Latest / Tech Talks With Kinsoft / WA Government – Systemic Microsoft 365 Security Failures
Transcript
- 0:00Welcome to Tech Talks with Kinsoft. I mean, this
- 0:02is the show where we take, you know, complex
- 0:04tech and security news, and we try to extract
- 0:07the most important, actionable insights for you
- 0:10to apply to your own work. And today... Well,
- 0:13imagine spending millions of dollars to build
- 0:16this state of the art digital fortress for your
- 0:18organization. Oh, yeah. Best firewalls, massive
- 0:21budgets. Exactly. You have the complex passwords,
- 0:23the security teams, but then your entire system
- 0:26gets completely compromised. And it's not by
- 0:29some team of elite hackers burning zero day exploits.
- 0:33It's because the foundational architecture basically
- 0:35leaves the back door propped open with a brick
- 0:38just because someone couldn't remember their
- 0:40key. It's terrifyingly common. We constantly
- 0:43look for these exotic threats on the horizon.
- 0:45But I mean, the most devastating breaches, they
- 0:47usually just stem from mundane, everyday configurations.
- 0:50Right. We all just sort of assume that enterprise
- 0:53software is secure by default. And that assumption
- 0:55is, well, it's incredibly dangerous. Yeah. Which
- 0:57brings us to our core source for today's discussion.
- 1:00So on March 6th, 2026, the Western Australian
- 1:03Office of the Auditor General, the OAG, released
- 1:06this report. It uncovered systemic Microsoft
- 1:10365 security failures across seven different
- 1:13state government entities. Seven. That's a huge
- 1:17sample size for systemic failure. It really is.
- 1:19And to put this into perspective for you listening,
- 1:22Microsoft. It isn't just an email client anymore,
- 1:25is it? Oh, no. Far from it. It's essentially
- 1:28the central nervous system of a modern enterprise.
- 1:31It handles your identity management, internal
- 1:33comms, file storage, data processing, automation,
- 1:36all of it. Yeah. So if that system suffers from
- 1:39systemic vulnerabilities, I mean, the attacker
- 1:41doesn't just have your emails. They have the
- 1:43literal keys to your entire operational kingdom.
- 1:46Right, which is a perfect segue. I want to avoid
- 1:48just, you know, reading off a dry, gross -free
- 1:50list of technical vulnerabilities today. So let's
- 1:52look at... how these weaknesses actually stack
- 1:53up in the real world. The report details this
- 1:56anatomy of a $71 ,000 theft. Yes, the BEC incident.
- 2:01Exactly. And the timeline of how it unfolded,
- 2:04it's just a masterclass in how threat actors
- 2:07exploit these seemingly minor misconfigurations.
- 2:10So where does this start? Well, it's a textbook
- 2:12business email compromise, right? Or BEC. And
- 2:16it demonstrates exactly how patience pays off
- 2:19for a threat actor. It began with a senior officer
- 2:23at one of these audited government entities.
- 2:25Their account was compromised through a highly
- 2:28targeted phishing attack. Okay, let's pause right
- 2:31there. Because IT departments are constantly
- 2:33telling us, you know, multi -factor authentication,
- 2:36MFA, that's the silver bullet against phishing.
- 2:38Right, the golden rule. Yeah. If I have a password
- 2:40and an MFA prompt on my phone, I should be safe.
- 2:43But the attacker just defeated the system's MFA.
- 2:46They walked right through it. Right. And we'll
- 2:48get into the mechanics of exactly how they bypassed
- 2:50in a minute, but I really want to focus on what
- 2:52happened immediately after they got through that
- 2:54front door. Because once they were inside, the
- 2:57attacker registered their own unmanaged device
- 2:59from an overseas location. Yeah, and that specific
- 3:02action registering a brand new device, that is
- 3:06where the technical failure becomes catastrophic.
- 3:09How so? Well, think about it. In a properly configured
- 3:12environment, an overseas IP address attempting
- 3:15to register an unrecognized mobile device, for
- 3:19a senior official no less, that should trigger
- 3:21a massive alert. Right. sirens going off everywhere.
- 3:24Exactly. The system should automatically block
- 3:27the action or, you know, at the very least force
- 3:29a manual review by an admin. But because the
- 3:33governance controls at this entity were just
- 3:34so loose, the system basically treated it as
- 3:38a normal. everyday user action. No alarm sounded
- 3:41at all. None. Zero. So it's basically like a
- 3:44burglar stealing your house keys, walking in,
- 3:46and then changing the locks on the doors so you
- 3:48can't get in. That is exactly what happened.
- 3:50They effectively locked the legitimate owner
- 3:51out of their own account without anyone noticing.
- 3:53That's wild. And then they didn't just, you know,
- 3:55smash and grab. They set up email forwarding
- 3:58rules to automatically funnel specific communications
- 4:01out of the inbox to hide their tracks. Yeah.
- 4:03And then they just sat there for weeks. Yeah,
- 4:06that's what we call dwell time. They were just
- 4:08conducting quiet reconnaissance. For a whole
- 4:11month, the attacker sat... In the guest room,
- 4:15so to speak, and studied the officer's emails.
- 4:17A whole month. A whole month. They mapped out
- 4:20the organizational chart. They learned the internal
- 4:22jargon. They observed exactly how the billing
- 4:24process worked. They figured out, you know, who
- 4:27authorized the payments. That's they're learning
- 4:30the actual rhythm of the business. Precisely.
- 4:32And they use all that intelligence to construct
- 4:35a highly believable payment scenario. They submitted
- 4:39a fraudulent invoice that looked perfectly legitimate.
- 4:43I mean, it used the correct internal billing
- 4:45codes and it mirrored the senior officer's exact
- 4:48communication style. Because they've been reading
- 4:50their sent folder for a month. Exactly. And because
- 4:52it originated from the actual authenticated internal
- 4:55account of a senior leader. It bypassed all standard
- 4:59email security filters. The entity paid out $71
- 5:02,000. Oh, wow. And the craziest part to me is
- 5:06when investigators finally came in to figure
- 5:08out what went wrong. They hit a total brick wall.
- 5:11The report says the entity hadn't retained sufficient
- 5:14logs, so a full forensic review was literally
- 5:17impossible. They were completely blind. Completely.
- 5:20But I want to circle back to the point I flagged
- 5:22earlier because I think a lot of people listening
- 5:23are wondering the same thing. You mentioned the
- 5:25attacker defeated the MFA. Yes. If an attacker
- 5:28steals my password, they still need that six
- 5:30-digit code from my phone. Right. How on earth
- 5:33do they bypass that without having my physical
- 5:36device in their hands? Yeah. So that brings us
- 5:38to the audit's findings on identity and access
- 5:40management, which honestly is the most critical
- 5:43takeaway here. The entities were operating under
- 5:46this illusion of security, assuming that all
- 5:48MFA is created equal. And it's not. Not at all.
- 5:52The audit found that all seven entities relied
- 5:54on weak, fishable MFA methods. We are talking
- 5:57about SMS text messages, voice calls, and email
- 6:02one -time passwords or OTPs. But wait, I'm going
- 6:04to play devil's advocate here. SMS codes feel
- 6:07so convenient. And if the code goes directly
- 6:10to my specific phone number through my cellular
- 6:13provider, how is a hacker sitting in another
- 6:15country getting their hands on it? Is the risk
- 6:18really that high or is this just like security
- 6:20paranoia? It is not paranoia. There are two primary
- 6:23methods and neither of them requires physical
- 6:25access to your phone. The first one is a SIM
- 6:28swapping attack. This is pure social engineering.
- 6:31The attacker gathers some basic personal info
- 6:34about you. They call your telecommunications
- 6:36provider, pretend to be you and say, hey, I lost
- 6:38my phone. Oh, no. Yeah. They convince the customer
- 6:42service rep to transfer your phone number to
- 6:44a new SIM card that the attacker controls. The
- 6:47moment that rep clicks approve, your actual phone
- 6:50loses service and the attacker starts receiving
- 6:53all your SMS sends. So the telecom provider actually
- 6:56just hands over the access. They do. It happens
- 6:58every single day. But the second method is even
- 6:59more common, and it's called an adversary in
- 7:02the middle attack or ATM. Adversary in the middle.
- 7:04How does that work? So the attacker sends you
- 7:07a highly convincing phishing email that directs
- 7:10you to a fake Microsoft login page. You type
- 7:13in your username and password. The fake page
- 7:16instantly forwards those credentials to the real
- 7:19Microsoft server in real time. Okay, so Microsoft
- 7:22thinks it's me logging in. Right. So Microsoft
- 7:24generates an SMS code and sends it to your real
- 7:26phone. And because I think I'm logging in, I
- 7:29look at my phone. get the code and type it into
- 7:31the fake website exactly the fake site then passes
- 7:34that code back to microsoft now here is the critical
- 7:37part microsoft verifies the code and issues what's
- 7:41called a session token a session token yeah think
- 7:43of a session token like a vip wristband at a
- 7:46concert once you have the wristband You don't
- 7:49need to show your ID to the bouncers anymore.
- 7:51You can just walk in and out. Oh, I see. The
- 7:53attacker intercepts that session token, drops
- 7:55it into their own browser, and boom, they are
- 7:57fully logged in as you. They bypassed the MFA
- 8:01entirely because they stole the mathematical
- 8:03proof of the authentication, not just the password.
- 8:06Wow. OK, that perfectly explains why the Australian
- 8:09Signals Directorate, the ASD, they noted in this
- 8:13report that these weak MFA methods were responsible
- 8:16for 58 % of all security incidents affecting
- 8:19the Australian government in 2024 and 2025. More
- 8:22than half. It's wild. But the OED report also
- 8:26pointed out that the vulnerabilities weren't
- 8:28just the methods, right? It was also the actual
- 8:30devices being used to authenticate. Right. So
- 8:33the entities were allowing staff to use personal
- 8:35devices to register for MFA, which is common,
- 8:38but they weren't enrolling those devices into
- 8:40a mobile device management system or MDM. Meaning
- 8:43the IT department had zero visibility into whether
- 8:46the personal phone receiving the secure code
- 8:48was actually secure itself. Exactly. If an employee's
- 8:51personal phone has a malicious app or malware
- 8:53installed, the organization's network is instantly
- 8:56exposed the moment that device interacts with
- 8:58the corporate environment. That's a huge blind
- 9:00spot. It is. And the OAG report actually drew
- 9:03a direct parallel here to the massive 2022 Medibank
- 9:07data breach. Remember that. It exposed the private
- 9:09health records of nearly 10 million Australians.
- 9:12Oh, yeah, that was a disaster. And that catastrophic
- 9:14breach also originated from an exploited personal
- 9:17device used for authentication. Which is just
- 9:19terrifying. The governance failures in this report
- 9:23went even deeper. It noted that in some cases,
- 9:27any user could create a new Microsoft 365 tenant
- 9:31and become a highly privileged administrator.
- 9:34Now, for you listening, if you don't manage cloud
- 9:37infrastructure, what does creating a tenant actually
- 9:39mean in this context? Why is that dangerous?
- 9:42So a tenant is essentially a dedicated, isolated
- 9:45instance of the cloud environment. Imagine your
- 9:48organization's Microsoft 365 environment is a
- 9:51giant digital skyscraper. Okay. By allowing any
- 9:54user to create a new tenant, you are essentially
- 9:56letting an employee build their own unmonitored
- 9:58annex attached to your skyscraper. Without a
- 10:00permit. Without a permit, without security guards.
- 10:04compromises a low -level account, spins up a
- 10:06new tenant where they are the absolute global
- 10:08administrator, and uses that trusted, connected
- 10:11environment to launch attacks or, you know, siphon
- 10:14data out. And your central IT team never even
- 10:17sees it on their dashboard. Exactly. They have
- 10:19no idea it exists. So we've seen how attackers
- 10:21break in through the front door. Because the
- 10:23identity verification is fundamentally broken.
- 10:26Yeah. But sometimes DACAs don't even need to
- 10:28break in because your own employees are basically
- 10:30just throwing the data out the window themselves.
- 10:32Yeah. The internal threat. Yeah. Let's look at
- 10:35how data actually leaves the building, which
- 10:37brings us to the second. major incident in the
- 10:39OAG report. It was a massive data spillage. And
- 10:42this incident is a perfect example of internal
- 10:45failures compounding external risks. An unnamed
- 10:48government entity emailed personal and highly
- 10:51sensitive information about 32 individuals to
- 10:53a third -party service provider. And crucially,
- 10:57the report notes this data included information
- 10:59on minors. Yes. Which changes the entire legal
- 11:03and ethical landscape of the breach. It is so
- 11:06much worse. Right. So they email this highly
- 11:07sensitive data to a vendor. What does the vendor
- 11:10do? They just upload that data to a standard,
- 11:13unmanaged Dropbox account. Yep. And then later
- 11:16on, that Dropbox account gets compromised in
- 11:18a completely separate cybersecurity incident.
- 11:20Yeah. Exposing the sensitive data of those miners
- 11:22to an unknown threat actor. The government entity
- 11:25failed on multiple structural levels here. I
- 11:28mean, first, during the vendor onboarding process,
- 11:31they had not conducted any security assessment
- 11:33of the third -party provider. They just trusted
- 11:35them. Blindly. They handed over sensitive data
- 11:37without verifying if the vendor had the technical
- 11:40capability to actually protect it. But the internal
- 11:43tracking failure is what really stands out to
- 11:45me here. The audit explicitly states the entity
- 11:48had zero data loss prevention. or DLP, controls
- 11:52across their Microsoft 365 apps. No DLP on OneDrive,
- 11:57SharePoint Exchange Teams, nothing. Which is
- 11:59staggering for a government entity. Right. Now,
- 12:02I understand DLP is a concept like stopping data
- 12:05from leaving. Yeah. But how does it actually
- 12:07function mechanically to prevent something like
- 12:09this from happening? Think of DLP as a deeply
- 12:11embedded, automated compliance officer that reads
- 12:14every single document and message in real time.
- 12:17It uses mathematical algorithms, regular expressions,
- 12:20even AI now, to identify sensitive patterns.
- 12:23Like what kind of patterns? Like credit card
- 12:24formats, tax file numbers, or specific health
- 12:27terminology. When a user tries to email a spreadsheet
- 12:30containing the personal details of 32 minors,
- 12:33the DLP system flags it instantly. And then what?
- 12:37Does it just warn them? Depending on how you
- 12:39configure the policy, it can automatically block
- 12:41the email from sending entirely. Or it can mandate
- 12:45that the file be encrypted. Or it can force the
- 12:48user to provide a written justification right
- 12:50there on the screen before the system releases
- 12:53the data. OK, so because they lacked DLP, there
- 12:57was no digital die pack attached to the data.
- 12:59It just flowed out of the organization and they
- 13:01had no technical mechanism to even detect that
- 13:04it had left. None. And the audit. found this
- 13:06culture of careless data handling was everywhere.
- 13:09I mean, all seven entities allowed external data
- 13:12storage on unmanaged services. Oh, wow. Yeah,
- 13:14we're talking about a massive shadow IT problem.
- 13:17Staff are just syncing official work data to
- 13:19personal Dropbox accounts, Facebook, Google Drive,
- 13:22completely bypassing corporate oversight. It's
- 13:24literally like having a highly secure bank vault,
- 13:27but you're allowing the tellers to stump wads
- 13:30of cash into their personal backpacks to just
- 13:32count at home. That is a perfect analogy. It
- 13:35is a... Right. Okay, I get that from a strict
- 14:01security perspective, banning everything sounds
- 14:03great. But from an operational... standpoint,
- 14:05how do organizations actually balance the genuine
- 14:08need to collaborate with external partners without
- 14:12completely losing visibility of where their data
- 14:14goes? Because if you just block external sharing,
- 14:16the business grinds to a halt. Right. And people
- 14:20will just find workarounds anyway. Absolutely,
- 14:22they will. You solve it by shifting from implicit
- 14:24trust to explicit mathematical verification.
- 14:27You don't block the sharing. You secure the data
- 14:30itself. Secure the data. Not the perimeter. Exactly.
- 14:33You implement advanced DLP policies that automatically
- 14:36classify and tag the data based on its sensitivity.
- 14:39So a public marketing document that can be shared
- 14:42freely. Makes sense. But a file containing personally
- 14:46identifiable information that is automatically
- 14:49encrypted. And that mathematical restriction
- 14:51travels with the file. Oh, that's interesting.
- 14:54So even if they put it in Dropbox? Even if an
- 14:56employee uploads it. to an unsanctioned Dropbox
- 14:59folder and a hacker downloads it, the file remains
- 15:02locked. It will only open if the person double
- 15:05-clicking it can actively authenticate themselves
- 15:07back to your central Microsoft 365 server as
- 15:10an authorized recipient. That is a brilliant
- 15:13way to handle it. So the security lives inside
- 15:15the file itself? Yes. Okay, so we've covered
- 15:17the front door with authentication and we've
- 15:18covered the back door with data sharing. But
- 15:20looking deeper into this report, the structural
- 15:22integrity of the environment itself was compromised
- 15:25by unvetted apps and a lack of logging. Oh, the
- 15:29apps. This is such a widely misunderstood threat
- 15:31vector. The audit found that staff weren't restricted
- 15:34from installing unapproved Microsoft Teams applications,
- 15:38and they were allowed to use external code from
- 15:40Microsoft Power BI. See, I don't totally get
- 15:43this. Why is an app? in Teams, a security risk.
- 15:47I mean, I use third party calendar integrations
- 15:51and like little polling apps all the time. Because
- 15:53Microsoft 365 operates almost like an operating
- 15:56system now. When a user installs a third party
- 15:59app into Teams, that app requests permissions.
- 16:02Like on your phone when you download an app.
- 16:04Exactly. But these are often broad permissions
- 16:07to read emails, view contacts, or access files
- 16:10across SharePoint. If the user clicks allow,
- 16:13they are granting that app access using their
- 16:15own identity. If that third -party app is built
- 16:18by a malicious actor or, and this happens a lot,
- 16:21if the developer's servers are poorly secured
- 16:24and get hacked, the attacker can leverage the
- 16:26app's permissions to siphon data straight out
- 16:29of your environment. They don't even need your
- 16:30password. They don't need your password or your
- 16:32MFA. The app already has authorized access. giving
- 16:35a contractor the master key to the building and
- 16:37then just never checking if the contractor loses
- 16:40the key. Yeah. And speaking of poor security,
- 16:43most of the entities did not enforce content
- 16:45security policies for Microsoft's Power Platform.
- 16:49The OAG noted this increased their susceptibility
- 16:52to cross -site scripting or XSS attacks. How
- 16:56does an XSS attack actually work inside a business
- 16:58application like that? Well, Power Platform allows
- 17:01businesses to build custom internal apps really
- 17:03easily, right? But if those apps don't have strict
- 17:06content security policies to sanitize the data
- 17:09that users input, it creates a vulnerability.
- 17:12An attacker can type a malicious piece of JavaScript
- 17:15into a standard text field, say a customer feedback
- 17:19form. Later, when a highly privileged administrator
- 17:22opens that form to read the feedback, the malicious
- 17:25script executes silently inside the administrator's
- 17:28browser. While they're logged in. While they're
- 17:29logged in. It can immediately hijack their active
- 17:32session, effectively giving the attacker administrative
- 17:34control without ever triggering a login prompt.
- 17:37Wow. The hidden traps are just everywhere. And
- 17:40when things do go wrong, like we saw in the $71
- 17:42,000 theft, you need a trail to follow. And the
- 17:46detail that really caught my eye here was regarding
- 17:48the system logs. Ah, yes, the logging failure.
- 17:52The audit found that log files were sometimes
- 17:54only retained for six months. Now, it's specifically
- 17:58noted that the Australian Signals Directorate
- 18:00recommends keeping them for at least 18 months.
- 18:03To someone running a regular business, six months
- 18:06of data storage might sound like a long time.
- 18:08Why is 18 months the magic number? Well, think
- 18:11of system logs as the black box of an airplane.
- 18:14They record every login, every file download,
- 18:17every permission change. We discussed earlier
- 18:19how the attacker in that BEC fraud just sat quietly
- 18:22in the account for a month. Right. The dwell
- 18:24time. Exactly. Advanced persistent threats, whether
- 18:27it's state sponsored actors or organized cyber
- 18:30criminal syndicates, they don't usually smash
- 18:32and grab. They infiltrate and then they wait.
- 18:34They map the architecture, escalate privileges,
- 18:36find the most valuable data. So they might be
- 18:38inside the network for the better part of a year
- 18:40before they actually detonate ransomware or wire
- 18:42money out. Exactly. Industry metrics consistently
- 18:45show that it can take an organization over 200
- 18:49days just to realize a breach has even occurred.
- 18:52200 days. Over 200 days. If your logs are set
- 18:55to auto -delete after 180 days, which is about
- 18:58six months, by the time your security team realizes
- 19:00you've been compromised, the initial evidence
- 19:03showing exactly how the attacker got in and what
- 19:05backdoors they created has been permanently erased.
- 19:08You have no black box. You have nothing. 18 months
- 19:11ensures that Even with a massive dwell time,
- 19:14your forensic investigators have the historical
- 19:17data required to find the root cause and properly
- 19:20eradicate the attacker from the network. It is
- 19:23incredibly sobering when you look at the aggregate
- 19:25of all these findings. But, you know, it's easy
- 19:27to read this report and just point fingers at
- 19:29the government. I actually think this audit is
- 19:31a perfect checklist for you, the listener, to
- 19:33evaluate your own organization. Oh, absolutely.
- 19:35So how do we turn these systemic failures into
- 19:38practical, actionable defenses? If our listener
- 19:42is sitting at their desk right now feeling a
- 19:44little overwhelmed and they only have the political
- 19:46capital at their company to push for one of these
- 19:48changes tomorrow, what is the absolute most critical
- 19:52first step? The first non -negotiable step is
- 19:55upgrading to phishing -resistant MFA. You have
- 19:58to move away from SMS codes and email OTPs. Okay,
- 20:01and what does true phishing -resistant MFA actually
- 20:05look like mechanically? It looks like hardware
- 20:07security keys, such as FIDO2 tokens. These are
- 20:10physical USB keys that you plug into your machine.
- 20:13They use asymmetric cryptography. So no more
- 20:15typing in six digits. Right. When you log in,
- 20:18the physical key mathematically verifies the
- 20:20actual domain of the website you are on. So even
- 20:23if an attacker tricks you into visiting a perfectly
- 20:25forged login page, the hardware key knows the
- 20:28domain doesn't match Microsoft's actual servers.
- 20:31And it just blocks it. It simply refuses to complete
- 20:33the cryptographic handshake. The phishing attack
- 20:36fails instantly. That is a phenomenal upgrade,
- 20:39especially for those privileged administrative
- 20:40users. Okay, what's next on the defense list?
- 20:44Next, you need to implement broad data loss prevention
- 20:47controls across the entire M365 suite. Right,
- 20:51the digital dye packs. Exactly. You need total
- 20:53visibility. Policies must span OneDrive, SharePoint,
- 20:57Exchange, and Teams. You have to know exactly
- 21:00when sensitive info is attempting to leave the
- 21:02environment. And you need the technical mechanisms
- 21:05to mathematically restrict that data, regardless
- 21:07of where it travels. And tied directly to that,
- 21:10I assume, is controlling and strictly limiting.
- 21:12that unmanaged cloud storage we talked about.
- 21:14You must eliminate the shadow IT. If work data
- 21:17is stored in the cloud, it must be in an approved,
- 21:20monitored, and secured corporate tenant. No more
- 21:23rogue Dropbox folders syncing sensitive client
- 21:25data to personal laptops. Yeah, and the report
- 21:28also heavily recommends implementing robust business
- 21:31email compromise defenses. Yes, which involves
- 21:34configuring anti -spoofing protocols like DMRC
- 21:36so attackers can't impersonate your partner domains,
- 21:39but it also means establishing automated threat
- 21:42hunting alerts. Like what kind of alerts? Well,
- 21:44if an end user suddenly creates a forwarding
- 21:46rule that sends all their inbox traffic to an
- 21:49external Gmail address, that shouldn't just be
- 21:52logged. It should trigger an immediate high priority
- 21:54alert that pages your IT security team. Right,
- 21:58because that's exactly what happened in the $71
- 22:00,000 theft. Precisely. And finally, you should
- 22:04be adopting the ASD's Essential 8 framework and
- 22:07ensuring thorough security assessments of all
- 22:10third -party vendors before handing over any
- 22:12data. I mean, the vendor security is your security.
- 22:16Yeah, you really have to treat your identity
- 22:17and your data as the new security perimeter because
- 22:20that old concept of a trusted internal network,
- 22:24it simply doesn't exist anymore. It doesn't.
- 22:26And, you know, to kind of leave you with a final
- 22:28thought to ponder here, we talked about how the
- 22:30attacker spent a month manually studying an inbox
- 22:32to craft one perfect fraudulent invoice, right?
- 22:35Well, as generative AI becomes increasingly integrated
- 22:38into these cybercriminal toolkits, threat actors
- 22:41won't need a month. AI will be able to ingest
- 22:45an entire mailbox, mimic the communication style
- 22:47perfectly, and dynamically generate thousands
- 22:50of highly personalized, context -aware BEC attacks
- 22:54across an organization in seconds. That is terrifying.
- 22:57It is. If your defense relies on an employee
- 23:00manually spotting a slightly suspicious tone
- 23:02in an email, you will lose. Mathematical trust
- 23:05through hardware keys and data encryption is
- 23:07the only way forward. Because remember, the default
- 23:10settings on enterprise software platforms are
- 23:12designed for maximum convenience and immediate
- 23:14collaboration. They are not designed for maximum
- 23:16security. If you haven't actively configured
- 23:19your security settings, you aren't secure. You're
- 23:21just lucky. That is such a powerful point. If
- 23:24today's episode made you second guess your own
- 23:26setup, don't wait for an audit or a massive financial
- 23:29loss to find out what's missing. Visit www .kinsoft
- 23:32.com .au to discuss your security and IT needs.
- 23:36Thank you so much for joining Tech Talks with
- 23:37Kinsoft. Stay curious, stay secure, and we will
- 23:40catch you next time.