How state, local government need to build a cyber resilience strategy for email
Full article597 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
With an ever-increasing number of threats coming toward state and local government agencies, leaders must think more strategically about cyber resilience.
As state and local government agencies fight against an onslaught of threats like ransomware and phishing, a standard cybersecurity strategic plan isn’t enough.
Those threats are bombarding agencies at an unprecedented rate — and a good chunk of them are coming at what one county chief information security officer calls “the Achilles’ heel” of any system: email.
“It’s users clicking on links, it’s the fact that those bad emails get to us,” said Michael Dent, the CISO for Fairfax County, Virginia. “We’ve got to be able to stop that.”
In South Dakota, it’s a similar fight. Jim Edman, the state’s chief security officer, said that with almost 90 percent of incoming email to state employees being categorized and flagged as spam, it makes protecting against threats difficult — especially if something slips through the cracks.
“The employees, boy, those people are sitting in front of that computer reading that message — they are absolutely critical,” Edman said. “If they give up their credentials, or they click on something that’s going to download malware, then you’re in a reactive game there.”
Most spam gets filtered out at the email gateway level, Edman and Dent said, but the key to developing resilience really centers on employee education.
“[Employees] are the ones that are getting the phishing messages, the spoof phishing attempts and other aspects of social engineering,” Edman said. “I think there’s a lot of components to everybody’s cyber strategy, and certainly one of those important components is going to be client education.”
While employee education helps cover the weakest links in the systems, states can use technology and cybersecurity strategy to help bridge the gap.
“Security teams are getting better and better,” Edman said. “If you apply the updates, you keep the patches, you use a desktop protection system and you don’t click on the ‘prince from Nigeria’ message saying you just won $8.7 million, that goes a long way in the digital world.”
For more information on a checklist to plan for cyber resilience, and more on how state and local agencies should go about creating that plan, check out the full report.
Download the special report report here. This article was produced by CyberScoop for, and underwritten by, Mimecast.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/cyber-resilience-strategy-mimecast/