ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Spear Phishing Defenses

    Scheduled Pinned Locked Moved IT Discussion
    11 Posts 5 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • MattSpellerM
      MattSpeller
      last edited by

      Our company is getting spear phished really hard. They're emailing our CFO and CEO pretending to be one another and trying to get them to visit malicious sites and send banking info. As an IT staff member I feel particularly helpless and that pisses me off.

      Suggestions?

      coliverC scottalanmillerS 2 Replies Last reply Reply Quote 0
      • Deleted74295D
        Deleted74295 Banned
        last edited by

        SPF record with hard fails.

        1 Reply Last reply Reply Quote 5
        • coliverC
          coliver @MattSpeller
          last edited by

          @MattSpeller said in Spear Phishing Defenses:

          Our company is getting spear phished really hard. They're emailing our CFO and CEO pretending to be one another and trying to get them to visit malicious sites and send banking info. As an IT staff member I feel particularly helpless and that pisses me off.

          Suggestions?

          Education... and set up an SPF record to lock down your domain to only your servers. Have a good disaster recovery plan in place for the inevitable time when they do click on one of the links.

          1 Reply Last reply Reply Quote 3
          • MattSpellerM
            MattSpeller
            last edited by

            After some investigation (this is not my strong suit, learning lots) we do indeed have SPF enabled and I tested it - it's also setup correctly

            aaron-closed accountA 1 Reply Last reply Reply Quote 0
            • MattSpellerM
              MattSpeller
              last edited by

              Beyond education are there any other steps I can take?

              We came darn close to disaster and it's really bothering me

              scottalanmillerS 1 Reply Last reply Reply Quote 0
              • Deleted74295D
                Deleted74295 Banned
                last edited by

                DKIM is the next step up from SPF records.

                What anti spam filter are you using?

                1 Reply Last reply Reply Quote 1
                • scottalanmillerS
                  scottalanmiller @MattSpeller
                  last edited by

                  @MattSpeller said in Spear Phishing Defenses:

                  Our company is getting spear phished really hard. They're emailing our CFO and CEO pretending to be one another and trying to get them to visit malicious sites and send banking info. As an IT staff member I feel particularly helpless and that pisses me off.

                  Suggestions?

                  Remember.... while IT should help when possible, spear phishing is the responsibility of the people, not of IT. It's an HR problem within the security context, not an IT problem. It's wetware, not technology that is targeted and might fail.

                  MattSpellerM 1 Reply Last reply Reply Quote 3
                  • scottalanmillerS
                    scottalanmiller @MattSpeller
                    last edited by

                    @MattSpeller said in Spear Phishing Defenses:

                    Beyond education are there any other steps I can take?

                    We came darn close to disaster and it's really bothering me

                    Should not be bothering you, should be bothering your CEO and CSO. What actions are THEY taking to ensure education?

                    1 Reply Last reply Reply Quote 1
                    • scottalanmillerS
                      scottalanmiller
                      last edited by

                      Are you blocking internal domain emails coming from the outside?

                      1 Reply Last reply Reply Quote 2
                      • MattSpellerM
                        MattSpeller @scottalanmiller
                        last edited by

                        @scottalanmiller I'm going to investigate the blocking stuff this afternoon and make sure it's all in place.

                        It's easy to say it's not really our responsibility but I enjoy working here and I want this company to succeed. Right now the phishing is a direct threat and I'm not one to back down. There may end up being nothing I can do beyond education but I want to be god damned sure that's the case.

                        1 Reply Last reply Reply Quote 1
                        • aaron-closed accountA
                          aaron-closed account Banned @MattSpeller
                          last edited by

                          This post is deleted!
                          1 Reply Last reply Reply Quote 2
                          • 1 / 1
                          • First post
                            Last post