI at Zivver

With employees spending roughly 2.6 hours dealing with 120 business emails each day, emails success as a communication tool is largely due to its simplicity. Such widespread use also creates a massive cyber threat surface, however, resulting in emails unwelcome status as the leading source of data leaks worldwide. Human error is the most frequent cause – an employee accidentally emailing sensitive information to the wrong person, for example. In addition to outbound security vulnerabilities, organisations also face a constant barrage of inbound email threats, such as phishing and business email compromise (BEC) scams.

In this pandemic-prompted era of increased remote working, cybersecurity professionals have the added challenge of making home office technology as secure as office-based systems. And with organisations relying on digital communications especially email – more than ever before, compliance with evolving data protection regulations must be ensured throughout.

So what is the best way forward, in this complex web of cyber threats, risks and vulnerabilities?

Broadly speaking, organisations need to adopt an enabler approach to stem the tide of email data breaches; focusing on security and usability, in equal measure, to help their staff make better and safer decisions when handling sensitive information. From an outbound perspective, the simplest and most effective option is to deploy a secure communication solution that adds a security and privacy layer on top of the enterprises existing email environment, such as Outlook or Gmail. By allowing staff to continue working in their usual way, productivity levels will be maintained, without disruption. A best-practice solution will also provide non-intrusive alerts to guide employees, helping them to avoid accidental data leaks. Alerts which will, for example, ask, Are you sure you want to send this? before an employee emails sensitive financial information to an unknown recipient.

Raising security awareness among staff, and fostering a data privacy-focused culture, is another important step in the prevention of email data leaks. To enable this, organisations need to draw up concise guidelines so that before sending an email employees always ask themselves, Do I really need to send this email? and Does this person really need to be ccd?.

Brand reputation and customer trust are also impacted by emails insecurities. This is exemplified by Oktas recent survey which found that after a company data breach is disclosed over 47% of customers stop using their services entirely. The reality is that trust is hard to earn, but easy to lose, and businesses struggle to regain customer trust after a data leak or cyberattack.

To help address the above-mentioned security shortfalls, we recently formed a new alliance with trusted email identity company, Agari, which enables organisations to protect each users inbox with email defence designed to eliminate email deception. In addition, its brand protection product addresses the specific outbound exploit of domain spoofing/brand hijacking, to ensure that emails which are sent can be trusted by recipients. These capabilities bridge inbound email security gaps, at the same time as supporting our outbound offering, which secures email communications in all three stages of transmission – before, during and after sending via a combination of alerts, two-factor authentication, and zero-knowledge encryption.

By tackling emails insecurities as a matter of urgency, and adopting an enabler approach (supported by best-practice technology), organisations will alleviate at least some of the cyber risk pain-points caused by the ongoing pandemic and help to futureproof the security of their digital communications in the process.

With employees spending roughly 2.6 hours dealing with 120 business emails each day, emails success as a communication tool is largely due to its simplicity. Such widespread use also creates a massive cyber threat surface, however, resulting in emails unwelcome status as the leading source of data leaks worldwide. Human error is the most frequent cause – an employee accidentally emailing sensitive information to the wrong person, for example. In addition to outbound security vulnerabilities, organisations also face a constant barrage of inbound email threats, such as phishing and business email compromise (BEC) scams.

In this pandemic-prompted era of increased remote working, cybersecurity professionals have the added challenge of making home office technology as secure as office-based systems. And with organisations relying on digital communications especially email – more than ever before, compliance with evolving data protection regulations must be ensured throughout.

So what is the best way forward, in this complex web of cyber threats, risks and vulnerabilities?

Broadly speaking, organisations need to adopt an enabler approach to stem the tide of email data breaches; focusing on security and usability, in equal measure, to help their staff make better and safer decisions when handling sensitive information. From an outbound perspective, the simplest and most effective option is to deploy a secure communication solution that adds a security and privacy layer on top of the enterprises existing email environment, such as Outlook or Gmail. By allowing staff to continue working in their usual way, productivity levels will be maintained, without disruption. A best-practice solution will also provide non-intrusive alerts to guide employees, helping them to avoid accidental data leaks. Alerts which will, for example, ask, Are you sure you want to send this? before an employee emails sensitive financial information to an unknown recipient.

Raising security awareness among staff, and fostering a data privacy-focused culture, is another important step in the prevention of email data leaks. To enable this, organisations need to draw up concise guidelines so that before sending an email employees always ask themselves, Do I really need to send this email? and Does this person really need to be ccd?.

Brand reputation and customer trust are also impacted by emails insecurities. This is exemplified by Oktas recent survey which found that after a company data breach is disclosed over 47% of customers stop using their services entirely. The reality is that trust is hard to earn, but easy to lose, and businesses struggle to regain customer trust after a data leak or cyberattack.

To help address the above-mentioned security shortfalls, we recently formed a new alliance with trusted email identity company, Agari, which enables organisations to protect each users inbox with email defence designed to eliminate email deception. In addition, its brand protection product addresses the specific outbound exploit of domain spoofing/brand hijacking, to ensure that emails which are sent can be trusted by recipients. These capabilities bridge inbound email security gaps, at the same time as supporting our outbound offering, which secures email communications in all three stages of transmission – before, during and after sending via a combination of alerts, two-factor authentication, and zero-knowledge encryption.

By tackling emails insecurities as a matter of urgency, and adopting an enabler approach (supported by best-practice technology), organisations will alleviate at least some of the cyber risk pain-points caused by the ongoing pandemic and help to futureproof the security of their digital communications in the process.

Read the full article at zivver.com