Abnormal Security’s CISO, Mike Britton consolidates some of the best advice from a three-part webinar series on the current state of risk found in email-based cyberattacks
The threat of email attacks today is so great, it took Abnormal Security three separate webinars just to cover it (and I’d wager they only scratched the surface). In a recent blog, Mike Britton provides the highlights and major takeaways from that webinar series to bring you the nuggets of wisdom that will have a real impact on your cybersecurity strategy’s focus and execution around stopping email-based attacks.
Here are a few of the pearls I pulled from that article:
- Modern threat actors do extensive research on their targets, creating convincing emails that trick employees.
- Compromised credentials (a focus of most phishing campaigns today) provides the threat actor with an ability to access other applications, reset passwords for other accounts, and can act as the basis for launching additional attacks.
- Email will continue to be a primary attack vector for ransomware, because of the breadth of abilities threat actors have to trick recipients into opening attachments.
- Stopping attacks is a shared responsibility. Troy Hunt (of Have I Been Pwned? Fame) said that “requiring employees to complete ongoing security awareness training can help them identify malicious emails that are usually the first step in attacks.”
Take a look at the longer list of key takeaways and realize that anytime email is involved in an attack, so are your users – making it necessary to enroll every one of them in Security Awareness Training to they can play their part in stopping email-based cyberattacks.