Compared to last year’s “2018 Email Security: Trends, Challenges, and Benchmarks,” which identified a perception gap between email security and regular white-collar professionals, GreatHorn’s new data shows that gap still exists as employees with limited or no involvement in email security are three times more likely to say the only email-based attacks they receive in their inbox is spam. This is a major factor why simulated phishing click-rates dropped only 1% from 2017 to 2018, despite businesses investing millions in security awareness training programs and other email security technologies.
“Our latest research shows that employees – particularly non-technical professionals – overestimate the efficacy of their workplace’s email security strategy,” GreatHorn CEO Kevin O’Brien said. “There is an alarming sense of complacency at enterprises at the same time that cybercriminals have increased the volume and sophistication of their email attacks. Businesses must protect themselves at every point of the email lifecycle, including post-delivery, to adequately protect themselves from modern spear phishing and social engineering attempts.”
Almost Half of Respondents See Email Attacks at Least Weekly
GreatHorn found that 24.4% of survey respondents indicated that malicious email messages, including impersonations, wire transfer requests, W2 requests, payload attacks/malware, business services spoofing, and credential theft attempts, reach their inbox every day, with an additional 25.4% that report seeing attacks at least weekly.
When separated into two groups, email security and white-collar professionals, GreatHorn found a stark contrast in the frequency of malicious email threats reported. About one-third (32.8%) of email security experts report seeing threats every day, and an additional 27% report weekly, for a total of 59.8% seeing threats at least weekly. This marked difference in perception speaks to the training and awareness gap that was first highlighted in last year’s report.
“Just Spam” or Something More Malicious?
Data from GreatHorn’s research shows that nearly half (48.5%) of white-collar professionals report seeing only spam in their inboxes, while only 16.4% of email security professionals said the same. This indicates a larger nomenclature problem that causes two-thirds of white-collar professionals to mischaracterize sophisticated email threats as “just spam.” This conflation of spam mail and dangerous email threats has bad implications for enterprises as employees underestimate the dangers associated with malicious emails, putting themselves and the business at risk.
Businesses Are Not Getting Enough from Email Security Investments
When asked, “Which of the following are problems for you despite your current email security solution?,” 79.4% of all respondents indicated fundamental issues with their solution. Areas where email security professionals said their systems were vulnerable include:
- 34.2% report “challenges with remediation”
- 26.6% report their current solution, “Doesn’t stop internal threats (e.g. if a user account is compromised)”
- 21.2% report “Missing payload-free attacks (e.g. impersonations, social engineering, etc.)”
- 19.8% express concern that their solution “Negatively impacts business operations (e.g. too many false positives)”
- 18.9% report “Missing payload attacks (e.g. malicious attachments and/or links)”
Over a third (34.3%) of email security professionals felt this situation, in which glaring email security vulnerabilities were both present and exposing the company to risk, was “good enough.” More senior roles (i.e. technical decision makers, budget owners, and CISOs) were much more likely to be either “dissatisfied” or “very dissatisfied” with their email security solution.
These responses demonstrate the industry’s view that email-based attacks are unavoidable and unstoppable. Enterprises must assume that some amount of malicious mail will bypass any email security strategy and fortify their security posture by implementing technologies that can intelligently identify, alert on, and disarm attacks that reach corporate inboxes.
More Resources
- To download the full report, please go to greathorn.com/2019-benchmark-report
- Join the July 25 webinar discussing the findings of the report at greathorn.com/2019-benchmark-webinar
- For detailed analysis of the report, visit the GreatHorn blog at: https://www.greathorn.com/blog.
About GreatHorn
GreatHorn safeguards cloud email from advanced threats such as individual and brand impersonations, credential theft attempts, malware, ransomware, and other advanced social engineering-based phishing attacks by protecting organizations before, during, and after an email attack. Through its proactive threat detection engine, in-the-moment user education, and robust incident response capabilities. GreatHorn’s threat detection and response platform frees security teams from time-consuming email security management while enabling them to respond to genuine threats faster than ever before. More information is available at www.greathorn.com.