Posts

Showing posts with the label Email

Throwback Thursday - koalas and magnetographics

Image
This week, I'm thoroughly engrossed by a deep dive into ISO/IEC 2382, a suite of standards on IT terminology from the 1990's around the end of the previous millennium - ancient history as far as IT goes. "ISO 2382 was initially based mainly on the usage to be found in the Vocabulary of Information Processing which was established and published by the International Federation for Information Processing and the International Computation Centre, and in the American National Dictionary for Information Processing Systems and its earlier editions published by the American National Standards Institute (formerly known as the American Standards Association). Published and Draft International Standards relating to information technology of other international organizations (such as the International Telecommunication Union and the International Electrotechnical Commission) as well as published and draft national standards have also been considered." I say "IT" but it...

Phishing evolution

Image
The Interweb drums have been beating out news of an upsurge in phishing attacks over the past month or so. I’ve certainly had more than the normal number of things along these lines lately:     As usual, these are relatively crude and (for most reasonably alert people) easy to spot thanks to the obvious spelling and grammatical errors, often using spurious technobabble and urgency as well as the fake branding and sender email address in an attempt to trick victims.   The ‘blocked emails’ and ‘storage limit’ memes are popular in my spam box right now, suggesting that these are basic phishing-as-a-service or phishing-kit products being used by idiots to lure, hook, land and gut other idiots.   They are, however, using my first name in place of “Dear subscriber” or “Hello, how are you doing?” that we used to see, implying the use of mailmerge-type content customisation with databases of email addresses and other info on potential victims*. Moving up the scale, some curr...

Working off-site

Image
We're rapidly spiralling-in on a scope, purpose and hence title for the next security awareness and training module, currently extruding its way through the awareness module sausage machine at IsecT HQ. Inspired by a customer request to cover the security aspects of 'home working', we set out to complement the BYOD and business continuity topics ... but in exploring the associated information risks and controls, we've realized that there are other ways and means of working with similar issues.  Mobile or portable working, for example, is almost the rule for managers and professionals these days, at least to the extent of being constantly in touch by cellphone, keeping up with emails and TXT messages, and using work apps on smartphones, laptops and tablet PCs. Commuters on public transport often seem totally absorbed by their screens and ear-buds, whether that's personal or work emails, podcasts, news from the city desk, Harry Potter, Game of Thrones, Bach or BoyZone...

SEC begets better BEC sec

According to an article on CFO.com by Howard Scheck , a former chief accountant of the US S ecurities and E xchange C ommission’s Division of Enforcement:  "Public companies must assess and calibrate internal accounting controls for the risk of cyber frauds. Companies are now on notice that they must consider cyber threats when devising and maintaining a system of internal accounting controls." A series of B usiness E mail C ompromise frauds (successful social engineering attacks) against US companies evidently prompted the SEC to act. Specifically, according to Howard: "The commission made it clear that public companies subject to Section 13(b)(2)(B) of the Securities Exchange Act — the federal securities law provision covering internal controls — have an obligation to assess and calibrate internal accounting controls for the risk of cyber frauds and adjust policies and procedures accordingly." I wonder how the lawyers will interpret that obligation to 'assess...

Go ahead, make my day

Image
What can be done about the semi-literate reprobates spewing forth this sort of technobabble nonsense via email?  "hello, my prey. I write you since I attached a trojan on the web site with porn which you have visited. My malware captured all your private data and switched on your camera which recorded the act of your wank. Just after that the malware saved your contact list. I will erase the compromising video records and data if you pay me 350 EURO in bitcoin. This is wallet address for payment : [string redacted] I give you 30h after you view my message for making the transaction. As soon as you read the message I'll know it immediately. It is not necessary to tell me that you have paid to me. This wallet address is connected to you, my system will delete everything automatically after transfer confirmation. If you need 48h just Open the calculator on your desktop and press +++ If you don't pay, I'll send dirt to all your contacts.       Let me remin...

CERT NZ goes phishing

CERT NZ (apparently) has once again circulated an email warning about phishing, containing a distinctly phishy link to "READ MORE INFORMATION". The hyperlink leads from there to certnz.cmail20.com with a tracker-type URL tail. Unlike most of the intended audience, I guess, I'm cyber-smart enough to check out the whois record: cmail20.com domain is registered to Campaign Monitor Pty Ltd of New South Wales - presumably a legitimate mass emailer/marketing company whose services are being used by CERT NZ to circulate the warnings - but that's not the point: the fact is that the embedded link target is patently not CERT NZ's own domain. What's more, the body of the email is a rather vaguely-worded warning, not entirely dissimilar to many a classic phisher. "Nasty stuff is going to happen unless you do something" just about sums it up.  It isn't even addressed to me by name, despite me being required to supply my name and email address when I signed u...

Phishing awareness and training module

Image
It's out: a fully revised (almost completely rewritten!) awareness and training module on phishing. Phishing is one of many social engineering threats, perhaps the most widespread and most threatening. Socially-engineering people into opening malicious messages, attachments and links has proven an effective way to bypass many technical security controls. Phishing is a business enterprise, a highly profitable and successful one making this a growth industry. Typical losses from phishing attacks have been estimated at $1.6m per incident, with some stretching into the tens and perhaps hundreds of millions of dollars. Just as Advanced Persistent Threat (APT) takes malware to a higher level of risk, so Business Email Compromise (BEC) puts an even more sinister spin on regular phishing. With BEC, the social engineering is custom-designed to coerce employees in powerful, trusted corporate roles to compromise their organizations, for example by making unauthorized and inappropriate wire tr...

Phishing awareness module imminent

Image
Things are falling rapidly into place as the delivery deadline for October's awareness module on phishing looms large. Three cool awareness poster graphics are in from the art department, and three awareness seminars are about done.  The seminar slides and speaker notes, in turn, form the basis for accompanying awareness briefings for staff, managers and professionals, respectively.   We also have two 'scam alert' one-pagers, plus the usual set of supporting collateral all coming along nicely - a train-the-trainer guide on how to get the best out of the new batch of materials, an awareness challenge/quiz, an extensive glossary (with a few new phishing-related terms added this month), an updated policy template, Internal Controls Questionnaire (IT audit checklist), board agenda, phishing maturity metric, and newsletter.  Lots on the go and several gaps to be plugged yet. Today we're ploughing on, full speed ahead thanks to copious fresh coffee and Guy Garvey singing ...

Phishing awareness

Image
Today marks the end of a long but successful week. We've been slogging away at the phishing awareness topic for October's module, picking out the key issues, coming up with the awareness messages and figuring out the stories to tell. Despite technology being such a small part of phishing, it plays an important part that we can't just ignore. Multi-Factor Authentication, for example, is increasingly being used by organizations that care about identification and authentication, so workers are quite likely to have at least heard of it, even if they are not actually using it as yet. Explaining what MFA is would set them up to appreciate what it means when they are offered or required to accept it. At the same time, MFA is not a universal or ultimate solution. Managers and professionals should appreciate that there are pros and cons to implementing MFA, and lots of choices in exactly what form of MFA the organization might adopt ... but explaining all that in detail would divert...

Lame email scam

Image
This plopped unceremoniously into my inbox today: It's hard to imagine anyone falling for such a lame appeal ... but then perhaps the scammer's real aim was to be blogged about, and I've been phooled. I presume neither "Gilda Ancheta" nor uhn.ca (the University Health Network based in Toronto, Canada, apparently) have anything to do with this email, especially as the reply-to address (not shown above but embedded in the email header) is [somebody]@rcn.com I've forwarded the message to abuse@rcn.com.  Tag!

Peripheral vision

Image
Part of security awareness is situational or contextual awareness - being alert to potential concerns in any given situation or context. At its core, it is a biological capability, an inherent and natural part of being an animal.  Think of meercats, for instance, constantly scanning the area for predators and other potential threats. We humans are adept at it too, particularly in relation to physical safety issues. The weird creepy feeling that makes the hairs stand up on the back of your neck as you wander down a dark alley is the result of your heightened awareness of danger triggering hormonal changes. A rush of adrenaline primes you for the possible fight or flight response. I'm talking here about reflexes acting a level below conscious thought, where speed trumps analysis in decision-making. When 'something catches your eye', it's often something towards the edge of your visual field: peripheral light receptors coupled with the sophisticated pattern-recognition cap...

Email and messaging security awareness materials published

Image
May's awareness materials have been delivered to customers, a ~50Mb zip file of awareness content on email and messaging security. If you have been following this blog over the past month, you'll have a good idea about what's in the new module . I make no bones about it: this is an extremely important topic for all security awareness programs.  Given the prevalence and impact of issues such as phishing, malware and privacy breaches, any organization that foolishly ignores the risks and leaves its employees to flounder in the dark deserves what it gets!

Home straight

Image
As today is the last day of April, we've been running flat out in top gear all week to complete May's awareness materials on email and messaging security before our self-imposed delivery deadline. There is just one more paper to prepare today while the proofreading is in progress, then we'll package and deliver the materials before taking a breather. The final paper to cross the line this month will be a management-level awareness piece about security metrics for email and messaging.  It should take two or three hours to prepare, on the basis that I write at about one A4 page per hour on average. If that sounds slow, my excuse is that a lot of thinking and creative effort goes into each piece: I'm not just typing frantically - far from it. The shortest, most succinct and high level awareness items often seem to take the longest to prepare, especially the ones with diagrams and figures. The starting point for all our materials is a template, an MS Word template in this c...

The security awareness plate-spinning extravaganza

Image
The awareness module on 'email and messaging security' is coming along nicely, with just 4 days until our usual end-of-month delivery deadline. We could easily consume at least another month refining the materials, getting further into some of the technical issues and digging up more news, security controls and related issues to discuss ... but in the end we'd still only have a single awareness module on a particular topic, focusing on a small part of the information risk landscape. It's better to complete and deliver what we have, then turn the awareness spotlight to illuminate a different part of the landscape next month. Yesterday I read " Be Compromise Ready: Go Back to the Basics - 2017 Data Security Incident Response Report ", a glossy survey report by BakerHostetler that started out strongly by acknowledging the value of employees as part of an organization's cyberdefense: "Employees are often cited as a company’s greatest asset. In the cyberse...

Catering for multiple audiences

Image
We've used the professionals' seminar as a donor to kick-start the staff and management seminars. Copying seminar slides into new templates and fiddling around with the layout and formatting is the easy bit: adapting the presentations to suit the different audiences takes a bit more thought. Most managers are unlikely to have an interest in the techical details of email encryption, for instance, but they ought to appreciate that there are options in that regard, each having pros and cons for the organization. We need to give them just enough context and background to be able to take this up with their IT, risk and information security professionals - some questions to pose, perhaps, as well as a basic grounding in the concepts and terminology to facilitate meaningful communications. The awareness module will also contain management briefings, a sample policy and a paper on email and messaging security metrics, encouraging managers to contemplate the strategic, governance, compl...

Getting back on track

Image
After a busy week away at the ISO27k meeting, I'm catching up with the day-job, working flat out to complete the email security awareness module by the end of this month. Yesterday, the professionals' seminar slide deck came together nicely: It's not quite finished yet but the 'story' behind/linking the slides is taking shape. We've incorporated a mixture of graphic images, diagrams and recent press clippings to illustrate and enhance the content.  Notice the near absense of bullet points, avoiding 'death by PowerPoint'. There are a few paragraphs of text quoted in the press clippings (which, we believe, are relevant, topical, interesting and worth it) but most slides use striking visual imagery and strong colors. The idea is for a seminar leader, presenter or facilitator to explain and talk about each slide, conversing and interacting with the audience, where appropriate expanding on the literal content of the slides, interpreting things in the particul...