Going Fishing ... or being Phished? by SPONSOR - Alchemy

Going Fishing ... or being Phished? by SPONSOR - Alchemy

Alchemy group logo

 

It’s summertime – you’re off on a fishing holiday. Meanwhile someone could be about to engage in their own phishing trip – more precisely spear-phishing. This is a targeted phishing attack intended to look credible to its recipient.

 

No-one is immune. The more senior you are the

more likely you are to be targeted by a spear-phisher or

be used as bait to target a junior member of staff.

 

Usually the spear-phisher aims to obtain information such as password and banking details to steal money or hold a firm to ransom. They may also seek to install malware on your computer systems.

 

Malware, as many of you know to your cost, can cause computer systems to grind to a halt. In seconds your business could be non-operational and worse, company data and confidential client data compromised – possibly irrevocably. Law firms are especially attractive targets.

 

A Security Breaches Survey by HM Government in 2015 revealed that 74% of small businesses and 90% of large organisations suffered a security breach in 2015. Symantec has described attackers as: “bigger, bolder and faster.”

 

How the spear-phisher operates

 

To be successful a spear-phisher needs to gather information from a variety of sources so that he can send a communication that appears to be from a trustworthy source. This is the reconnaissance phase.

 

Let’s say you’re a partner in a law firm and the firm’s website has your photo, email address and some information about you. You might also be on LinkedIn and even Facebook where perhaps you haven’t blocked non-Friends from seeing your account or you comment on the Wall of a Friend who hasn’t secured their Wall. Such disparate information can be fodder for the cyber criminal.

 

Construction and delivery of a Spear-phishing attack

 

Armed with this information they can send a personalised email which could be as simple as “Are you at your desk?” 

 

Because it seems to come from someone  you know, you might  innocently  respond  and  engage in further dialogue. This is where the cyber criminal has potentially got you hooked. So when they then send a link or an attachment or make a request that seems genuine if you take the bait then inadvertently you have enabled the cyber criminal to deliver their payload.

Don’t be a target!

There are some really simple steps that you and your firm can take to ensure you don’t become a target. For example: 

  • have a cyber security strategy, implement it and monitor it regularly

  • update software regularly

  • install firewalls and use email cleansing

  • use a contact form rather than having your email address on your business website

  • be cautious how much information you share on social media sites

  • have robust anti-malware at the desktop

  • back-up data - this can save your business and your firm's reputation if a spear-phisher manages to install malware on your computer systems

  • educate your staff about cyber crime and cyber security via regular training

Something that Alchemy Systems advises on is simulating spear phishing attacks which enable law firms to rapidly identify risk.

So don’t be spear-phished !

Identify your areas of risk then develop and

implement a cyber security strategy.


 

Alchemy Systems have 19 years of IT systems experience and are a Microsoft Partner. Alchemy Systems Designs, Supplies, Installs, Supports and Protects clients’ IT systems. The legal sector has always been a strategic focus. Our staff are experienced in the specific needs and challenges of law firms from service desk to strategy to protection services.

Tel. 0330-043-080198 email. sales@alchemysys.co.uk

www.alchemysouthwest.co.uk


Like   Back to Top   Seen 447 times   Liked 0 times
Subscribe to Updates And Join Over 1.2K Subscribers Today!

Subscribe to:
x

Subscribe to Updates

If you enjoyed this, why not subscribe to free email updates and join over 1274 subscribers today!

Subscribe to updates



Subscribe to:

Alternatively, you can subscribe via RSS RSS

‹ Return to

All email subscriptions must be confirmed to comply with GDPR.

I've already subscribed / don't show me this again