Tech Insight : Email Security
In this tech insight, we take a look at the many threats to email security that businesses face and what businesses can do to mitigate them, together with what help is available to help tackle those threats effectively.
Email Accounts For Most Security Breaches
Prioritising email security is important because most cyber-security breaches involve email, with social engineering a strongly favoured tactic favoured by cyber-criminals and 99 per cent of email attacks relying on victims clicking links (Proofpoint Annual Human Factor Report).
Types of Email-Based Attacks
The many different types of email attack threats that businesses face include targeted phishing schemes, business email compromises, and ransomware attacks. For example:
– The Check Points mid-year security report in August this year showed that ransomware attacks (for extortion) have increased dramatically over the past year, with 93 per cent more attacks carried out in the first half of 2021, and with ransomware now appearing in 10 per cent of breaches (Verizon).
– Phishing. This cheap, easy, and highly effective tactic uses emails purporting to be from reputable sources containing links that (if clicked-on) direct the victim to pages where payment and other personal data is stolen or malware is downloaded. For example, at the end of 2019, Thomas Cook customers were targeted by phishing attacks in the wake of the travel company going into receivership. Verizon’s 2021 Data Breach Investigations Report shows that phishing increased by 11 per cent from Aug 2020 to Aug 2021 and that phishing is present in 36 per cent of breaches. The National Cyber Security Centre offers advice on how to protect your business/organisation from phishing attacks here: https://www.ncsc.gov.uk/guidance/phishing.
– Malware attachments to emails. It is estimated that a business is targeted by a ransomware attack every 11 seconds (Kaspersky) and Between 2019 and 2020, ransomware attacks rose by 62 percent. Malware is now involved in over 70 per cent of system intrusion (Verizon). Common forms of malware include viruses, worms, Trojan Horses, spyware, adware, and ransomware. Remote Access Trojans (RATs), for example, are malicious programs that can arrive as email attachments and provide a ‘back door’ for administrative control over the target computer, and can be adapted to avoid detection and to carry other types of attack tactics including disabling anti-malware solutions and enabling man-in-the-middle attacks.
– BEC and VEC. Whereas Business Email Compromise (BEC) attacks have been successful at using email fraud combined with social engineering to bait one staff member at-a-time to extract money from a targeted organisation, security experts say that this kind of attack is morphing into a much wider threat of ‘VEC’ (Vendor Email Compromise). This is a larger and more sophisticated version which, using email as a key component, seeks to leverage organisations against their own suppliers.
– AI-based threats. Many technology and security experts agree that AI is likely to be used in cyberattacks in the near future and its ability to learn and to keep trying to reach its target (e.g. in the form of malware) make it a formidable threat. Email is the most likely means by which malware can reach and attack networks and systems, so there has never been a better time to step up email security, train and educate staff about malicious email threats, how to spot them and how to deal with them. The addition of AI to the mix may make it more difficult for malicious emails to be spotted. The good news for businesses, however, is that AI and machine learning is already used in some anti-virus software (e.g. Avast) and this trend of using AI in security solutions to counter AI security threats is a trend that is likely to continue.
Protecting Your Email From Common Threats
Ways to protect your email from common security threats include:
– Always keeping anti-virus and patching up to date.
– Staff education and training; e.g. how to spot suspicious emails and what to do/what not to do, such as not clicking on links from unknown sources.
– Disabling HTML emails if possible (text-only emails can’t launch malware directly).
– Encrypting sensitive data and communications as an added layer of protection.
– Getting into the routine of checking your bank account’s activity for suspicious charges.
– Making sure important and sensitive company data is backed up and including business email compromise (BEC) in business continuity planning and disaster recovery planning.
– Preventing email archives from being publicly exposed; e.g. by making sure that archive storage drives are configured correctly.
– Monitoring for any exposed credentials (particularly those of finance department emails).
– Using two-Factor Authentication (2FA) where possible, and enterprise users may wish to block .html and .htm attachments at the email gateway level so that they don’t reach members of staff, some of whom may not be up to speed with their Internet security knowledge.
– Not using the same password for multiple platforms and websites (password sharing). This is because credentials stolen in one breach are likely to be tried on many other websites by other cyber-criminals (credential stuffing) who have purchased/acquired them (e.g. on the dark web).
Broad Methods and New Approaches
Other broader methods that companies can use to protect their email security include:
– Adopting a ‘zero-trust’, “never trust, always verify” approach to company cyber security. The control that administrators have, and the monitoring and alerting can help dramatically reduce risk, including with company emails.
– Moving from perimeter to pervasive email security, e.g. as suggested by Mimecast’s CEO Peter Bauer. This involves dealing with threats to the perimeter, from inside the perimeter, and from beyond the perimeter, plus an API-led approach to help deliver pervasive security throughout all zones.
Tech Company Help
Ways offered by tech companies to help businesses and organisations keep their email secure include:
Microsoft
Outlook’s Junk Email Filter, and the Report Message add-in for Outlook.
– Office 365’s Advanced Threat Protection (ATP) plans.
– Secure Score for Office 365 / Microsoft 365 Defender portal – a way to measure and get suggestions about how to protect your business from threats, all through a centralised dashboard – find out more here: Microsoft Secure Score | Microsoft Docs
– The “campaign views” tool in Office 365 that is designed to offer greater protection from phishing attacks by enabling businesses to be able to spot the pattern of a phishing campaign over individual messages.
– Offering online advice for protecting Outlook email accounts – see Help protect your Outlook.com email account (microsoft.com).
– Microsoft is making its plus addressing (disposable email address), custom email feature available to all Office 365 users by adding it to Exchange Online.
Google also offers a number of tools and suggestions, including:
– Advanced Gmail security for phishing and malware for G Suite administrators – see Advanced phishing and malware protection – Google Workspace Admin Help.
– Offering steps to identify compromised accounts – see Identify and secure compromised accounts – Google Workspace Admin Help.
– Advice on Firewall settings.
– Blocking malicious emails before they reach email boxes. For example, on its Cloud blog on 16 April 2020, Google reported that Gmail blocks more than 100 million phishing emails each day.
What Does This Mean For Your Business?
With so many types of attacks relying upon email as a way in (e.g. phishing), effective email security is vital. Businesses and organisations need to make sure that they are prepared to not just effectively defend against the whole range of email attacks but are be able to spot and eliminate threats as they arrive, and ensure that staff are aware of email threats and know what to do when faced with suspicious emails and links. Also, attackers adapt their campaigns and methods very quickly, and use methods that can evade the more common protection solutions (i.e. ‘polymorphic’ attacks) so businesses and organisations must find ways to get a fuller picture of the email threats they face and find solutions that can focus effectively on zero-day and targeted attacks in addition to known vectors. With the threat of AI-based attacks now on the horizon too, there has never been a more important time for businesses to take a very close look at what more they could be doing to maximise their email security.
Tech News : Twitter Bans Sharing ‘Private’ Images & Video Without Consent
In a change to its Private Information Policy, Twitter has banned the sharing of personal media, such as images or videos without the subject’s consent.
Why?
Twitter says that as part of its ongoing work to align its safety policies with human rights standards, it needs to take action to tackle the possible misuse of media and information that is not available elsewhere online as a tool to harass, intimidate, and reveal the identities of individuals. Twitter says that it is particularly concerned about how sharing images or videos, without consent, could have a disproportionate effect on women, activists, dissidents, and members of minority communities in terms of violating their privacy or even leading to emotional or physical harm.
Existing Policies and Rules Not Enough
Twitter’s existing policies and rules only cover explicit instances of abusive behaviour. The update to the Private Information Policy, however, means that Twitter can now take action on media that is shared without any explicit abusive content, but is posted without the consent of the person depicted.
What Can’t You Share Anyway?
The existing aspects of Twitter’s policies mean that users can’t share the following media or information without the consent of the subject / the person it belongs to:
– Home address or physical location information, including street addresses and GPS coordinates.
– Any identity documents e.g., government-issued IDs and social security or other national identity numbers.
– Contact information, including non-public personal phone numbers or email addresses.
– Any financial account information e.g., bank account details or credit card details; other private details such as biometric data or medical records.
How Will The Change Work?
The change to the Private Information Policy means that if Twitter is notified by the individuals depicted (or by an authorised representative) that they did not consent to having their private image or video shared, Twitter will remove it.
Exceptions
Twitter has said, however, that the policy is not applicable to:
– Media featuring public figures or individuals when media and accompanying Tweet text are shared in the public interest or add value to public discourse.
– Situations where images or videos of private individuals are shared in an effort to help someone involved in a crisis situation e.g., the aftermath of a violent event.
– Situations where the ‘context’ dictates that the image/video should stay e.g., where the image/video has been made publicly available and/or is being covered by mainstream/traditional media.
Criticism
The policy change received criticism online for lacking clarity e.g., about who is considered to be a public figure and what can be defined as “private” images. Some critics also questioned how the policy would be enforced and suggested that the policy may end up disproportionately affecting those marginalised individuals that Twitter claims it will protect. Twitter sought to clarify its position by posting on its own platform to say that images/videos showing people participating in public events such as large-scale protests, sporting events, etc. would not generally violate the policy and that they would require a first-person report of the photo/video in order to review the media before any enforcement action could be taken.
What Does This Mean For Your Business?
With the strengthening of data protection laws (e.g. GDPR in Europe) and social media companies now under serious scrutiny over how they protect their users (e.g. the recent Facebook Whistleblower allegations), it is not surprising to see social media platforms announcing new safety measures. For Twitter, this strengthening of an existing policy to deal more effectively with image and video privacy and security issues sounds helpful and responsible but, as critics have said, needs further clarification and still relies upon Twitter’s own judgements about context, public interest, and other (often grey) areas. This illustrates how complex the matter of sharing, consent, and social platform self-policing and policies have become. This expansion of an existing policy is one in what is likely to become a long line of incremental changes for Twitter to try and show that it can keep its own house in order, dodge being cast as a ‘publisher’ rather than a ‘platform’, and thereby avoid the need for more regulation.
Tech Tip – Using Google To Search Within A Website
If you’d like to quickly search within a whole website (e.g. a competitor’s website for specific term or subject) here’s a quick way to do so using Google.
– Go to Google.
– In the search field, type “site:” followed by the URL of the site and your search terms. For example: site:bbc.co.uk Christmas
– This should return all pages (and many images) in the website that feature the search term you’ve specified.
Sustainability : Ethical Phones and Computers
In this article, we look at what ethical phones and computers are, what makes them ‘ethical’ and what contribution they could be making to helping the environment by tackling issues such as the growing e-waste mountain.
Tackling E-Waste
The world currently has a significant problem with electronic waste in terms of a “take, make, consume, dispose” attitude, mounting volumes of production and disposal, and little engagement with the ‘circular economy’ by many manufacturers. For example, the UN’s Global E-waste Monitor report (2020) shows that e-waste is now the fastest growing global waste stream with a record 53.6 million metric tonnes (Mt) of electronic waste generated worldwide in 2019, up 21 per cent in just five years. Not only does the worldwide pile of electronic waste weigh more than all the commercial airliners ever made, or the Great Wall of China (WEEE), but less than 20 per cent of the world’s e-waste is collected and recycled. This means that gold, silver, copper, platinum and other high-value, recoverable materials (conservatively valued at US $57 billion), are simply dumped or burned, and there is a huge pollution-centred environmental impact.
Other Issues
There are also arguments that many of the factory workers who manufacture electronic goods such as phone handsets are on low wages, while governments are overlooking opportunities to promote and incentivise more re-use and re-cycling of the kinds of scarce materials found in e-waste. There are also questions about ethics and responsibility and whether manufacturers are putting profits before the planet and people.
Right-to-Repair
Making phones and computers that can be repaired by their users (rather than just by approved repairers) is seen as another important way to help reduce the e-waste mountain. The ‘right-to-repair’ movement is one that seeks to have rules/legislation passed that forces manufacturers of electrical products such as phones to make parts (and information) available to end customers, not just approved/authorised repairers, and technicians, so that it is possible for end-users to fix the product(s) at home. The basic idea is that this could help tackle built-in obsolescence, thereby prolonging product life cycles, creating better value and saving money for consumers, and reducing the number of products going to waste thereby helping the environment. Ethical phones and other ethical devices have the ‘right-to-repair’ built-in to their design.
How Could Ethical Electronic Devices Help?
If devices such as ethical phones and computers are manufactured with fair trade, welfare of workers, repair, and recycling already built into the business model from the outset, and if there is wide market adoption, it could have a much more positive environmental impact (than the current untenable situation) and could slow and cuts the flow of e-waste, plus help countries to meet their environmental targets.
What Is An ‘Ethical’ Phone?
An ethical phone is one that has been manufactured with the circular economy in mind and the end-of-life of the product being incorporated into its design and manufacture (repair and recycling). Taking ‘Fairphone’ as an example of an ‘ethical phone ’, it offers:
– A take-back scheme so that customers can easily return the handset, thereby giving the opportunity of recycling the phones rather than sending them to landfill.
– A handset that’s ‘e-waste neutral’ because an equivalent volume of electronics is recycled per phone that’s sold.
– Workers who manufacture the handsets have a living wage bonus scheme enabling them to (depending on targets) receive 30 per cent extra on their wages.
– Ethically sourced precious metals and recycled metals are used in the handset manufacture, which includes aluminium and tungsten, plus recycled tin, copper, and rare earth metals. Also, Fairphone claims to be the first and only smartphone company to integrate Fairtrade gold in its supply chain.
– Recycled plastic for the phone casing.
– A modular design to minimise both repair costs and downtime. This helps tackle popular phone damage issues such as screen damage (accounts for 67.4% of phone repairs) and battery problems (33.9% of phone repairs).
– The right-to-repair built-in to the design with handsets able to be repaired using just a screwdriver and easy access to parts. This coupled with the phone’s modular design can give it longevity, thereby reducing the need for a new phone and reducing the environmental impact.
Phone Manufacturers Turning To More Ethical Ideas
Apple, for example, recently announced the introduction of its “self-service repair” programme, beginning next year, which will give iPhone 12 and iPhone 13 customers access to parts and information which will allow them to repair their own phones.
Ethical Computers
There are now ethical computers on the market which have many of the same ideas as ethical phones incorporated in their design and manufacture. For example:
– The Iameco D4R (laptop) – this is encased in recycled wood and made so that it can be repaired easily and components can be swapped. The company claims that this laptop model accounts for at least 30 per cent fewer greenhouse gas emissions and 75 per cent less freshwater use compared to standard laptops.
– Aleutia PCs – which is made primarily for use in the developing world, (where there is little access to grid power); these computers use solar cells for power.
– VeryPC computers (e.g., the Broadleaf model) – are built to ‘green’ principles. In 2009, for example, the company set out to build “the most sustainable PC on the planet”.
– More well-known brands introducing models with a more environmental focus. For example, these include the Lenovo ThinkPad L Series laptops with their low energy consumption and more post-consumer recycled content (30 per cent) than other ThinkPads.
What Does This Mean For Your Organisation?
Organisations get through a lot of phones, computers, and other electrical devices, and although they may be happy to promote environmental aspects of their operations and services, this aspect (i.e., the problem of contributing to the e-waste mountain) is often overlooked. As Fairphone points out, choosing ethical phones is a way that organisations can make a conscious decision to contribute to globally recognised UN Sustainable Development Goals, and it is an opportunity to send a clear signal about environmental and ethical values as an organisation, and as an employer. Consumers, employees, customers, and other stakeholders are increasingly conscious of the environment and value the environmental credentials of organisations. Using ethical phones and devices, therefore, is a way to both help the environment, and enjoy the benefits of improved customer attitudes to an organisation.
Tech Insight : How To Know If Someone Has Read Your Email?
In this tech insight, we take a look at the better-known ways of being able to tell if someone has read your email.
The Usual Suspects
The main ways to tell if a person has read your email include:
– Request a read receipt when you compose the email. The read receipt is then sent to you as an email with the time and date of when your message was opened. For example, in Gmail, when composing the email, bottom right, click “More options” > “Request a read receipt”. In Outlook, Go to File > Options > Mail, and Under Tracking, select “Read receipt” which confirms that the recipient viewed the message checkbox.
– Delivery receipt. This is a way of confirming (by receiving an email back) if an email message has been delivered to the recipient’s e-mail server. In Outlook, for example, go to File > Options > Mail, and Under Tracking, select “Delivery receipt”. Although it will directly confirm if the email has been read, it will confirm if the email address you sent to exists.
– Tracking pixels. A tracking pixel / marketing pixel / spy pixel is a 1×1 pixel graphic that can be hidden in anything from banner ads to emails and used to track user behaviour. Tracking pixels can be inserted in emails and used to log if and when an email is opened, how many times it’s opened, and what device / devices are used. It can also use the (IP) address to get a rough idea of the recipient’s physical location.
– LinkedIn’s Inmail. This service, within LinkedIn, allows one LinkedIn member to directly message another LinkedIn member that they aren’t connected to. LinkedIn allows read receipts on its internal messages so that the sender can see if the email has been read. These receipts can be requested by clicking on the ‘Me’ icon at the top of the page, and selecting “Settings & Privacy” (dropdown list), “Communications” > “Messaging experience” > “Change”, and next to “Read receipts and typing indicators” turning the toggle to ‘on’.
– Third-party mail marketing programs and CRMs. Mailchimp, for example, can track who opened your marketing email (sent to their email address), and how many times. Zoho can track emails but requires a read-receipt request to see if the email has been opened (using the “Ask Receipt” feature).
– Third-party email tracking tools/ apps. Many of these work as an extension in Google Chrome, for example, Right, SalesHandy, Mailtrack, Streak, or MailTracker.
– Using codes. With Campaign Monitor, for example, UTM codes can be set within the emails to tell the analytics tool which recipients visited from your email campaigns, thereby confirming that the email has been opened.
Fooling Read Receipts?
App security and the option to opt-out/turn-off features like receipts mean that in many cases, it’s possible to fool these features. There are, however, some ‘hacks’ and methods for some apps posted online. One example involving WhatsApp, involves recording a voice note (in WhatsApp), where a sender can see if a recipient has played the recording, even if the recipient has disabled the ‘Read Receipt’ feature.
What Does This Mean For Your Business?
For business, marketing (and sometimes legal reasons), it is often important and helpful to know if a person has seen and opened your email. Emails, however, are private communications involving the management of personal data and, as such, there are relatively ways to monitor email openings (e.g. requesting a read receipt or other methods described earlier). For businesses, this may be an ongoing marketing challenge but, as individuals, there is value in maintaining our own email privacy and security.
Featured Article : Digital Markets Act Could Protect Whistleblowers
The EU’s adoption of a proposal on the Digital Markets Act (DMA) on Tuesday not only offers the potential to help tackle the market dominance of big tech businesses but could also protect whistleblowers.
What Is The Digital Markets Act?
Currently at the proposal stage, the Digital Markets Act (DMA) from the European Commission is designed to ensure a higher degree of competition within the European Digital Markets, by preventing large companies from abusing their market power and by allowing new players to enter the market. The idea is to create more of a level playing field for businesses which the EC believes could help to foster innovation, growth, and competitiveness. The DMA will apply to businesses, and the EC has another initiative called the Digital Services Act (DSA) which will be used help protect the rights of users of digital services.
DMA Will Apply To “Gatekeepers”
One of the core ideas of the DMA is that rules are needed to govern “Gatekeeper” online platforms. These “Gatekeepers” are defined as “digital platforms with a systemic role in the internal market that function as bottlenecks between businesses and consumers for important digital services”. For a large online platform to qualify as a “Gatekeeper” and, therefore, be subject to rules of the DMA, the EC says that the criteria to be met are that a company has:
– A strong economic position, significant impact on the internal market and is active in multiple EU countries.
– A strong intermediation position, meaning that it links a large user base to a large number of businesses.
– An entrenched and durable position in the market, meaning that it is stable over time.
To be more specific, a Gatekeeper platform has:
– A core platform in at least three EU countries with at least 45 million end users, and more than 10,000 business users.
– A business that operates in the European Economic Area (EEA), and generates €8 billion (£6.7 billion) in annual turnover, and has a market capitalisation of at least €80 billion (£67 billion).
Recent Whistleblower Allegations
Antitrust allegations, arguments about paying tax, and criticism about how big tech platforms are (or aren’t) policing themselves (with issues such as harmful content and misinformation) have long been made against the big tech platforms. The recent allegations by Facebook employee-turned-whistleblower, Frances Haugen, has shone a strong light on the subject. Haugen alleged that Facebook, now ‘Meta’, which could be described as a “Gatekeeper”, is putting profit before people, and not addressing alleged issues about the safety of young users (Facebook and Instagram). For example, Frances Haugen claimed that Facebook was “unquestionably” making online hate worse, and told UK MPs that safety teams were under-resourced, and that “Facebook has been unwilling to accept even little slivers of profit being sacrificed for safety” and being “more dangerous than other forms of social media”.
Why Whistleblowers Are Important
Whistleblowers are insiders who take an ethical stance (or have other motivations) by publicly speaking-out about a company/organisation’s wrongdoing or questionable behaviour, often at their own expense. Some of the reasons why whistleblowers are important are that they:
– Protect a company’s customers, employees, and other stakeholders.
– Protect an organisation by helping to combat fraud and misconduct.
– Help enforce the general rule of law by shining a light on law-breaking.
– Point to areas that may have been causing problems to the business itself and this can lead to the creation of a better culture and greater transparency which can business perform better.
Whistleblowing, however, is often unwelcome as it can show individuals and companies in a negative way and can lead to retaliation against the whistleblower. Given the power imbalance between the organisation and the individual who speaks out, plus the barriers of being able to speak out, companies need to have systems in place to allow reporting of concerns, and there needs to be protection for whistleblowers.
Already A Whistleblowing Directive
The EU already has a directive (DIRECTIVE (EU) 2019/1937) which came into force in October 2019 which is specifically designed to protect whistleblowers by stipulating that companies working in the EU with 50 or more employees must create internal reporting systems in order to help employees and third parties report violations of EU law and to protect those persons from retaliation when they speak up.
How The DMA Will Protect Whistleblowers
The DMA proposal states that Internal Market MEPs should ensure adequate protections are afforded to any whistleblowers at companies who come under the DMA’s remit and violate the DMA’s rules. This should help protect whistleblowers from retaliation by big tech “Gatekeeper” platforms.
Other Points in the DMA
Other important things that DMA seeks to do include:
– Protecting personal data-collection consent under GDPR, particularly where the data of minors is concerned in relation to direct marketing or targeted advertising strategies.
– Strengthening existing laws to give greater powers to help tackle absolute market dominance of big online platforms in the EU.
The Punishments
The proposed punishments for big digital platforms that the DMA rules against could be fines of no less than 4 per cent and no greater than 20 per cent of the gatekeeper’s global turnover. Given the size of a big digital platform’s operations, this could represent a significant punishment.
What Does This Mean For Your Business?
For the household-name digital platforms, this means a toughening-up of regulations in the EU area and could represent a threat to what many perceive to be their huge market dominance and, therefore, their profits. Greater protection for whistleblowers could also represent a threat in terms of allowing yet more damaging and costly bad publicity. For other, smaller digital companies operating in the EU area, the DMA is likely to be a welcome step, allowing them more of a chance to compete and gain more share in a market dominated by giants for so long. Big digital platforms, however, already operate in a highly regulated environment and whistleblower revelations, such as Frances Haugen’s, illustrate that they may still be able to operate in ways that could be perceived as questionable. The wealth of digital platforms may, however, mean that the threat of smaller fines may not be such a big deterrent. As such, it remains to be seen how much difference the DMA can make when it is finally introduced.