One significant finding published in our 1H 2022 FortiGuard Labs Threat Report is that ransomware is rampant. We’re seeing ransomware attacks becoming more sophisticated and aggressive, with attackers introducing new strains and updating, enhancing, and reusing old ones. What’s especially concerning as we look back at the first half of 2022 is that the number of new ransomware variants we identified increased by nearly 100% compared to the previous six-month period.
How does ransomware make its way into an organization in the first place? Ransomware can be delivered to an unsuspecting victim in many ways. Yet according to research, phishing is the number one attack vector associated with ransomware. This is why it’s critical for all employees to be cyber aware and cybersecurity training can make the difference from being one click away from a breach.
A phishing attack is a type of cybersecurity threat that often targets users directly through email, text message, or on social media. During one of these scams, the attacker poses as a trusted contact to steal sensitive data like login credentials, account numbers, and credit card information.
Phishing attempts can be diverse, as attackers are continually becoming more sophisticated and creative with their techniques. Some well-known types of phishing attacks include spear phishing, clone phishing, vishing, whaling, snowshoeing, and business email compromise, to name a few.
There’s also been a reported uptick in a newer method of phishing recently, referred to as Multi-Factor Authentication (MFA) Fatigue. This is when a threat actor runs a script that attempts to log in with stolen credentials over and over, which sends an onslaught of MFA push requests to a user’s device. The intent is for the user to become overwhelmed by the stream of notifications and accidentally hit “approve,” giving the malicious actor their credentials.
What unites these exploits is that they share a common goal: identity theft or the transfer of malware.
When it comes to preventing cyberattacks like phishing, your security team and your organization’s employees both have important roles to play. From having the right technologies to implementing organization-wide cybersecurity training programs, there are many simple actions enterprises can take to improve their security posture and defend against potential compromises.
Here are five best practices we recommend every enterprise implement to guard against phishing:
1. Enable spam filters: This is perhaps the most basic defense an organization can take against phishing. Most email programs include basic spam filters that automatically detect known spammers. You can also purchase more comprehensive spam filters that weed out emails based on additional attributes such as headers, language, and the content within the email. Spam filters are helpful because they provide an extra layer of security for your network, which is especially important given the popularity of email as an attack vector.
2. Update software regularly: Make sure that the software and operating systems your organization uses are updated regularly. Patching can harden vulnerable software and operating systems against certain attacks. Updating security tools helps them better detect and remove malware or viruses that may have inadvertently been loaded onto an employee's laptop or phone via a phishing scheme. However, while many software manufacturers provide regular updates or notifications when a new patch is released, not all do, making it important to regularly visit your vendors’ websites to check for updates.
3. Implement Multi-Factor Authentication (MFA): MFA requires a user to leverage multiple pieces of information before logging into a corporate network and gaining access to its resources. Generally, this requires implementing at least two of the three elements of MFA: something you know (like a password or PIN), something you have (like a physical token, laptop, or smartphone), and something you are (like a fingerprint, iris scan, or voice recognition.) These layers of authentication are essential in the event a scammer has already stolen the credentials of some employees. With MFA in place — especially if it includes biometric authentication — scammers are blocked from accessing sensitive data.
4. Back-up data: All corporate data should be encrypted and backed up regularly, which is critical in the case of a breach or compromise.
5. Block unreliable websites: Use a web filter to block access to malicious websites in the event an employee inadvertently clicks on a malicious link.
According to the Verizon Data Breach Investigations Report for 2022, 82% of successful breaches involved the human element. While having the right security technologies and processes in place is undoubtedly critical for protecting an organization, humans are often the weakest link in an enterprise’s cybersecurity ecosystem. Hence, educating employees on cybersecurity best practices is a must.
When implementing an ongoing, organization-wide education program, identify key areas to cover that present the biggest risks to the end user (and inevitably your business). In the case of phishing, offer employees practical tips for identifying a potential phishing attempt. For example, encourage them to review emails closely — verifying the sender’s address, reviewing the grammar and spelling, and looking for links or attachments — before taking any action.
Fortinet’s Security Awareness and Training service provides organizations with education programs to help create a cyber-aware culture in which employees are more likely to recognize and avoid falling for common cyberattack attempts.
While phishing is a popular attack technique among cybercriminals, the reality is that it’s just the tip of the iceberg. Cybercriminals are frequently adding new techniques to their playbooks to sidestep defense mechanisms, evade detection, and scale their operations. Our threat intelligence shows that cybercriminals are finding new attack vectors to experiment with related to familiar exploits and increasing the frequency with which they execute them.
As a result, security teams must be more agile than ever before, making integrated security solutions a must-have for any enterprise. Creating a holistic cybersecurity mesh architecture — as opposed to stitching together multiple point products — allows for much tighter integration and increased automation, making it easier for security teams to coordinate quickly and respond effectively in real time.
Fortinet offers products and services that uniquely support anti-phishing efforts, such as FortiMail, our secure email gateway solution. Our entire portfolio of solutions and products are designed to work seamlessly together as part of the Fortinet Security Fabric — something many refer to as a Cybersecurity Mesh Architecture (CSMA). This deep integration, powered by a common operating system (FortiOS), enables organizations to share threat intelligence, correlate data, and automatically respond to threats as a single, coordinated system.
Fortinet offers the only single-vendor solution to consolidate critical technologies and converge critical environments — including security, networking, endpoints, and the cloud — into a single platform. As cybercriminals constantly find new ways to infiltrate networks, this type of holistic approach to security has never been more vital.
Find out more about how Fortinet's Training Advancement Agenda (TAA) and Training Institute programs—including the NSE Certification program, Academic Partner program, and Education Outreach program—are helping to solve the cyber skills gap and prepare the cybersecurity workforce of tomorrow.