Email security continues to be top of mind for organizations as attackers become more devious in how they conduct their attacks. Companies face evolving threats, which are often extremely personalized and mimic common real-world emails they receive. To better understand the climate of email security, Barracuda surveyed 660 IT professionals across various industries and locations on the impact of phishing.
An Increased Sense of Confidence
Sixty-three percent of professionals report that their organization’s data and systems are more secure than they were one year prior. Among the three regions surveyed — America; Europe, the Middle East, and Africa (EMEA); and the Asia-Pacific region (APAC) — APAC reported the highest sense of security (70%), while EMEA reported the lowest (52%). Although this rise is likely caused by an increased security presence and education practices, if an organization lacks the tools to detect these threats, it may be superficial.
Despite an overall positive outlook, phishing and ransomware top the list of security risks that organizations are not fully prepared to deal with, along with spearphishing, malware, viruses, data loss, spam, smishing (that is, phishing via text message), email account takeover, and vishing (phishing via phone). Only 7% of organizations are not worried about any of these risks. In fact, email threats continue to proliferate and have a major impact. On average, 82% of organizations claim to have faced an attempted email-based security threat in the past year, although the figures differ slightly by global region.
Loss from a Breach Is More Than Financial
In addition to 74% of organizations reporting that email security attacks have had a direct business impact, they are also affecting the personal lives of IT security professionals, with nearly three-quarters experiencing higher stress levels, worrying outside the office, and being forced to work nights and weekends. APAC reports the highest levels of personal impact from email security attacks.
In addition, an overwhelming 78% of organizations say the cost of email breaches is increasing, with one-fifth saying they are increasing dramatically. Identifying and remediating threats, communicating with those affected, business interruptions, and IT productivity losses are all factors, as well as potential data loss, regulatory fines, and brand damage.
As a result, 66% of respondents claim that attacks have had a direct monetary cost on their organization in the last year. Nearly a quarter (23%) say attacks have cost their organization $100,000 or more.
In conjunction with the previously noted increase in a sense of security, employees continue to play an integral role in their company’s security. Ninety-four percent of organizations say employees are reporting suspicious emails to IT on a daily basis, but 58% say most emails reported to IT aren’t actually fraudulent. More than three-quarters (79%) of organizations say their employees aren’t good at spotting suspicious emails for a number of reasons, which shows a lack of readiness to spot email threats.
Only 21% say that the employees do a great job of alerting IT to suspicious emails only when needed. Additionally, 18% report that their employees were careless and did not recognize obviously suspicious emails.
These findings are concerning because phishing emails that prey on the poor security awareness of end users is one of the most common ways for attackers to download malware and steal data from organizations. Plus, reporting the wrong types of emails only wastes the time of already-stretched security teams. In addition to better awareness training, improved tools are needed to filter potentially dangerous emails and ensure they never make it into the inboxes of end users in the first place.
Phishing and Malware Are Common
Email security is a challenge because there are several types of threats that are commonly seen. With increased security technology, attackers are using more personalized methods to engage with victims, often bypassing traditional security systems.
Phishing remains top of mind, as 43% of organizations have been the victim of a spearphishing attack in the past 12 months. Seventy-five percent of security professionals have personally received training on phishing in the last year, which is much needed because 70% of organizations have experienced a variety of direct business impacts as the result of these attacks.
Furthermore, most IT professionals (79%) say they are worried about attacks and breaches stemming from inside the organization. Their fears are valid: A hacker could compromise an employee’s email account via spearphishing and use it to target other with business email compromise attacks or phishing emails that appear very authentic.
In addition to phishing threats, an overwhelming 90% of Office 365 users have security concerns. Eighty-six percent of organizations agree that third-party email security solutions are essential for keeping an Office 365 environment secure.
The Future of Email Security
Email threats will continue to evolve at the same time as protection methods become more advanced. Organizations must keep email security in the forefront of their efforts and ensure that employees are educated and aware.
Mike Flouton is vice president for Barracuda’s email security business. In this role, he oversees product management for Barracuda’s portfolio of email security solutions: Barracuda Total Email Protection, Barracuda Essentials, Barracuda Sentinel, and Barracuda PhishLine. View Full Bio