ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Spear Phishing Defenses

    Scheduled Pinned Locked Moved IT Discussion
    11 Posts 5 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Deleted74295D
      Deleted74295 Banned
      last edited by

      SPF record with hard fails.

      1 Reply Last reply Reply Quote 5
      • coliverC
        coliver @MattSpeller
        last edited by

        @MattSpeller said in Spear Phishing Defenses:

        Our company is getting spear phished really hard. They're emailing our CFO and CEO pretending to be one another and trying to get them to visit malicious sites and send banking info. As an IT staff member I feel particularly helpless and that pisses me off.

        Suggestions?

        Education... and set up an SPF record to lock down your domain to only your servers. Have a good disaster recovery plan in place for the inevitable time when they do click on one of the links.

        1 Reply Last reply Reply Quote 3
        • MattSpellerM
          MattSpeller
          last edited by

          After some investigation (this is not my strong suit, learning lots) we do indeed have SPF enabled and I tested it - it's also setup correctly

          aaron-closed accountA 1 Reply Last reply Reply Quote 0
          • MattSpellerM
            MattSpeller
            last edited by

            Beyond education are there any other steps I can take?

            We came darn close to disaster and it's really bothering me

            scottalanmillerS 1 Reply Last reply Reply Quote 0
            • Deleted74295D
              Deleted74295 Banned
              last edited by

              DKIM is the next step up from SPF records.

              What anti spam filter are you using?

              1 Reply Last reply Reply Quote 1
              • scottalanmillerS
                scottalanmiller @MattSpeller
                last edited by

                @MattSpeller said in Spear Phishing Defenses:

                Our company is getting spear phished really hard. They're emailing our CFO and CEO pretending to be one another and trying to get them to visit malicious sites and send banking info. As an IT staff member I feel particularly helpless and that pisses me off.

                Suggestions?

                Remember.... while IT should help when possible, spear phishing is the responsibility of the people, not of IT. It's an HR problem within the security context, not an IT problem. It's wetware, not technology that is targeted and might fail.

                MattSpellerM 1 Reply Last reply Reply Quote 3
                • scottalanmillerS
                  scottalanmiller @MattSpeller
                  last edited by

                  @MattSpeller said in Spear Phishing Defenses:

                  Beyond education are there any other steps I can take?

                  We came darn close to disaster and it's really bothering me

                  Should not be bothering you, should be bothering your CEO and CSO. What actions are THEY taking to ensure education?

                  1 Reply Last reply Reply Quote 1
                  • scottalanmillerS
                    scottalanmiller
                    last edited by

                    Are you blocking internal domain emails coming from the outside?

                    1 Reply Last reply Reply Quote 2
                    • MattSpellerM
                      MattSpeller @scottalanmiller
                      last edited by

                      @scottalanmiller I'm going to investigate the blocking stuff this afternoon and make sure it's all in place.

                      It's easy to say it's not really our responsibility but I enjoy working here and I want this company to succeed. Right now the phishing is a direct threat and I'm not one to back down. There may end up being nothing I can do beyond education but I want to be god damned sure that's the case.

                      1 Reply Last reply Reply Quote 1
                      • aaron-closed accountA
                        aaron-closed account Banned @MattSpeller
                        last edited by

                        This post is deleted!
                        1 Reply Last reply Reply Quote 2
                        • 1 / 1
                        • First post
                          Last post