Showing posts with label Lindsey Havens. Show all posts
Showing posts with label Lindsey Havens. Show all posts

Friday, December 1, 2017

The Targeted Approach to Anti-Phishing: Improving Core Skills

The Targeted Approach to Anti-Phishing: Improving Core Skills

Wouldn’t it be great if every one of your users could be turned into an anti-phishing specialist?

Like sleeper agents, they’d be ready at any moment to drop their day jobs and sniff out every last malicious email that makes it past your perimeter defenses.

It’s an enticing fantasy.

But is it reasonable to expect your users to become genuine anti-phishing experts? We think not.

The post The Targeted Approach to Anti-Phishing: Improving Core Skills appeared first on Security Boulevard.



from The Targeted Approach to Anti-Phishing: Improving Core Skills

Wednesday, October 18, 2017

Email Sender Domain: How to Spot a Phish Video

Email Sender Domain: How to Spot a Phish Video

In observance of National Cyber Security Awareness month, we are releasing several videos to help employees and consumers spot a phish. In the second video, we take a look at the  sender's email address to help spot a potentially malicious email. To view all videos released in this series, visit this page: https://info.phishlabs.com/2017-cyber-security-awareness-month. 

The post Email Sender Domain: How to Spot a Phish Video appeared first on Security Boulevard.



from Email Sender Domain: How to Spot a Phish Video

Friday, June 2, 2017

Coming Soon – Healthcare Security Awareness Training, the 2017 Buyer’s Guide

bigstock-Man-Checking-The-Health-Of-His-61929695.jpg

Historically, security awareness training (SAT) in the healthcare industry… isn’t great. In fact, if you start talking about SAT to a healthcare CISO, you can see the frustration on their face almost immediately.

Back in February we attended HIMSS, one of the biggest healthcare IT shows in the US. We wanted to find out exactly what healthcare providers needed from a SAT program, and show them that (done properly) SAT can have a tremendous positive effect on the operational security of healthcare organizations.



from Coming Soon – Healthcare Security Awareness Training, the 2017 Buyer’s Guide

Wednesday, May 3, 2017

How Source Code Analysis Helps Defend Against Phishing

How Source Code Analysis Helps Defend Against Phishing

If you want to protect your organization from phishing attacks, threat intelligence is a vital tool.  From phish kits and phishing sites to individual email lures, there’s a huge amount to learn from each section of the phishing kill chain.

Last month we kicked off our new webinar series, in which we’ll be taking a deep dive into specific phishing attacks to help members of the infosec community understand precisely how and why each attack vector works.



from How Source Code Analysis Helps Defend Against Phishing

Friday, March 24, 2017

How and Why the Phishing Threat Landscape Has Changed

Screen Shot 2017-03-22 at 21.46.54.png

Over the last decade phishing has exploded. Volume has increased every year, with threat actors reliably focusing the majority of their efforts on the same five or six industries.

It was a serious threat, of course, but it had become somewhat… predictable.

But in 2016, some major changes occurred. In just 12 months, the entire phishing landscape shifted.



from How and Why the Phishing Threat Landscape Has Changed

Thursday, March 2, 2017

APWG & Kaspersky Research Confirms Phishing Trends & Intelligence Report Findings

APWG & Kaspersky Research Confirms Phishing Trends & Intelligence Report Findings

“For any study or research project, the ultimate assessment of validity is independent duplication of results.”

This quote was the first line of an email I received a few days ago from Crane Hassold, our senior security threat researcher at PhishLabs.

And since we’ve recently published our annual Phishing Trends & Intelligence (PTI) report, I was interested to learn more.



from APWG & Kaspersky Research Confirms Phishing Trends & Intelligence Report Findings

Thursday, February 23, 2017

Anatomy of a Phishing Attack: How Phish Kits Evolved in 2016

Anatomy of a Phishing Attack: How Phish Kits Evolved in 2016

At this point, most organizations are already aware of phishing. No matter what industry you’re in, phishing is one of the top cyber threats you’ll face in 2017.

But for most people, the threat actors responsible for phishing attacks are something of a mystery. They picture a faceless, hooded specter, hidden somewhere in the dark recesses of the Internet.



from Anatomy of a Phishing Attack: How Phish Kits Evolved in 2016

Tuesday, February 14, 2017

The Sinister New Trend in Phishing (and Why You Should Care)

bigstock-Faceless-Hooded-Anonymous-Comp-74798056.jpg

Unless you’ve been living under a rock for the past decade, you’ve already heard of phishing.



from The Sinister New Trend in Phishing (and Why You Should Care)

Friday, January 27, 2017

Building Powerful Security Awareness Training for the Healthcare Industry

Training.jpg

Over the past couple of weeks, we’ve written a lot about the current state of security in the healthcare industry, and why things need to change.

We’ve also covered the main causes of healthcare data breaches, and noted that powerful security awareness training is the most natural starting point for security conscious healthcare organization.

But so far, we haven’t really covered what should be included in a healthcare specific security awareness training program. After all, while some aspects of security are relevant to every industry, healthcare organizations are faced with a few highly specific problems that need to be addressed.

Before we consider what should be included, though, it’s worth looking at things from another perspective.



from Building Powerful Security Awareness Training for the Healthcare Industry

Thursday, January 19, 2017

Anatomy of a Healthcare Data Breach

Healthcare data breaches are becoming an almost daily occurrence.

from Anatomy of a Healthcare Data Breach

Wednesday, December 21, 2016

Why Security Awareness Training Should Be Your Easiest Investment Decision

Why Security Awareness Training Should Be Your Easiest Investment Decision

On the face of it, there’s really only one reason to invest in security awareness training: To avoid breaches, and save money. In reality there’s a bit more to it than that, but let’s stick with this assumption for now.



from Why Security Awareness Training Should Be Your Easiest Investment Decision

Wednesday, October 19, 2016

Pay Up: The 2016 Definitive Guide to Ransomware

Ransomware_Thumbnail.png

Right now most organizations are completely unready to cope with ransomware, both from security and recovery standpoints. In many cases, even basic security protocols such as consistent vulnerability management are lackluster or missing entirely, and threat actors are making millions of dollars every year as a result. 

That’s why, as part of our   Cyber Security Awareness Month series,  we are helping you take action by sharing our best resources on ransomware. 

In an effort to fight back together against cyberattacks, download this free copy of our Ransomware Whitepaper where we explore the growing threat of ransomware, and what you can do to keep your organization secure. We will walk you through the actions you should be taking to prevent ransomware from gaining a foothold inside your network, and how to make your security program the best it can be. 



from Pay Up: The 2016 Definitive Guide to Ransomware

Friday, October 14, 2016

The Growing Business of Cybercrime as a Service

Cybercrime.png

As part of our Cyber Security Awareness Month series, we have so far explored data breaches and Business Email Compromise (BEC). These topics and tactics roll up into a more global discussion about the growing economy of cybercrime. We reported in 2015 that, as competition continues to rise in the underground marketplace, illicit operations are evolving and expanding services to offer “Cybercrime-as-a-Service” (CaaS). Let's take this opportunity to look into this business model, which continues to strengthen and grow in scope as threat vectors evolve. 



from The Growing Business of Cybercrime as a Service

Thursday, October 13, 2016

All Phish are Not Created Equal: The Evolving BEC Scam

All Phish are Not Created Equal: The Evolving BEC Scam

To further our Cyber Security Awareness Month initiative in helping you be #CyberAware, we want to focus on a specific type of phishing tactic that has gained popularity in the last few years: Business Email Compromise, commonly referred to as "BEC."  As cybercriminals evolve their attack methodologies, they have learned from their mistakes and BEC is an unfortunate example of how they are circumventing technology defenses and exploiting organizations' greatest vulnerability: employees.  



from All Phish are Not Created Equal: The Evolving BEC Scam

Friday, September 9, 2016

Federal Trade Commission Hosts Ransomware Workshop

FTC_Ransomware_play.png

The Federal Trade Commission (FTC) responded to the rising ransomware threat on September 7, 2016 with a technology workshop in Washington, D.C. The workshop brought security experts, including PhishLabs' Vice President of Threat Research, Joseph Opacki, together to address common questions and concerns around the ransomware threat. Opacki  joined a panel during the workshop to educate the audience on the overall landscape of the ransomware threat and reasons it's proliferating at such a high pace.



from Federal Trade Commission Hosts Ransomware Workshop

Thursday, September 8, 2016

Federal Trade Commission Fall Technology Series: Ransomware | September 2016

The Federal Trade Commission (FTC) responded to the rising ransomware threat on September 7, 2016 with a technology workshop in Washington, D.C. The workshop brought security experts together to address common questions and concerns around the ransomware threat, such as: How do ransomware extortionists gain access to consumer and business computers? What role can consumer and business education play in preventing ransomware infections? Are there steps consumers and businesses should be taking to reduce the risk of ransomware

The post Federal Trade Commission Fall Technology Series: Ransomware | September 2016 appeared first on PhishLabs.



from Federal Trade Commission Fall Technology Series: Ransomware | September 2016