As part of his SANS Technology Institute Master's degree, Geoffrey Parker recently published a whitepaper called Automating Response to Phish Reporting that got an A, was made a gold paper and got published in the SANS InfoSec Reading Room.
It's an excellent independent analysis of available email triage tools, and covers:
Here is the abstract:
"Phish Reporting buttons have become easy buttons. They are used universally for reporting spam, real phishing attacks when detected, and legitimate emails. Phish Reporting buttons automate the reporting process for users; however, they have become a catch-all to dispose of unwanted messages and are now overwhelming Response Teams and overflowing Help Desk ticket queues.
The excessive reporting leads to a problem of managing timely responses to real phishing attacks. Response times to false positives, spam, and legitimate messages incorrectly reported are also significant factors. Vendors sold phish alert buttons with phishing simulation systems which then became part of more in-depth training systems and later threat management systems.
Because of this organic growth, many companies implemented a phish reporting system but did not know that they needed an automation system to manage the resulting influx of tickets. Triage systems can automate a high percentage of these phish alerts, freeing the incident response teams to deal with the genuine threats to the enterprise on a prioritized basis."
We warmly recommend this excellent whitepaper. Read it here at SANS.
Find out how adding PhishER can be a huge time-saver for your Incident Response team.
Date/Time: Wednesday, July 24 @ 2:00 pm (ET)
Save My Spot!
https://event.on24.com/wcc/r/2018396/91E93646DDA057B561EB41A24725B538?