Threat Watch

Whaling Gets Real

Powered by social-networking sites and compromised corporate databases, super-targeted phishing attacks are moving from theory to practice. Here's how to understand this evolving information-security threat and protect your company and its executives

By Rick Cook

Page 3

someone you know, mail them back and ask what they’re sending," Stewart says. "You’ve really got to be suspicious of these types of messages that seem to come from an authority figure. In that sense we have an easier job in user education. It comes to security team having a meeting of the executive team [and saying,] Be suspicious of anything you get. Run it by us."

Paller, however, warns that "education" in the form of seminars and lectures doesn’t work well in the long run; in fact, he says, it hardly works at all. Instead, he suggests a process he calls "inoculation," which involves repeatedly sending out fake whaling-type messages. "When [the user bites], [he or she] gets a message saying, ’Oops, you’ve just been had.’ You do that over and over again until people learn.”

Rick Cook is a freelance writer based in Phoenix.

--

The comment field below does not work. Please send your feedback to csoletters@cxo.com.

Other stories by Rick Cook

whaling

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Security Directions: A Virtual Conference

Security Directions Available On Demand Sept. 30 - Dec. 30

Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.

» Register Now

WEBCAST
Protecting PII: How to Work with IT to Manage Risk

Compuware Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.

» View this Webcast

Featured Sponsors