{"id":119686,"date":"2015-03-01T14:00:19","date_gmt":"2015-03-01T12:00:19","guid":{"rendered":"http:\/\/mybroadband.co.za\/news\/?p=119686"},"modified":"2015-02-27T15:19:52","modified_gmt":"2015-02-27T13:19:52","slug":"dont-click-on-that-valentines-email","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/119686-dont-click-on-that-valentines-email.html","title":{"rendered":"Don&#8217;t click on that Valentine&#8217;s email"},"content":{"rendered":"<p>The theft of 80 million customer records from health insurance company <a href=\"https:\/\/www.anthemfacts.com\">Anthem<\/a> earlier this month would be more shocking if it were not part of a larger trend. In 2013, the <a href=\"http:\/\/archive.defensenews.com\/article\/20120324\/DEFREG02\/303240001\/U-S-Military-Goes-Cyber-Offensive\">Department of Defense<\/a> and <a href=\"http:\/\/www.deseretnews.com\/article\/865573798\/Cyberattacks-on-Utahs-secure-government-networks-up-dramatically.html?pg=all\">some US states<\/a> were receiving 10\u201320 million cyberattacks per day. By 2014, there was a <a href=\"http:\/\/www.idtheftcenter.org\/ITRC-Surveys-Studies\/2014databreaches.html\">27% increase<\/a> in successful attacks, culminating with the infamous <a href=\"http:\/\/www.heritage.org\/research\/reports\/2014\/10\/cyber-attacks-on-us-companies-in-2014\">hack of Sony Pictures<\/a>.<\/p>\n<p>Much of the media focus is on the losses rather than the process by which such breaches take place. Consequently, instead of talking about how we could stop the next attack, people and policymakers are discussing punitive actions. But not enough attention is given to the actions of individual end users in these cyberattacks.<\/p>\n<h3 class=\"my-4\">We are the unintentional insiders<\/h3>\n<p>Many of these hacking attacks employ simple phishing schemes, such as an e-card on Valentine\u2019s Day or a notice from the IRS about your tax refund. They look innocuous but when clicked, they open virtual back doors into our organizations.<\/p>\n<p>It is you and I who click on these links and become the <a href=\"http:\/\/www.sei.cmu.edu\/reports\/13tn022.pdf\">\u201cunintentional insiders\u201d<\/a> giving the hackers access and helping spread the infection. Such attacks are hard to detect using existing anti-virus programs that, like vaccines, are good at protecting systems from known external threats \u2014 not threats from within.<\/p>\n<p>Clearly, this virtual battle cannot be won using software alone. In the same way personal hygiene stymies the spread of infectious disease, fixing this cyber quandary will require all of us to develop better <a href=\"http:\/\/www.washingtonexaminer.com\/article\/2519577\">cyberhygiene<\/a>. We need to begin by considering the cyberbehaviors that lead to breaches.<\/p>\n<p>My research on phishing points to three. Firstly, most of us pay limited attention to email content, focusing instead on <a href=\"http:\/\/dx.doi.org\/10.1016\/j.dss.2011.03.002\">quick clues that help expedite judgment<\/a>. A picture of an inexpensive heart-shaped valentine gift gets attention, oftentimes at the cost of looking at the sender\u2019s email address.<\/p>\n<p>This is coupled by our ritualized media habits that our always-on and accessible smartphones and tablets enable. Many of us check emails throughout the day whenever an opportunity or notification arises, even when we know it is dangerous to do so, such as while driving. Such habitual usage significantly increases the likelihood of someone <a href=\"http:\/\/dx.doi.org\/10.1111\/jcc4.12100\">opening an email as matter of routine<\/a>.<\/p>\n<p>And finally, many of us just aren\u2019t knowledgeable about online risks. We tend to hold what I call \u201ccyber risk beliefs\u201d about the security of an operating system, the safety of a program, or the vulnerability of an online action, most of which are flawed.<\/p>\n<div id=\"attachment_119690\" style=\"width: 610px\" class=\"wp-caption alignnone\"><a href=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2015\/02\/Internet-for-dummies.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-119690\" class=\"wp-image-119690\" src=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2015\/02\/Internet-for-dummies.jpg\" alt=\"Internet for dummies\" width=\"600\" height=\"450\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2015\/02\/Internet-for-dummies.jpg 668w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2015\/02\/Internet-for-dummies-533x400.jpg 533w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/a><p id=\"caption-attachment-119690\" class=\"wp-caption-text\">Internet for dummies<\/p><\/div>\n<h3 class=\"my-4\">Cleaning up our cyberhygiene act<\/h3>\n<p>Developing cyberhygiene requires all of us \u2014 netizens, educators, local government, and federal policymakers \u2014 to actively engage in creating it.<\/p>\n<p>To begin, we must focus on educating everyone about the risks of online actions. Most children don\u2019t learn about cybersafety until they reach high school; many until college. More troublingly, some learn through risky trials or the reports of someone else\u2019s errors.<\/p>\n<p>In an age where online data remain on servers perpetually, the consequences of a privacy breach could haunt a victim forever. Expanding federal programs such as the <a href=\"http:\/\/niccs.us-cert.gov\/education\/stem-improvements\">National Initiative for Cybersecurity Education<\/a>, which presently aims to inspire students to pursue cybersecurity careers, could help achieve universal cybersecurity education.<\/p>\n<p>Second, we must train people to become better at detecting online fraud. At the very least, all of us must be made aware of online security protocols, safe browsing practices, secure password creation and storage, and on procedures for sequestering or reporting suspicious activity. Flawed cyber-risk beliefs must be replaced with objective knowledge through training.<\/p>\n<p>Although some training programs address these issues, most target businesses that can pay for training. Left out are households and other vulnerable groups, which, given the recent \u201c<a href=\"http:\/\/www.gartner.com\/newsroom\/id\/2466615\">bring your own device to work<\/a>\u201d (BYOD) trend, increases the chances that a compromised personal device brings a virus into the workplace. Initiatives such as the <a href=\"http:\/\/niccs.us-cert.gov\/training\/fedcte\">Federal Cybersecurity Training Events<\/a> that presently offer free workshops to IT professionals are steps in this direction, but the emphasis must move beyond training specialists to training the average netizen.<\/p>\n<div id=\"attachment_119692\" style=\"width: 610px\" class=\"wp-caption alignnone\"><a href=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2015\/02\/Barack-Obama.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-119692\" class=\"wp-image-119692\" src=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2015\/02\/Barack-Obama.jpg\" alt=\"Barack Obama\" width=\"600\" height=\"401\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2015\/02\/Barack-Obama.jpg 668w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2015\/02\/Barack-Obama-598x400.jpg 598w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2015\/02\/Barack-Obama-250x166.jpg 250w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/a><p id=\"caption-attachment-119692\" class=\"wp-caption-text\">Barack Obama<\/p><\/div>\n<p>Finally, we must centralize the reporting of cyber breaches. The President\u2019s proposed <a href=\"http:\/\/www.whitehouse.gov\/the-press-office\/2015\/01\/12\/fact-sheet-safeguarding-american-consumers-families\">Personal Data Notification and Protection Act<\/a> would make it mandatory for companies to report data breaches within 30 days. But it still doesn\u2019t address who within the vast network of enforcement agencies is responsible for resolution. Having a single clearing house that centralizes and tracks breaches, just like the <a href=\"http:\/\/www.cdc.gov\">Centers for Disease Control and Prevention<\/a> tracks disease outbreaks across the nation, would make remediation and resource allocation easier.<\/p>\n<p>Across the Atlantic, the City of London Police created a system called <a href=\"http:\/\/www.actionfraud.police.uk\">Action Fraud<\/a>, which serves as a single site for reporting all types of cyberattacks, along with a specialized team called <a href=\"http:\/\/content.met.police.uk\/Article\/What-we-do\/1400015320495\/falcon\">FALCON<\/a> to quickly respond to and even address impending cyberattacks. Our city and state police forces could do likewise by channeling some resource away from fighting offline crime. After all, real world crime is at a <a href=\"http:\/\/www.fbi.gov\/about-us\/cjis\/ucr\/crime-in-the-u.s\/2013\/crime-in-the-u.s.-2013\">historically low rate<\/a> while cybercrimes have grown exponentially.<\/p>\n<p>This article was originally published on <a href=\"http:\/\/theconversation.com\">The Conversation<\/a>. Read the <a href=\"http:\/\/theconversation.com\/before-decrying-the-latest-cyberbreach-consider-your-own-cyberhygiene-37834\">original article<\/a>.<\/p>\n<h3 class=\"my-4\">More security news<\/h3>\n<p><strong><a href=\"http:\/\/mybroadband.co.za\/news\/security\/119650-sim-spying-was-a-hacking-operation.html\">SIM spying was a hacking operation<\/a><\/strong><\/p>\n<p><strong><a href=\"http:\/\/mybroadband.co.za\/news\/security\/119604-sa-government-pcs-spied-on.html\">SA government PCs spied on<\/a><\/strong><\/p>\n<p><strong><a href=\"http:\/\/mybroadband.co.za\/news\/security\/119558-signal-jamming-probe-tabled.html\">Signal jamming probe tabled<\/a><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Normal Internet users may be the unintentional insiders who enable cyber attacks to spread<\/p>\n","protected":false},"author":340972,"featured_media":119688,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[5244,35,801],"class_list":["post-119686","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-cyber-attacks","tag-headline","tag-malware"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/119686"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/340972"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=119686"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/119686\/revisions"}],"predecessor-version":[{"id":119696,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/119686\/revisions\/119696"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/119688"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=119686"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=119686"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=119686"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}