Showing posts with label phishing. Show all posts
Showing posts with label phishing. Show all posts

Thursday, February 28, 2019

Beware of Compromised Personal E-mail

Over the last few years personal e-mail providers like Yahoo and AOL have had massive data breaches, in which user's e-mail addresses and passwords were compromised.  Recently there have been a number of phishing campaigns whereby these compromised e-mail accounts are being used. 

How this works
So a Yahoo or AOL e-mail account owner who has never changed their password, and a hacker gains access to it (Most likely from a password list bought on the Dark Web).  The hacker then send a personalized e-mail to everyone in the compromised account owner's Address Book with a link to either collect credentials or launch malware.  The sad thing is some people have been getting these phishing e-mails from people close to them who have passed away.  Other's are getting e-mails from friends and relatives that seem legitimate and so the recipient innocently clicks on the link seeing that the e-mail is from someone they know.

Security Tip
Ask yourself these questions when you receive an e-mail:
  1. Do I know the sender?  (hover your cursor on the display name or click the display name to see the real e-mail address)
  2. Am I expecting this e-mail or any web links/attachments from this sender?
If you answer "No" to either question, it is probably a phishing e-mail.

If you know the sender, pick up the phone and verify that they sent you the e-mail and any attachments or web links.  Don't reply to the sender's e-mail as the hacker has control over the e-mail account.

In 2018, the number of malicious web links (URLs) sent by cyber criminals was more than twice as many as malicious attachments sent.

Think before you click!


In addition, if you have a Yahoo or AOL e-mail address and haven't changed your password in the last year,,,,CHANGE YOUR PASSWORD NOW!


Be Secure!

@TJMProfessional

Tuesday, October 16, 2018

Information Leakage - Using the Internet Judiciously

One of the best online resources for cyber criminals is Google.  While businesses seek to utilize their company website, Facebook, Twitter, LinkedIn, and the like for marketing and recruitment purposes, they are unintentionally leaking information that can be useful to cyber criminals.  At the same time, their employees are also guilty of both disclosing more details about their job duties as well as connecting to and friending people based on invites without any due diligence.

For businesses, below are some typical areas where internal information is disclosed:

Press Releases: Expanding your business?  Offering a new product?  That is great and something to brag about.  But pick and choose what details you make public.  Let's say you are offering a new product or service, and you bought a new piece of equipment to provide it, or have a new vendor to help you support it.  If possible, don't name business partners or describe any new additions of equipment by name.  While these details don't sound like anything of importance, internal details can be used in spear-phishing to gain the trust of your employees.  Let's say you name your new business supplier (XYZ Corp) in your press release.  A few weeks later an e-mail is sent to your accountant that appears to be from XYZ Corp saying they just changed banks and to use the below banking information to pay future invoices.  You figure out that it was a phishing e-mail when XYZ Corp starts calling you because of all the unpaid invoices, and now you are out the money.

Job Postings:  One of my pet peeves is all of the information you can glean from an organization's job postings.  An example is if your company is hiring a Database Administrator, you don't have to say in the posting "Must be experienced with MS SQL Server 2008 R2 Express"  This tells the public what version of your database you are running, and what security issues you may be vulnerable to.  Simply saying "Must be experienced with MS SQL Server" will suffice.

Vendor Endorsements: I never give public vendor recommendations (posted on the vendor's website).  Why?  Because I don't want anyone knowing too much about the inner workings of my business, such as my vendors.  The reason being is that a cyber criminal can use that relationship to try to spear phish either company.  Also, this may not be something you want your competitors to know about either.  If you have a really good vendor relationship and they want a recommendation, offer to give one-off personal recommendations.  Just don't put it out on the web for the world to see.

Website Contacts: If possible (granted it is a must for some industries), do not have a directory of your employee's names and contact information on your company website.  This is a treasure trove for cyber criminals for both phishing e-mails as well as scam phone calls.  Use generic contact e-mails in your Contact US sections such as sales@xyzcorp.com, or even better is a contact form that does not disclose company e-mail addresses.


Tips for your employees:

Social Media: Encourage your employees to leave their job duties generic when updating their LinkedIn profile or online resumes.  If you are an Accountant for a business, that is great.  You don't have to put on LinkedIn that you handle all of the business's banking, send wire transfers, or are familiar with Wells Fargo's business banking portal.  This is way too much information to be giving out to potential cyber criminals and can be utilized in a Business Email Compromise (BEC) or spear -phishing attack.  Save the details for the resume you submit to a potential employer.  The one you publicly post should be a summary.

Technology questions using company e-mail address: Technology folks will often visit tech blogs and websites soliciting information and knowledge regarding a problem they are trying to resolve.  This is all well and good, but sometimes they post detailed questions that disclose the names/versions of systems and applications using their company e-mail address, and therefore identifying the organization with the problem.  Information about current IT issues (whether security related or not) should not be publicly disclosed.  It's not something you want hackers to see, and it doesn't look good to current or future customers to see.

Be Secure!

@tjmprofessional

Thursday, October 4, 2018

How to Overcome Your E-mail Insecurity - Part 3 of 3

Phishing
Less complex than BEC, but even more widespread, phishing e-mails will usually come from free e-mail providers, ex. gmail, yahoo, outlook/hotmail, but will have a display name that is different than the actual e-mail in trying to gain your trust.  The e-mail is supposedly from DHL, UPS, DropBox, Microsoft, or some large company that you trust, but then you find out that the underlying e-mail address is not from that companies e-mail domain, but is a gmail account or a similar domain like DHL_Accountservices.com, etc.  

Some recent attacks actually impersonated domains to try and fool employees at the actual business.  An example is if your business e-mail domain is "marysdonuts,com", the impersonated e-mail domain might be rnarysdonuts.com, whereby the "m" is replaced with an "r" and an "n" to fool your eye into thinking it's a lower case "m".  Cyrillic alphabet characters have also been used to play tricks on your eyes.

Security Tip:  Like the BEC e-mails, there is a call to action, usually an attachment (virus infected) or a button/link to click. 

Ask yourself these questions when you receive an e-mail:
  1. Do I know the sender?  (hover your cursor on the display name or click the display name to see the real e-mail address)
  2. Am I expecting this e-mail or any attachments from this sender?
If you answer "No" to either question, it is probably a phishing e-mail. Again, if you do know the sender, pick up the phone and verify that they sent you the e-mail and any attachments. 

So the lesson at the end of the day, is if you want to be safe, and not be a victim of e-mail fraud, BEC, or phishing you should use the low tech communication device that was invented by Alexander Graham Bell and verify before taking action based on e-mailed instructions.  After all, as discussed in my Part 1 blog post, e-mail is not secure by design.

Be Secure!

@tjmprofessional


Saturday, August 25, 2018

Phishing is not a Technology Problem

In reading the title of this post, IT folks all around the world are shouting at the top of their lungs; "Amen!".

While perhaps not a profound statement for the IT community, it is however a true statement that phishing is not an IT risk, but it is a Business risk.  Phishing is about social engineering or the use of trickery and deception through the utilization of technology as a delivery platform to coerce your employees into e-mailing mass HR or customer data, give up their password, or send money to the criminal posing as a company executive, government official or a vendor.  Therefore it is the social engineering aspect that needs to be addressed, but rarely is.  Hence, why Phishing is very effective, very profitable, and the volume and complexity of attacks are growing at a rapid pace.

The security software and appliance providers keep upping the ante with the latest technology tools (now AI) to detect or block phishing e-mails, but at the end of the day, this is just a holding action, not a sustainable solution as it is not 100% effective.  The root cause is still sitting one foot in front of the keyboard.  It is your employees and contracted staff that make phishing attacks possible.  And this is where the least amount of budget and time are spent on reducing your organization's risk of being phished.

Security experts have been debating for years about how effective security awareness training, mock phishing exercises, the security posters hung in the break room, and posting security tips on your organization's intranet site are.  And to be honest, perhaps the jury is still out on having any scientific data on that, but what is the alternative?  Do nothing?  We've seen first-hand with recent data breaches how well that works. 

Perhaps the secret formula is a balanced approach of tools, training, and procedures to combat this business risk.  At the end of the day, if you have tools that scan e-mails for suspicious activity, you train your employees on what phishing e-mails look like, give them an avenue to report them (be included in the security process), and hold mock phishing exercises with a teachable moment built in to educate, plus have well communicated procedures on not e-mailing mass data without approvals, or not sending wires without phone verification, or that the CEO (who probably doesn't remember your name) is never going to ask you to "kindly" pick up some iTunes gift cards at the store, then perhaps your organization has a shot at thwarting the Phishers.

Be Secure!!!

@TJMProfessional



Sunday, July 8, 2018

"Are you still in the office?" - A Phishing Story

The below is based on a true story:

Monday at 5:00 pm - You are just leaving the office.

You happen to have left the office on time today (for once) for your kid's soccer game, a happy hour, a hot date, or whatever.  At 5:35 pm you get an e-mail from your boss.  The subject is "Are you still in the office?".  Of course you open the e-mail.  In the body of the e-mail, your boss says "Hey, are you still there?  I need you to do me a favor that's most urgent."  Naturally you want to please your boss, and be responsive.  You immediately respond; "Sure, what do you need?". You then get a reply back; "Thank you so much.  I have a client that I am going to be meeting tonight, and really wanted to "Wow" them by getting their team some iTunes gift cards.  I totally forgot to get them.  Can you run out to a store and get me four $250 iTunes gift cards.  Once you have them, scratch off the back to reveal the code and kindly send me photos of the codes.  I need them before dinner is over at 8:00 pm tonight."

You make a slight detour on the way to your after-work event to stop by a store and purchase four iTunes gift cards with your corporate card.  You then whip out your phone and send your boss photos of the codes by 6:20 pm, and are still able to make your event.  You saved the day for your boss and helped him/her win over the new clients.  Deep down you are hoping your part in this is remembered when raise/bonus evaluation time comes around.  All is right in the world.

Tuesday Morning at 8:10 am - You are in the office and just grabbed your morning coffee.

The boss walks by your desk and says "Good Morning".  You respond in kind and add, "How did the clients like the gift cards?"  Your boss stops, turns to you and says "What are you talking about?"

It is at this point you find out that the e-mail was not from your boss, but that you were the victim of a spear-phishing e-mail.  The cyber criminal stole a $1,000 which you put on your corporate card and had thought you would be getting reimbursed for.

Does this sound like a far fetched story?  It's not.  It is safe to say that thousands of intelligent people around the world fall for this type of phishing campaign every day.  Per the FBI's 2017 Internet Crime Report*, there were 25,344 reported phishing victims in the US alone in 2017.  Keep in mind, most phishing attacks go unreported due to the victim being embarrassed for having been tricked.  Today's cyber criminals rely on human behavior over technical skill.  They will use fear, greed, people's good nature and helpfulness to try to defraud your employees and your business.  Security awareness training is a very effective defense against phishing attacks and is fairly cheap.  Speaking of awareness, let's get to it.  Below are some tips as to what this employee should have done to prevent being a victim:

Tips:
1.)  If you are getting an e-mail from someone (such as your boss), and the request is unusual (ie. not something they have ever asked you to do before.), pick up the phone and call them on a number you know is valid.  Also, if the e-mail is from the CEO or CFO and they most likely don't even know your name, they probably aren't asking you for a favor.  This is when it is good to forward it to your boss with your suspicions, and ask him/her to look into it.  Communicate outside the e-mail thread and use the chain of command to authenticate odd e-mail requests.

2.) Any e-mail asking you to buy something (typically iTunes, gift cards, or prepaid debit cards), transfer customer/employee data, or transfer funds (sending a wire, ACH, Western Union, Money Gram, etc.) needs to be independently verified by picking up the phone and calling the person on a number you know is valid (don't use any contact info in the e-mail that was sent to you).

3.) Cyber criminals know what your office hours are.  So look for "Urgent" requests after hours as highly suspicious.

4.) As with #3 above, the cyber criminals know you most likely will be checking your work e-mail after-hours with a mobile device.  Most mobile phones only show the display name, not the actual e-mail address, so they can send an e-mail from a gmail account with your boss, CEO, or CFO's name displayed and it will appear on your phone or tablet as the display name, not the actual e-mail address.  Click on the display name to show the actual e-mail address.  Even if it looks legit, still call.  No one ever got fired or in trouble for verifying e-mail instructions that seem odd.

5.) Look for very short e-mail messages (with no details).  Also bad grammar/spelling are common signs.  In addition, look for non-American style English being used  "I have a most urgent request" or "Kindly send me the gift card codes."  Does your boss or CEO talk like that? 

6.) Let's say you fell for it, and realize it afterwards.   Report it!  You can still save the day.  In this case, the employee should have notified his company's security officer or HR so that all the other employees could be notified of the scam to prevent additional victims at your organization.  Secondly, he/she should contact Apple and had the codes deactivated.  It wouldn't get the money back, but it would stop the criminals from getting it.  When criminals see a good target, they will keep coming back.  Try to ensure that their attack on you isn't profitable.  This way they will seek an easier target next time and leave you alone.  



Be Secure!


Link to the 2017 FBI Internet Crime Report
* https://pdf.ic3.gov/2017_IC3Report.pdf

Friday, May 25, 2018

No Silver Bullet for the Cyber-wolves

The majority of individuals and businesses are sold a bag of goods regarding cyber security.  They hear marketing pitches for security software, appliances, and managed services, and are told that "this product" or "that service" will secure your business or secure your home computer, and at the end of the day, it is giving them a false sense of security.

While these products and services can help reduce your risk of a cyber incident, they are only a small piece of your overall security program.  There is no silver bullet that can keep hackers at bay.  To do this, you need to employ a Defense in Depth security program.  While this sounds like a daunting and expensive task, it can actually be done very inexpensively and with a few simple steps.

Risk Assessment - "If You Can't Measure It, You Can't Improve It." - Peter Drucker
The first step is to have a security risk assessment performed.  This informs you where your information security risks are, what controls you have in place, and what control gaps/weaknesses you need to shore up.

Polices, Plans & Procedures - "Those that fail to plan, plan to fail."  - Alan Lakein

  • Information Security Policy - This should cover, at a minimum, access control/user management, anti-virus, patching, password management, data classification and handling, use of encryption, remote access, change/configuration management, software acquisition/licensing, logging, and use policy.
  • Incident Response Plan - You need to have this before you have an incident.  Don't worry about trying to identify every single type of incident to deal with, just get it down to high level impact, ex. network outage, server outage, application outage, security breach, malware infection, etc.  Have written procedures on how our staff should respond to each of these types of incidents. 
  • Business Continuity Plan - If there is an electrical outage, fire, or natural disaster you need to have a plan of action on how and where you will resume your business.  Also have all your employees, contractors, and vendor contact information in the plan.  Keep the plan in multiple locations, including a hard copy at your home.  If there is no power, your cloud or PC may not not be accessible.  Do not get hung up on the type of disaster, focus on the fact that your office in not accessible, and the plan needs to answer the question "What do I do now to stay in business?".  Do a paper walk-through with your management team at least twice a year and update contact info.


Anti-Malware (Anti-Virus, End Point Control, Patching)
Having anti-virus and end point protection is not optional.  Make sure they are actively running, updated daily, scans are daily (off hours), and that only an Admin can disable or change the settings.  Also, no user on your business network should have Local Admin, and the IT guys should have an Admin account for doing things that require Admin access, and a non-Admin (normal user) account to surf the web and check e-mail.  Malware is most dangerous if it can execute using Admin privileges, and whoever clicks on it,,,executes it.   Patching needs to be done timely on operating systems, database management systems (MS SQL, MySQL, Oracle), and application software (Apache, Adobe, Office, etc.)

PC & Server Hardened Standard Image
Your PCs and servers require certain services to operate.  Over time, as you add software, more and more services are activated, and usually set to run at startup (when most do not need to).  Besides slowing down the machine and providing a poor user experience (takes forever to start up and to shutdown), having unnecessary services running is increasing the attack surface for a hacker or malware.  You should have a standard image for your organizations PCs and servers in which you deactivate all non-essential services (daemons if in the Unix/Linux world).  Also, remove all no-essential user accounts.  Most operating systems and applications come with Test or Guest accounts.  Either remove them or disable them.  If you have to keep any default accounts, then change the passwords and make them complex (10-14 characters, alpha-numeric, caps, and special symbols).  this is called hardening.  Once you have a hardened image, copy it, and that is what every machine in your organization gets as a baseline.  And as you are not letting your users have Local Admin, they will not be able to install software which will ensure that only approved, malware free, and licensed software is running on your network.

Network Security
You should have multiple layers of firewalls/routers/switches.  Keep these patched timely too, and all default accounts and passwords need to be changed.  You should have some type of Intrusion Detection or reporting system in place to sift through the firewall logs and report the critical alerts so you know if you are under attack, and can follow your Incident Response Plan as noted above to prevent or stop an attack.

Security Awareness Training
While listed last in this post, it is by far the most important low cost security measure you can do.  Cyber Criminals have figured out that it requires a lot of skill and hard work to hack your network.  It is much easier to trick your employees into giving them a userid and password, your customer/employee data, or wiring money out of you business bank account.  Your awareness program is not a once a year video or PowerPoint slide deck.  It needs to be ongoing and use a number of mechanisms to stay at the top of mind of your employees.  Monthly security tip e-mails, security posters in the break room, mock phishing exercises, having a security expert come in quarterly for live or web based training, having your IT or security team do monthly brown-bag lunch presentations will have a big impact on your employees' security awareness.

To sum it up, there is no silver bullet, and information security is not a menu to choose from.  You have to do all of these things, and more to have a defense in depth security architecture.    You need to put up enough barriers to frustrate them which will encourage them to leave your organization alone and go hack someone else...(hopefully your competitors who don't take my advice).



Friday, January 12, 2018

Vishing, It's not Just for Kids Anymore.

When I was a kid, it was common practice to phone scam your grumpy neighbors.  Calling and asking; "Is your refrigerator running?", and getting the response "Uh yes it is.", and then saying "Then you better go catch it!", was something that gave us hours of childish joy at the expense of our severely annoyed neighbors.

I had thought those days were behind me, but I guess not.  So in addition to phishing, another attack vector that scam artists and hackers are starting to employ with greater frequency is Vishing or Voice Phishing.

The common approach is that they get a list of names and phone numbers and will call folks and pose as their electric utility, their cell phone provider, or the water company.  They will be calling because they either didn't get your last payment and now have to shut off your service, or have some other urgent matter to speak with you about.   I have also seen where this is automated using a phone dialer and a recorded message instructing you to call another phone number immediately to resolve the issue.  They will then try to get you to provide them with your personal information in order to "verify" who they are speaking with.  They will structure the call in a way so they get your information in pieces so it doesn't raise any suspicions.  They may try to get your banking or credit card information in order to "pay your overdue balance".  Remember, if one of your service providers is calling you, they should already have your information as they are calling your phone number of record.

Red Flags to look for:

  1. Your utility companies will give you multiple late notices and you will need to be 2+ months late on paying your bill before they shut off your service.
  2. If you get one of these calls and are not sure if it is a scam, hang up and call the phone number on your last bill.  This way you will know if it's legit.


Another popular vishing scheme is to call posing as the IRS.  This scam has been targeting businesses and individuals alike.  The "agent" will claim that you have an outstanding tax debt and it has to be paid immediately or you will be taken to court, lose your house, business, car, and bank account.  As with "turning your service off" above, this scam preys upon most people's fear, and who isn't fearful of getting into trouble with the IRS?  In some cases the scam is more about getting your social security number and date of birth rather than payment.  Either way, don't give any information over the phone.

Red Flags to look for:

  1. The IRS will never call or e-mail you about a tax debt, they will send you notice via certified mail.
  2. The IRS will never ask you to pay your tax debt using Western Union, Money Gram, or by getting a prepaid debit card at your corner drug store.
While the above two schemes have been known to target both individuals and businesses, the last one I'll be discussing is just focused on individuals.  

In this scenario, the caller will tell you they are calling from the local courthouse, and you had been sent a notice for jury duty months ago, but you did not show up to court today, so you are now in contempt.  If you want to get out of going to jail, you need to immediately send money to pay the fine using Western Union (or one of their competitors).  Again the fear factor is used to create panic and a sense of urgency.

So the lesson here is you need to authenticate the person on the other end of the phone.  When in doubt, hang up and call back using a phone number you know is legitimate.

If only my grumpy old neighbor could see me now.

Be Secure!



Wednesday, January 3, 2018

How long it takes a Hacker to notice your website?

Like most small business owners, I did all of the SEO things one does when they have a new business website up and get noticed by search engines and clients.  I set up my descriptions, keywords, signed up for Google My Business, and created a profile on Manta.  With my website up for only 1 day, per Google Analytics I got my first visitor.  Can you guess from where?  You guessed it, Russia.  Not really part of my geographic profile, but what the heck, a website visitor, is a website visitor.  The individual had spent about a minute on each of my pages.  That’s great, I’m getting noticed the first day my website is up. 

And then on day 2, it happened.  I had an e-mail in my Spam folder.  I looked at the subject line, and sure enough, it was a phishing e-mail.  The e-mail was in the name of an individual and the subject line read “Your Monthly Statement document is ready for review”   Keep in mind, my website had been up for only 2 days.  My website and the listing websites were the only places my newly created company e-mail was posted.  And when I hovered my cursor above the displayed e-mail address, yes you guessed it, it had a .ru domain. 
A week later I got my first spear phishing attempt.  This e-mail was also displaying the name of an individual and the subject line read; “Please DocuSign: Order Form for tjmprofessional.com” and the body stated; “ accounting@tjmprofessional.com has sent you a document to review and sign. “.  Ironically, I don’t have a separate generic e-mail address called “accounting”.  But to give credit to the hacker, it did look more enticing and believable.  And yes, again the e-mail had a Russian domain.

So if you are wondering if your a 6 month old startup, or your 50 year old family business is at risk for a cyber attack?  The answer is most definitely "Yes!".  My business was found, researched, and attacked within 2 days of its online existence. 

Now if only my clients could develop these hacker skills, and find my website as easily.  Who would need to pay for Google AdWords?   J


Tuesday, November 28, 2017

Too much information - 5 Tips for Businesses

Our reality is that we live in an age where information that was once an online currency has been devalued by one simple fact.  We give it away for free everyday.  Whether as individuals or as businesses, your online footprint is most likely pretty large.  We want to let our friends and families know about the big events in our life, trips we take, places we are at, where we work, and things we buy.  At the same time, businesses need to have a large online presence to do business in the 21st century.  One of the first lessons of SEO (Search Engine Optimization) is to be listed on as many sites as possible.  While this is all well and good for improving communication with friends families and to market products and services for businesses, it is also feeding cyber criminals valuable intelligence on how and when to strike.

From a personal standpoint, there have been cases where burglars created fake Facebook profiles and then would be able to get a number of people in their area to accept friend requests.  Then once someone posts that they are going to be on vacation for a week, that is when the burglars would strike.  And now with Geo-location features on various apps and social media sites, your "friends" and followers can track your physical movements, which will automatically tell bad actors when you are not home.  For your personal online footprint, the FBI has recently released tips for giving out too much information on social media.  Rather than restate these tips, below is the URL:

https://www.fbi.gov/contact-us/field-offices/portland/news/press-releases/fbi-tech-tuesday-building-a-digital-defense-against-the-dangers-of-using-social-media-while-traveling

For businesses, it can be more difficult to reduce the amount of information about your business online as that is contrary to your goals of customer acquisition and increased sales.  So for businesses, not for profit organizations, and municipalities, below are my 5 tips on how to better defend yourselves:

  1. Limit your information leakage to the public - Over the years, one of the things that drove me nuts was the amount of company specific details that Human Resources and/or hiring managers would put in job postings online.  If you are hiring a Database Administrator, it is sufficient to say "Experienced with Oracle".  You do not need to put the version and release number you are currently running in the job posting.  Also many medium to large companies may have in-house developed applications.  Stating in the job description, "Experience with the STARS loan system" not only serves no purpose (As only your current and former employees would have experience with it.), but now you just let every cyber criminal know the name of your loan system, which could be used in a social engineering attack on your company.
  2. Train Employees - If Mary in accounting is the person who wires money to pay vendors and performs your organization's online banking activities, please train Mary not to put that little tidbit of information on her public LinkedIn profile.  Give employees security awareness training, and tips on how to state their job duties on LinkedIn so that it doesn't make them a phishing target.  On the subject of phishing, train employees how to recognize phishing e-mails, not to click on e-mails from people they don't know, and not to click on attachments they were not expecting.  It may seem like a little thing, but the untrained employee is still the best asset a cyber criminal has.
  3. Mis-information - This can be one of the most effective strategies I've seen used.  As an example, the one company I worked for would always include the official name (as it is stated on the Deed) of our headquarters building on their website and in press releases.  It was the Kent Building.  The interesting thing is that internally, all the employees had a nickname for the building, and it wasn't shared outside the organization.  So as you would imagine, we would get a number of calls and e-mails from bad actors saying they were a contractor, or a new employee and needed to get their password reset.  When the help desk would inquire which building they were in, sure enough, they were in the "Kent Building".  That would be one of many signs that this request was a scam.  So think of something that you can put out there that is not key to your business, but could mislead an attacker, and signal your employees on the front line that it's a scam.
  4. Social Media & Communications Policy -  Have a company policy on who can post on the companies social media and websites, a review process to ensure that what is posted is appropriate and not leaking any internal information.  Also the policy should include what employees and contractors can and cannot post on their personal sites regarding the organization.  Believe it or not, but I've seen an IT Ops guys take selfies in the Network Operations Center of himself, with monitoring consoles in the background showing every major system in the company on the photo,  and it was posted to his Facebook page as "Tim at work".  A policy won't prevent anyone from doing something stupid, but it does at least let them know upfront that it is not allowed and what the consequences are if you violate the policy.
  5. Authentication Procedures - I'm not talking about entering your user id and password here, but taking that concept and employ it with any type of front line points of human contact, ie. phone calls, e-mails, chat, texts, etc.. (In other words, defend against Social Engineering)   Employees who are responsible for servicing your customers, deal with vendors, perform banking activities, or administer security should have written procedures on how to make sure that e-mail instructions are authentic, or that the person on the other end of the phone is who they say they are.  Too many times organizations have had their security compromised because of the "new employee" on the phone that got locked out of the VPN, or the CEO e-mailing Mary in accounting to send a wire for $1 million to a bank overseas to fund a new project.  Your employees need to have procedures, and be trained on them, so that they can verify these seemingly normal requests before they act. If left unchecked, this could could cost your organization big time!