RESOURCES
The Persistent Threat of Business Email Compromise
The Persistent Threat of Business Email Compromise
Business Email Compromise (BEC) is a sophisticated type of email and identity based attack that doesn't rely on malware or malicious links. Instead, it leverages social engineering tactics to manipulate human trust and judgement. This makes BEC attacks particularly challenging to detect and prevent, even for organisations with robust protection infrastructures and cyber security awareness programmes.
The financial impact of BEC attacks is staggering. According to the FBI's Internet Crime Complaint Center (IC3), in 2023 alone, there were 21,489 BEC complaints with adjusted losses exceeding £2.3 billion. The European Union Agency for Cybersecurity (ENISA) also highlights BEC as attackers' preferred method for financial gain in its 2023 cyber threat report. This persistence can be attributed to several factors:
- Constant evolution of attack techniques
- Human error and social engineering vulnerabilities
- Limitations of automated detection systems
- Lack of comprehensive, multi-layered defence strategies
How BEC Attacks Work
A typical BEC attack begins with an "Email Account Take Over." Attackers use various techniques to gain access to a corporate email account, including:
- Brute force attacks
- Password spraying
- Exploiting data from previous breaches
- Phishing campaigns
- Malware attacks on compromised devices
Once an account is compromised, the attacker can:
- Impersonate key financial personnel
- Investigate financial subjects and content that can be manipulated
- Send fraudulent emails requesting payments or sensitive data
- Set up email forwarding rules to gather information
- Export sensitive documents
Detecting and Responding to BEC Attacks
To combat BEC attacks effectively, organisations need a comprehensive approach that goes beyond traditional email security measures and build capabilities to detect specific BEC related indicators of compromise in the networks. These include but not limited to:
- Tracking behavioural anomalies in email and cloud application usage
- Focusing on high-risk users with access to sensitive data
- Identifying phishing attempts from compromised accounts
When a potential BEC attack is detected, swift response is crucial. This involves:
- Validating the compromised account and notifying the owner
- Revoking active sessions and tokens
- Enforcing password resets and multi-factor authenticationImplementing access limitations and isolation measures
- Investigating potential data leaks on the dark web
Detect the Subtle Signs of BEC attempts
Whilst general cybersecurity measures and awareness programmes are essential, organisations need specialised solutions that can detect the subtle signs of BEC attempts and respond rapidly to minimise potential damage. By implementing a dedicated BEC detection and response service, organisations can:
- Proactively identify and mitigate BEC threats
- Minimise the risk of financial loss and reputational damage
- Prevent the use of corporate accounts in broader attack chains
- Enhance overall email security without overburdening IT teams
Remember, when it comes to BEC, a multi-layered approach combining technology, awareness, and BEC-specific detection and response is key to safeguarding your organisation's assets and reputation.
Explore Cynode’s Business Email Compromise Detection and Response service here: Cynode MDR for BEC
-
Investing in Dark Web Monitoring: A Practical Guide
Should you invest in a Dark Web Monitoring service? The answer is not as straightforward as you might think—it really depends. Whilst Dark Web Monitoring is undoubtedly valuable, where does it rank in your list of priorities? For instance, if you have a limited budget, should you invest in Dark Web Monitoring or a Security Awareness Programme? The answers to such questions vary for each organisation, but there are some general principles that can guide your decision-making process.
-
The Risks of Increasing SaaS Use
Organisations increasingly rely on cloud applications, with small enterprises using over 20 SaaS apps per user and large companies exceeding 250 per company. This growth introduces significant cyber security risks, including unauthorised access and Shadow IT, where unsanctioned apps are used without oversight. To mitigate these risks, companies need advanced monitoring solutions like Cynode’s MDR for Cloud Apps Shadow IT, which offers visibility, consent policy enforcement, and threat detection across SaaS platforms, ensuring security and compliance.
-
Interview with Senior Cyber Advisor Per-Olov Kask
Delve into the fascinating career journey of a seasoned cyber security professional who has dedicated over three decades to the ever-evolving IT and cyber security landscape. Starting as an IT technician in 1993, our expert quickly rose through the ranks to become a country IT manager, driven by a passion for combating emerging cyber threats. In 2022, this journey led to an impactful role at Cynode as a Senior Cyber Advisor. Join us as we explore his experiences, insights, and the innovative approaches that make Cynode a leader in the cyber security field.
-
Regular EDR Policy Tuning
The cyber security world has recently focused on EDR technology due to its significant impact across industries. This post explores the evolution from early antivirus software to EDR platforms. Key milestones include the introduction of commercial antivirus software in 1987, the emergence of heuristic and behavioural detection methods in the early 2000s, and the development of Next-Gen Antivirus (NGAV) in 2010. EDR solutions, emerging around 2013, are crucial for detecting, investigating, and mitigating security threats but require regular policy updates and meticulous tuning for optimal performance.
-
Mastering Log Management: Enhancing SIEM and SOC Efficacy
Efficient log management is critical for SIEM and SOC efficacy. Challenges include log agent malfunctions, configuration errors, and network issues. This blog explores four log problem categories, from detection failures to incomplete logs, and introduces innovative solutions for proactive threat detection and response. Learn how Cynode's integrated threat simulation and log validation processes ensure optimal log coverage and enhanced security monitoring. Stay ahead of cyber threats with robust log management practices.
-
Understanding WebApp Exposure
WebApp Exposure Monitoring involves regular assessments and updates to perimeter defence platforms like WAF policies, ensuring alignment with the latest threat intelligence. Having a proactive stance to WebApp attacks is crucial as cyber threats incredibly fast, often outpacing traditional security defences. The process of continuously monitoring web applications allows organisations to more readily detect anomalies and respond to threats in real-time, minimising the risk of data breaches and other cyber incidents.
-
Introduction to Managed Security Service Providers (MSSPs)
Businesses increasingly struggle with cyber security management, especially with limited resources. Managed Security Service Providers (MSSPs) like Cynode offer comprehensive, efficient solutions, managing everything from security infrastructure to incident response, often using cloud services for cost efficiency. This article explores the benefits and services MSSPs provide, underscoring their importance in modern cyber security strategies.
-
Improving SIEM Efficacy as the Market Evolves
As the SIEM market evolves with new mergers and partnerships, Cynode supports practitioners to ensure no security event is missed, offering comprehensive services from threat-centric log and rule validation to complete SIEM management.
-
Welcome Konrad Falk as Our New Senior Cyber Advisor & Architect!
Konrad brings extensive experience in Cyber Security and IT, with a background in programming, networking, and security. Passionate about securing companies and educating others, he values the trust of our leadership and is eager to manage security incidents and tackle evolving threats hands-on.
-
“Trust me, I was an engineer” – Björn Nilsson
We are pleased to announce Björn Nilsson as the new Head of Security Operations Sweden at Cynode. His extensive experience in cyber security and IT infrastructure marks a significant milestone in enhancing our capabilities. Björn brings a wealth of expertise from various critical roles within the industry.
-
Cynode Boosts Team with Gustav Bivstedt's Technical Expertise
Cynode hires Gustav Bivstedt as a Cyber Advisor to enhance our Cyber Advisory and Assurance Services. His expertise strengthens our technical capacity and supports business growth, including new offerings in security testing, cyber maturity assessments, and proactive risk management with Cyber Threat Intelligence.
-
Meet our "VP of Product" Cumhur Hatipoglu
As Cynode’s CMO, I am constantly impressed by our team's innovation and engagement. Cumhur Hatipoglu, our new VP of Product, enhances our mission to innovate in cyber security and MDR services. His approach integrates NIST CSF and best security practices to ensure our solutions meet clients' evolving needs.
-
Hacking and Cyber Warfare Go Hand in Hand
Sweden, amidst its NATO application and tensions with Russia and Turkey, has experienced a rise in political cyber-attacks. Groups such as Anonymous have targeted governmental infrastructures, leading to data leaks. Escalation of cyber-crime and nation-state backed cyber warfare necessitates global enhancement of defense measures.
-
EU updates NIS Directive. Are you compliant?
The European Union introduced the NIS 2 Directive to improve the cyber security of critical infrastructure systems within its member states and to ensure that digital service providers and operators of essential services have adequate security measures in place to secure their networks and data.
-
Rise of Cyber Due Diligence in M&A Processes
Sweden's post-pandemic economic recovery has spurred M&As. Cynode emphasises integrating cyber due diligence to address vulnerabilities, protect essential information, and optimise security spending, enhancing the security posture before, during and after M&As.