Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

10/7/2013
07:27 PM
50%
50%

Technology Or Education? Tackling Phishing Requires Both

Neither technology nor awareness services can solve the phishing threat, but using both can significantly reduce attackers' success

Cybercriminals typically steal data using a triad of techniques--malware, hacking, and tampering with hardware.

The arguably more serious espionage attacks aimed at robbing companies of their intellectual property, however, have a slightly different triumvirate of threats, dropping the physical theft of hardware in favor of socially engineering the human side of the business, according to Verizon's 2013 Data Breach Investigations Report. In fact, 95 percent of all state-affiliated espionage attacks include a phishing component, the report's review of 47,000 data-security incidents found.

For companies, the data highlights a weakness in their network security: Even with near-ubiquitous anti-spam technologies guarding most inboxes, spearphishing attacks get delivered. And that puts the workers on the front lines, because every user could be put in a position of defending, or infecting, the business's network, says Trevor Hawthorn, chief technology officer of phishing-awareness service provider ThreatSim.

"Our customers are doing a lot of the right things that they are supposed to be doing [to filter out phishing], but they are still getting a high number of phishing messages," he says. "At that point, the end user becomes the last element of defense."

Phishing awareness allows companies to regularly test employees, raise the awareness of those employees who fail the test, and teach workers proper incident response, such as reporting phishing attempts. Phishing service firms give companies regular reports on how their employees performed in the tests and offer other metrics, such as how quickly employees reported a phishing e-mail.

[From fully undetectable malware to low-volume targeted trojans, digital threats frequently do not have a signature, but companies can still prepare. See 3 Steps To Secure Your Business In A Post-Signature World.]

Yet, while having more security-conscious users is a laudable goal, some security experts question whether it will make a difference as to whether a business suffers a breach. Finding a user who will click on a link in a well-crafted e-mail is a numbers game: Eventually, the attackers will succeed, says Kenneth Geers, senior global threat analyst with anti-malware provider FireEye.

"The thing with social engineering is, that if the attackers have done their homework, everyone is going to click," he says.

While current data suggests that a technology-only and an education-only approach both have flaws, they both reduce risk as well. With regular phishing-awareness campaigns, companies have generally reduced the success of the attacks to the single-digit percentiles, according to ThreatSim. Another phishing-education service, PhishMe, has seen similar results.

Another hopeful trend: Companies are starting to see their employees reporting the phishing attacks before their less security-conscious colleague click on the link, says Aaron Higbee, chief technology officer of PhishMe. Lengthening the time between report and click give the company's incident response team more time to find and eliminae similar attacks.

"It gives their incident response team a head start of 20 or 30 minutes," he says.

On the technology side, sandboxing and virtual analysis environments are improving and are better able to jail potentially malicious files and protect systems from attack. So, adopting both approaches can deepen defenses and result in a cumulative reduction in risk, says ThreatSim's Hawthorn.

"Security not about zero percent risk," he says. "I don't think there is a security control out there that guarantees anyone to have a zero percent chance of compromise. But by focusing on your biggest risks, and using defense in depth, you can have the most impact."

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message. Veteran technology journalist of more than 20 years. Former research engineer. Written for more than two dozen publications, including CNET News.com, Dark Reading, MIT's Technology Review, Popular Science, and Wired News. Five awards for journalism, including Best Deadline ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Peter Fretty
50%
50%
Peter Fretty,
User Rank: Moderator
10/24/2013 | 6:43:19 PM
re: Technology Or Education? Tackling Phishing Requires Both
Such an important message for people to understand. Security success is always multifaceted. Tools (i.e. firewalls, UTM appliances, etc.) protect when people are unaware and education keeps people from slipping and inadvertently providing otherwise authorized access. Eduction needs to be the foundation.

Peter Fretty, IDG blogger working on behalf of Sophos
7 Tips for Infosec Pros Considering A Lateral Career Move
Kelly Sheridan, Staff Editor, Dark Reading,  1/21/2020
For Mismanaged SOCs, The Price Is Not Right
Kelly Sheridan, Staff Editor, Dark Reading,  1/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment:   It's a PEN test of our cloud security.
Current Issue
IT 2020: A Look Ahead
Are you ready for the critical changes that will occur in 2020? We've compiled editor insights from the best of our network (Dark Reading, Data Center Knowledge, InformationWeek, ITPro Today and Network Computing) to deliver to you a look at the trends, technologies, and threats that are emerging in the coming year. Download it today!
Flash Poll
How Enterprises are Attacking the Cybersecurity Problem
How Enterprises are Attacking the Cybersecurity Problem
Organizations have invested in a sweeping array of security technologies to address challenges associated with the growing number of cybersecurity attacks. However, the complexity involved in managing these technologies is emerging as a major problem. Read this report to find out what your peers biggest security challenges are and the technologies they are using to address them.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-5226
PUBLISHED: 2020-01-24
Cross-site scripting in SimpleSAMLphp before version 1.18.4. The www/erroreport.php script allows error reports to be submitted and sent to the system administrator. Starting with SimpleSAMLphp 1.18.0, a new SimpleSAML\Utils\EMail class was introduced to handle sending emails, implemented as a wrapp...
CVE-2019-1517
PUBLISHED: 2020-01-24
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.
CVE-2019-1518
PUBLISHED: 2020-01-24
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.
CVE-2019-1519
PUBLISHED: 2020-01-24
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.
CVE-2019-1520
PUBLISHED: 2020-01-24
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.