Tips and Advice for Staying Safe Online During COVID-19
- by Brittany Day
In the midst of the COVID-19 crisis, businesses are relying more heavily on cloud email than ever in order to operate in this challenging remote environment. With office employees now becoming remote workers, many organizations are hurriedly moving to vulnerable cloud platforms like Office 365 during this pandemic.
Rushed deployments frequently lead to misconfiguration of cloud email, leaving users even more susceptible in these platforms. Attackers have taken note of this trend, and are capitalizing on inadequately secured cloud email accounts, launching dangerous coronavirus-related exploits targeting cloud email users. Because of the vital role that email plays in any business’s operations, it is by far the most popular attack vector among cyber criminals. According to SANS Institute, 95% of cyberattacks are initiated with a spear phishing email.
The FBI has issued multiple warnings regarding sophisticated COVID-19 related business email compromise (BEC) scams targeting cloud email users, and has emphasized the importance of fortifying Office 365 email with critical additional defenses. Guardian Digital CEO Dave Wreski states, “Consistent with the FBI’s findings, our EnGarde Cloud Email Security has identified and blocked more malicious emails targeting Office 365 users in April of 2020 than in any other month in the company's twenty-year history. Now is definitely not the time to overlook the importance of securing cloud email with multi-layered, real-time protection.”
What Are My Risks as a Cloud Email User?
Understanding the heightened digital risk that you face in this uncertain, fearful time is critical in staying safe while working remotely. Cloud email users face a plethora of threats on a daily basis that they may not be aware of. These “hidden dangers” include:
- Phishing & Malware: Cyber criminals are taking advantage of remote workers’ increased dependence on email and distracted behavior while working from home, along with the curiosity and fear that are characteristic of the current environment, and are launching sophisticated, highly-deceptive coronavirus-related phishing campaigns. These convincing, timely scams employ deceptive tactics such as impersonating government agencies, advertising fraudulent test kits and asking for donations. According to the US Department of Homeland Security, there has been “an increase in phishing attacks under the guise of coronavirus-themed emails containing attachments”. Many of these phishing campaigns contain dangerous malware designed to infect and destroy users’ computers.
- Insecure networks: The COVID-19 crisis has introduced a myriad of challenges that businesses are struggling to meet, such as undersized VPN infrastructure, insufficient bandwidth and limited availability of managed devices for employees to take home - and network security has suffered as a result. Incidents involving insecure configurations of services and firewalls have increased, as administrators are taking shortcuts to enable remote access.
- Office 365 security shortcomings: The default security provided in Office 365 is glaringly inadequate, leaving remote workers vulnerable to credential phishing and other advanced exploits. According to the FBI, “Thirty percent of phishing attacks make it through existing systems and are opened by target users.” It is no surprise that 92 percent of companies have at least one credential that’s been compromised. And Office 365 risk is now greater than ever - the United States Department of Homeland Security has warned that rushed remote Office 365 deployments may lead to overlooked critical security configurations.
- Office 365 vulnerabilities: In addition to the alarmingly insufficient default protection provided in Office 365, vulnerabilities are frequently discovered in the cloud platform itself. Two serious Office 365 remote code execution vulnerabilities, which enabled attackers to coerce users into opening malicious files, were identified in 2019.
Tips & Advice for Staying Safe While Working Remotely
In this tumultuous time, we want to help you avoid the dangers associated with increased cloud email use. Here are a few tips and best practices to help keep you and your company secure online:
- Watch for phishing, ransomware and other email-borne attacks.
- Don’t rely on endpoint security alone - the endpoint is the last line of defense, and if something goes wrong, it provides malicious hackers with easy access to your system.
- You should be the only user to access your home endpoint. When your home PC connects to your company’s network, it becomes one of the network’s various endpoints. Use a strong password in your user account in your operating system and, if you share your PC, make sure that each user has his or her own account in your operating system.
- Use a VPN to encrypt data between you and your server. When selecting a VPN, watch for pitfalls such as free VPNs which often carry inherent security flaws and privacy issues.
- Avoid insecure networks.
- Ensure that your operating system and all applications are updated - remember that your operating system and applications are only as secure as their latest security patches.
- Be wary of emails from personal email addresses.
- Use email authentication protocols to confirm the legitimacy of messages you receive. Sender authentication protocols help prevent spoofing, business email compromise (BEC) and other dangerous exploits.
- Most importantly: Implement a remotely-managed cloud email security solution that seamlessly complements default cloud email protection with critical additional layers of defenses. Defense-in-depth is crucial in fortifying cloud email against today’s advanced threats.
Guardian Digital EnGarde Cloud Email Security: Real-Time Protection Against Emerging COVID-19 Threats
Staying safe online may seem challenging and overwhelming in this heightened digital threat environment. Ninety-three percent of organizations are moderately to extremely concerned about cloud security. The good news is, choosing the right solution can greatly simplify securing cloud email - offering businesses’ invaluable peace-of-mind in this stressful time. Implementing a remotely-managed cloud email security solution that seamlessly integrates with organizations’ existing email infrastructure, fortifying cloud email with critical additional layers of defenses, is the most effective way for businesses to protect against emerging exploits - both in good times and in times of crisis.
Guardian Digital EnGarde Cloud Email Security is a comprehensive, remotely-managed solution that provides multiple layers of real-time protection - safeguarding remote workers, securing sensitive data, and ensuring business continuity and maximum productivity.
Key features and benefits of EnGarde’s protection include:
- Complete end-to-end email vigilance, preventing ALL malicious emails from reaching the inbox and eliminating the risk of human error
- Real-time defense against social engineering and impersonation attacks
- Multiple layers of sophisticated detection engines powered by Artificial Intelligence and Machine Learning
- Protects sensitive data shared via email with advanced encryption and authentication protocols
- Seamless implementation and rapid return on investment (ROI)
- Scalable cloud-based system simplifies deployment and increases availability
- Expert, caring around-the-clock customer support services and remote system monitoring
- Effectively Securing Business Email Accounts: Are Employees the Weakest Link?
- Encryption: An Essential Yet Highly Controversial Component of Digital Security
- Business Email Security Redefined: Key Benefits of Securing Your Business Email with Guardian Digital
- 8 Business Email Security Best Practices
- Demystifying Email Encryption: Stop Sender Fraud
- Demystifying Phishing Attacks: How to Protect Yourself Now
- Demystifying Tax Fraud: How to Avoid Falling Victim to Deceptive, Costly Scams This Tax Season
- Coronavirus Phishing Scams are On the Rise - Is Your Business Email at Risk of Infection?
- Dave Wreski: Founder of Guardian Digital – Open Source Cloud Email Security
- NJ DHS: Email Security for Businesses Beyond COVID-19
- New Ransomware Warnings: Is Your Business Safe from This Silent Threat?
- FBI: Existing Cloud Email Protection Inadequate Against Phishing, Ransomware
- Email Risk is Universal: Securing Business Email in Every Industry Sector
- How To Safely Navigate Office 365 While Working Remotely
- Tips and Advice for Staying Safe Online During COVID-19
- Why Your Business Needs Better Email Security
- Defending Against COVID Email Spoofing Attacks with DMARC
- You’ve Got Mail: How To Tell If It’s Fraud
- Open-Source Security Is Opening Eyes
- Think Like A Criminal: How To Write A Phishing Email
- The Four Biggest Email Threats Your Business Faces Today
- Learn About DocuSign Phishing Attacks in 3 Minutes
- Understanding Payload-Less Email Attacks in Under 3 Minutes
- Demystifying Fileless Malware in Less than 3 Minutes
- How to Protect Sensitive Data & Maintain Client Trust in Financial Services Industry
- Exchange Servers Are Vulnerable - Learn How To Secure Your Email Server Now
- Apache SpamAssassin Leads A Growing List of Open-Source Projects Taking Steps to Correct Instances of Racism and White Privilege
- Cyber Risk Is Greater than Ever in the Legal Industry
- Your Current Approach to Email Security May Not Be Enough
- Ways to Prevent Email Account being compromised in a Breach
- Celebrating 20 Years of Revolutionizing Digital Security
- IBM Closes its $34 Billion Acquisition of Red Hat
- Interview with Security Expert and Author Ira Winkler
- What is Phishing Email? How to prevent Phishing email scams?
- Ways Our Business Email Exceed Your Expectations
- Spear Phishing Protection - Definition & How To Recognize Spear Phishing Email
- What is Whaling (Whaling Phishing)? & How to Prevent Whaling attacks?
- Ransomware Attack Explained - Best Practices For Ransomware Protection
- Business Email Compromise (BEC) - Definition & Prevention From BEC Attacks
- Wire Transfer Scams Involving Real Estate Transactions: How to Prevent Fraud with Effective Email Security
- Guardian Digital and Mautic: A Dynamic Open-Source Duo
- Email Malware - How to Recognize & Prevent Malware Email Attack
- An Open-Source Success Story: Apache SpamAssassin Celebrates 18 Years of Effectively Combating Spam Email
- What is Spam Email - Types & How to Prevent Spam Emails?
- Email Virus - Complete Guide to Email Viruses Plus Best Practices
- What Is A Zero-Day Attack & How To Prevent Zero Day Exploit?
- 2020: A New Decade of Digital Threats - Is Your Business Email Secure?
- Linux: An OS Capable of Effectively Meeting the US Government’s Security Needs Heading into 2020
- Email Security: Complete Guide on Email Security & Types of Email Threats
- Guardian Digital Keeps its Customers Protected from Intel Design Flaw
- Security Spotlight: Open Source Email Security Solutions
- Top Six Advantages of Open Source Development/Products
- Python and Bash - Contenders for the most used scripting language
- Guardian Digital Outlines Top 4 Benefits of Choosing Cloud
- Unrivaled Protection Against Today’s Most Dangerous Threats
- Guard Your Email Accounts Against Today’s Most Dangerous Threats
- Security Highlights from Defcon 26
- Linux / Open Source FAQs: Common Myths / Misconceptions
- Email Security FAQs Answered by Guardian Digital
- Guardian Digital Mail Systems: Designed to be Secure Without Fail