Latest / Tech Talks With Kinsoft / Importance of Email Security
Transcript
- 0:00Welcome to Tech Talks with Kinsoft, your shortcut
- 0:02to staying sharp on the tech that matters. Today,
- 0:05we're doing a real deep dive in something called
- 0:08business email compromise, or BEC. It's a threat
- 0:13that's, well, it's more than just growing. It's
- 0:15really changing how businesses have to think
- 0:17about security. It absolutely is. Email is still,
- 0:20you know, the main way we communicate in business,
- 0:22but that also makes it the number one way criminals
- 0:24try to get in. Our goal today is to unpack BEC,
- 0:28see how it's changing, and look at the advanced
- 0:31security that can help protect you. All right,
- 0:33let's get into it. We've looked at some really
- 0:35interesting sources here, everything from the
- 0:37latest stats on BEC to the psychology behind
- 0:39why these scams work. And we'll also explore
- 0:42how cutting edge solutions like those from Acronis
- 0:45are actually fighting back. You might be genuinely
- 0:47surprised at how sophisticated this is all become.
- 0:49So maybe starting with the basics, even though
- 0:51BEC isn't new, what makes it such a huge deal
- 0:54right now? Why is it so persistent? Yeah, that's
- 0:56a good place to start because BEC is different.
- 0:59It's not like your typical virus attack. Basically,
- 1:01it's a financial scam, a really sneaky one. Criminals
- 1:04pretend to be someone you trust, could be your
- 1:06boss, a supplier, maybe even just a colleague.
- 1:09And the whole point is to trick you, trick you
- 1:11into sending money or giving up sensitive info.
- 1:13And it's not just a threat anymore. It's kind
- 1:15of become the main threat. Our sources are showing
- 1:17that back in 2024, BEC made up a massive 73 percent
- 1:23of all reported cyber incidents. 73 percent.
- 1:26Wow. That's. That's almost everything. It's huge.
- 1:29Yeah. And the cost is just as startling. As of
- 1:31March 2025, there's been about a 30 percent jump
- 1:35in these attacks. It's the second priciest type
- 1:38of breach out there. We're talking an average
- 1:39cost of nearly five million dollars, four point
- 1:42eight nine million dollars to be exact. Nearly
- 1:44five million per incident. Per incident. And
- 1:46the average amount they asked for in these fake
- 1:47wire transfers in early 2025, it was over twenty
- 1:50four thousand dollars. What's really concerning,
- 1:53too, is that it hits everyone, even smaller places
- 1:55like companies with under a thousand. employees,
- 1:58they have a 70 % chance of getting hit by at
- 2:00least one BEC attack every week. Every week.
- 2:03Every single week. And for the really big companies,
- 2:05you know, 50 ,000 plus employees, basically a
- 2:08guarantee, almost 100 % weekly chance. So bottom
- 2:11line, if your business uses email, you're a target.
- 2:15Simple as that. Those numbers are pretty stark.
- 2:18But sometimes abstract stats don't quite hit
- 2:21home. Can you maybe give us some real world examples?
- 2:23Show us the impact. Sure. And yeah, the real
- 2:25stories are quite sobering. Take December 2024,
- 2:29two companies over in Zamora, Spain. They lost
- 2:32almost 20 ,000 euro. The criminals just got into
- 2:35their email chain, changed some bank details
- 2:37in an invoice and poof, payment rerouted. Just
- 2:39like that. Just like that. Now they got most
- 2:41of it back, which is good. Shows quick action
- 2:43helps. But it demonstrates how easily it can
- 2:45happen. Right. Or look at Australia in 2024.
- 2:48Attackers there were using AI, believe it or
- 2:51not, to mimic partners, managers, leading to
- 2:53estimated losses around $2 .9 billion a year
- 2:56for businesses there. Using AI. Wow. Yeah. And
- 3:00maybe the most dramatic one, Orion Chemical Manufacturing
- 3:04in Luxembourg, August 2024. An employee was tricked
- 3:07into making multiple fraudulent wire transfers.
- 3:10They lost $60 million. $60 million. $60 million.
- 3:15It just highlights that even large, you know,
- 3:17presumably sophisticated companies are definitely
- 3:20not immune. And what really makes these BEC attacks
- 3:23work so well is they go straight for human behavior.
- 3:27It's like psychology. They don't always need
- 3:29fancy malware or viruses. Often it's just. Deception.
- 3:32Pure and simple. So less about breaking through
- 3:34firewalls and more about tricking the person
- 3:36sitting at the keyboard. Exactly. They know how
- 3:38we tend to react, like requests from the boss.
- 3:40Yeah. People tend to jump on those, right? Sure,
- 3:42yeah. Well, data shows that in almost 90 % of
- 3:44VEC attacks, 89%, to be precise, they're impersonating
- 3:47someone high up. Yeah. CEO, CFO, that sort of
- 3:50thing. Sometimes it's as simple as changing the
- 3:52display name in the email. One study found that
- 3:54in 36 % of VEC emails, looks legit at first glance.
- 3:58We've even seen... Cases using deep fake audio,
- 4:02fake voices mimicking the CEO over the phone
- 4:05to authorize payments led to huge losses. Hundreds
- 4:08of thousands. Voice clones. That's terrifying.
- 4:11It is. And then there's the urgency factor. They
- 4:13create this fake crisis. Urgent request. Need
- 4:15this done today. Act now. About three quarters
- 4:18of these attacks demand action within like 24
- 4:22to 48 hours. It pressures people, stops them
- 4:24from thinking it through or checking properly.
- 4:27Rushing them so they make mistakes. Precisely.
- 4:29And the other big one is trust. Posing as a known
- 4:32vendor, a supplier you work with all the time,
- 4:34or even just a colleague. Think about Google
- 4:36and Facebook. They lost over $100 million combined.
- 4:39The scammer just sent them fake invoices pretending
- 4:41to be a hardware supplier they actually used.
- 4:44Unbelievable. So the regular checks may be weren't
- 4:46applied because it looked like a routine vendor
- 4:48payment. Seems likely, yeah. The usual internal
- 4:51verification might just get bypassed when it
- 4:53looks like a normal external transaction. Okay,
- 4:55so with these tactics constantly evolving, what's
- 4:59next? How are things like AI changing the game
- 5:02here? It sounds like it's only getting tougher
- 5:03to defend against. It absolutely is getting tougher.
- 5:06And yeah, AI, especially generative AI, is a
- 5:09massive factor now. By mid -2024, estimates were
- 5:12that something like 40 % of BEC phishing emails
- 5:15were being generated by AI. 40 % already. Already,
- 5:19AI makes the emails sound much more convincing.
- 5:22No more awkward grammar or weird phrasing that
- 5:25used to be a giveaway. Plus, AI can churn out
- 5:27tons of variations super quickly, target specific
- 5:30people much more effectively. It's led to this
- 5:32explosion. We saw a 1 ,760 % year -over -year
- 5:37increase in BEC attacks reported. Wow, 1 ,760
- 5:40% increase. That's staggering. It is. And we're
- 5:42also seeing this other trend, vendor email compromise,
- 5:45or BEC. That jumped 66%. just in the first half
- 5:48of 2024. That's where they hack into your supplier's
- 5:51email, then send you fake invoices or payment
- 5:53instructions from their legitimate account, exploiting
- 5:55that supply chain trust. So they don't even need
- 5:57to trick your employees directly at first, just
- 5:59one of your partners. That's shush. Yeah, insidious
- 6:02is the right word. It really is. And then there's
- 6:05this blending of methods, multi -channel attacks,
- 6:07maybe an email first to set the stage, then a
- 6:10phone call to add pressure or a text message.
- 6:12And while it's still, let's say, emerging, those
- 6:15AI voice clones we mentioned, even video deepfakes,
- 6:18they're becoming more common, especially when
- 6:21targeting high value individuals or large transfers
- 6:24makes that second check absolutely vital. OK,
- 6:27so the threats are evolving fast, getting smarter.
- 6:29What are organizations actually doing? Or maybe
- 6:32what should they be doing to stand a chance?
- 6:35Well, the good news is there's a big push now,
- 6:37not just recommendations, but actual regulations
- 6:39are stepping up. Industry standards are demanding
- 6:41better defenses, really focusing on multiple
- 6:43layers of security, not just one silver bullet.
- 6:46So regulations are forcing the issue? In many
- 6:47cases, yes. Like in the U .S. PCI DSS version
- 6:514 .0. It now mandates DMRC email authentication
- 6:55by March 31st, 2025. DMRC basically tells email
- 7:00systems what to do with emails that fail. Authentication,
- 7:03reject them, quarantine them. Email providers
- 7:05are also getting much stricter about enforcing
- 7:07it. And globally, you've got things like the
- 7:09EU's NIS2 directive requiring businesses to report
- 7:12major cyber incidents within 24 hours. And the
- 7:15DORA regulation in the EU, specifically for financial
- 7:17services, it's all driving security upwards.
- 7:21So compliance is becoming a big driver. What
- 7:23about the core technical stuff? What needs to
- 7:24be in place? Absolutely crucial. First up, email
- 7:27authentication. We mentioned a DMRC, but it works
- 7:30with SBF and DKIM. These are protocols that verify
- 7:33the sender is who they say they are, stop spoofing,
- 7:37adoptions growing, but really enforcing strong
- 7:39DMRC policies, not just monitoring. That's key.
- 7:42Got it. SBF, DKIM, D -Air, FARC. What else? Multi
- 7:46-factor authentication, MFA. Especially on email
- 7:49accounts. This is a huge one for preventing account
- 7:51takeovers, which often lead to BEC. The stats
- 7:54show it works. In 2023, 58 % of BEC attacks hit
- 7:58organizations that didn't have MFA. Wow, over
- 8:00half. Yeah. But by early 2024, that number dropped
- 8:04to 25 % for orgs without MFA. Attackers had to
- 8:07shift tactics because MFA was blocking them.
- 8:09It clearly works. Okay, MFA is a must -have then.
- 8:11Definitely. And third, you need good email security
- 8:15filters. Modern ones use AI, machine learning,
- 8:18pattern detection. They can spot subtle signs
- 8:21of BEC. Things like alerting you if the display
- 8:25name says it's the CEO, but the actual sending
- 8:28domain is wrong, like a Gmail address instead
- 8:30of the company one. These filters are essential
- 8:32to just reduce the sheer volume of malicious
- 8:34emails hitting inboxes. Makes sense. Technology
- 8:37is clearly critical. But you said earlier these
- 8:39attacks exploit human psychology. So what about
- 8:42the people part of the defense? How do we make
- 8:44employees less vulnerable? Ah, yes. That's arguably
- 8:47the most critical piece of the puzzle. You need
- 8:49what some call human -centered security. Training
- 8:52and awareness are paramount. So ongoing training.
- 8:55Ongoing and practical. First, organizations absolutely
- 8:58need strict verification protocols. Any request
- 9:01for money or sensitive data changes must be verified
- 9:04through a different channel. Like get an email
- 9:06asking to change bank details. Pick up the phone
- 9:08and call a known trusted number for that vendor,
- 9:10not a number from the email itself to confirm.
- 9:13This simple trusted callback stops so many BEC
- 9:16attempts. That second check. Seems simple. But
- 9:19effective. Incredibly effective. Also, you need
- 9:22a plan for when things do go wrong. An incident
- 9:25response plan. Because even with the best offenses,
- 9:27something might slip through. If the victim or
- 9:30their bank acts really fast, often the funds
- 9:32can be frozen or even recovered. We saw data
- 9:35showing over half of BEC victims got back at
- 9:38least 82 % of the money if they reported it quickly.
- 9:41Speed matters then. Hugely. And finally, back
- 9:44to training. Regular security awareness training
- 9:46combined with simulated phishing attacks. makes
- 9:49a massive difference. Sources show that with
- 9:51behavior -focused training, you can see like
- 9:53a 6x improvement in employees spotting phishing
- 9:56attempts within just six months. An 86 % drop
- 9:59in successful incidents. That's a huge improvement.
- 10:02It really is. You see things like the percentage
- 10:04of users who actually report real threats jump
- 10:06from maybe 13 % initially up to 50 % after just
- 10:09six months of good training. It's about teaching
- 10:11people those red flags. Weird domains, bad writing,
- 10:15though. AI is making that harder, that sense
- 10:17of urgency, unexpected attachments or requests,
- 10:20making them pause and think. Okay, so it really
- 10:22is a combination. You need the tech, but you
- 10:25absolutely need the trained human element, too.
- 10:28Given all that complexity, let's talk solutions.
- 10:30You mentioned Acronis earlier, and our sources
- 10:32highlight them, too. How do they fit into this
- 10:35multi -layered defense picture? Yeah, Akronis
- 10:38comes up strongly. They've been recognized, for
- 10:40instance, as a leader in the G2 grid for cloud
- 10:42email security, specifically for small businesses.
- 10:45And Gartner mentioned them in their 2023 market
- 10:48guide for email security. Their main offering
- 10:50here is Akronis email security, which, interestingly,
- 10:54is powered by perception point technology. The
- 10:57whole focus is on catching these modern, tricky
- 10:59email attacks and doing it fast, within seconds.
- 11:03Within seconds. How do they achieve that speed
- 11:05and coverage? It's through a pretty comprehensive,
- 11:08multilayered approach. They're designed to block
- 11:10all sorts of things. Spam, basic phishing, but
- 11:12also the advanced stuff like BEC, account takeover
- 11:15attempts, malware, APTs, those persistent threats,
- 11:17and even zero -day attacks. Zero days being the
- 11:20brand new threats nobody knows about yet. Exactly.
- 11:22And they do this by combining multiple techniques.
- 11:25They use powerful threat intelligence from, I
- 11:28think... six different leading sources plus their
- 11:31own engine. They use traditional signature -based
- 11:34detection and check URL reputations using four
- 11:36different engines for that. They even have unique
- 11:39image recognition tech that spots malicious websites
- 11:42just based on the logos or images used on the
- 11:44page, which is pretty clever for phishing detection.
- 11:46Image recognition. Okay, that's different. It
- 11:48is. And they combine machine learning with DMRC
- 11:51checks to prevent spoofing effectively. So it
- 11:54sounds like they're covering a lot of bases.
- 11:55How do they handle those really advanced hidden
- 11:58threats, the zero days and APTs you mentioned?
- 12:01Right. That's a key differentiator. Their system
- 12:03is designed to recursively unpack everything
- 12:06in an email. It digs deep into embedded files,
- 12:09follows links, analyses everything layer by layer
- 12:12to find hidden threats. And crucially, for APTs
- 12:15and zero days, they use unique CPU level detection
- 12:18technology. CPU level. What does that mean in
- 12:21practice? It means it operates at a very fundamental
- 12:24level of the computer's processor. This allows
- 12:27it to spot and block malicious exploits before
- 12:29the actual malware payload even gets released
- 12:32or executed. It acts much earlier in the attack
- 12:35chain than many traditional scanners, which might
- 12:38wait for the malware file itself. And because
- 12:40of this, they can give a clear yes -no verdict
- 12:42on an email within seconds. Which is a big deal
- 12:45compared to older systems that might take minutes,
- 12:48right, leaving a window of risk. Exactly. That
- 12:51speed is crucial. A few minutes delay in scanning
- 12:54could be enough time for a user to click a malicious
- 12:56link that arrived in their inbox before the scan
- 12:59finished. Acronis aims to prevent that. Okay,
- 13:02that advanced detection and speed sound impressive.
- 13:05But how easy is this to actually implement for
- 13:07a business? Especially, say, for MSPs managing
- 13:10multiple clients. That seems to be another major
- 13:12focus for them, ease of deployment and management.
- 13:15Akronis email security is cloud native. It integrates
- 13:18directly with email systems like Microsoft 365.
- 13:20They talk about API -based provisioning for M365
- 13:24being like the flip of a switch. Flip of a switch.
- 13:26So quick setup. That's the idea. Rapid deployment,
- 13:29quick time to value, which is obviously important
- 13:32for businesses and especially for managed service
- 13:35providers, MSPs, who need efficiency. Another
- 13:39important point is that it scans 100 % of email
- 13:41traffic, both inbound and outbound, in real time.
- 13:45Outbound too? Why is that important? Well, if
- 13:49one of your internal accounts gets compromised
- 13:51somehow, scanning outbound traffic stops that
- 13:54account from being used to send phishing emails
- 13:56or malware out to your partners, customers, or
- 13:59even other employees. It prevents that lateral
- 14:02movement of threats. Ah, stopping internal spread.
- 14:06Makes sense. Right. And they also offer incident
- 14:09response services as part of it. So you get access
- 14:11to their cyber analysts who can help monitor
- 14:13things and assist with remediation if an attack
- 14:15does occur. It's like having an extension of
- 14:17your own security team. So it sounds like more
- 14:19than just a filter. It's kind of a managed security
- 14:21component. You could see it that way. And it's
- 14:23important to understand Acronis email security
- 14:25isn't just floating out there alone. It's part
- 14:27of their bigger platform, Acronis Cyber Protect
- 14:30Cloud. OK, what's that? That platform is really
- 14:32designed with service providers in mind, but
- 14:34it integrates a whole suite of protection. backup
- 14:37and disaster recovery. There are next -gen anti
- 14:40-malware endpoint management tools all in one
- 14:43place. Email security is just one piece. They
- 14:46actually have, I think, seven different services
- 14:48specifically aimed at protecting Microsoft 365
- 14:52environments. Things like security posture management,
- 14:55security awareness training tools, XDR integration.
- 14:58So it's about bringing everything together, integration
- 15:00and consolidation. Exactly. The idea is to reduce
- 15:04complexity, reduce the number of different vendors
- 15:06and dashboards you need to manage and provide
- 15:09a more holistic, streamlined security posture.
- 15:12Less complexity often means better security and
- 15:15less strain on resources. Right. That makes a
- 15:17lot of sense. It feels like a very integrated
- 15:18approach is needed for a threat like BEC. So
- 15:22wrapping this up then, what's the main takeaway
- 15:24from this deep dive on business email compromise
- 15:27and how we can actually fight back? I think the
- 15:29core message is yes, email is still probably
- 15:31your biggest digital weak spot. It's critical
- 15:33but vulnerable. But the good news is comprehensive,
- 15:36multilayered defenses are available and effective.
- 15:39The key is understanding that technology alone,
- 15:42while essential, isn't enough. That human awareness,
- 15:46the training, the verification protocols, they're
- 15:49just as vital. It's about... combining smart
- 15:51technology like the advanced detection in Acronis
- 15:54email security with really solid internal processes
- 15:57and ongoing employee education. The threat landscape
- 16:00is changing fast, especially with AI getting
- 16:02into the mix. But thankfully, the defenses are
- 16:05evolving, too. It definitely leaves us with something
- 16:08to think about. It prompts the question for you
- 16:10listening right now. What steps are you actually
- 16:12taking proactively to lock down your organization's
- 16:15most vital communication channel? Because it's
- 16:17clearly an ongoing effort, isn't it? Not a one
- 16:19-time fix. Absolutely right. It's a continuous
- 16:21process. And if you are looking to discuss your
- 16:25specific security needs, your IT environment,
- 16:27we certainly encourage you to visit www .kinsoft
- 16:30.com .au. Great advice. Well, thanks for tuning
- 16:33in to Tech Talks with Kinsoft. We really hope
- 16:36this deep dive leaves you feeling not just informed,
- 16:39but actually empowered to take action. We'll
- 16:41see you next time.