Quantcast
 
Search for: Search what?
Jul 6, 2009  
 Sections
Latest New Product News
Industrial Market Trends
Green & Clean News
Association & Government News
Adhesives and Sealants
Agricultural and Farming Products
Architectural and Civil Engineering Products
Automatic ID
Chemical Processing and Waste Management
Cleaning Products and Equipment
Communication Systems and Equipment
Computer Hardware and Peripherals
Construction Equipment and Supplies
Controls and Controllers
Display and Presentation Equipment
Electrical Equipment and Systems
Electronic Components and Devices
Explosives, Armaments and Weaponry
Fasteners and Hardware
Fluid and Gas Flow Equipment
Food Processing and Preparation
Health, Medical and Dental Supplies and Equipment
HVAC
Labels, Tags, Signage and Equipment
Laboratory and Research Supplies and Equipment
Lubricants
Machinery and Machining Tools
Material Handling and Storage
Materials and Material Processing
Mechanical Components and Assemblies
Mechanical Power Transmission
Mining, Oil Drilling & Refining
Mounting and Attaching Products
Non-Industrial Products
Optics and Photonics
Packaging Products & Equipment
Paints and Coatings
Plant Furnishings and Accessories
Portable Tools
Printing and Duplicating Equipment
Retail and Sales Equipment
Robotics
Safety and Security Equipment
Sensors, Monitors and Transducers
Services
Software
Test and Measuring Instruments
Textile Industry Products
Thermal and Heating Equipment
Timers and Clocks
Transportation Industry Products
Vision Systems
Waste Handling Equipment
Welding Equipment and Supplies
 Press Releases
Products in the News
Company News
Mergers & Acquisitions
People in the News
Literature & Websites
 Resources
News Delivery Options
Browse Categories
Browse Companies
Mobile Edition
PR Resources
Licensing
Advertising
How to Write an effective Press Release
Trade Associations
Small Business Support
MEP
Advertisement
Micro Plastics, The Worlds Largest Manufacturer of Threaded Nylon Fasteners
Machine Screws, Nuts, Washers, Standoffs, Spacers, Rivets, Clamps, Clips, Knobs, Printed Circuit Board Hardware, Panel Fasteners, Wire and Cable Hardware. - - - FREE SAMPLES

Web-Based Solution lessens spear fishing vulnerability.


July 31, 2008 - PhishMe enables user awareness training to proactively thwart spear phishing and whaling attacks, cyber crimes that use email-based social engineering to gain unauthorized access to corporate systems and confidential data. With built-in templates and WYSIWYG functionality, users can build real phishing attacks against employees within minutes, collect metrics on user behavior, and immediately present training material to employees that fall prey.

 See related product stories
Anti-Virus Software updates every 5-15 min.
Software provides policy-based end point encryption.
Software creates secure online backup of data.
Software provides backup for users of whole disk encryption.
Software offers scalability to data backup service providers.
 See more product news in:
Software
 Tools for you
del.icio.us DIGG  
Facebook Reddit
StumbleUpon Twitter
Print This Page E-Mail Story
Watch_Company  Save Story
View Company Profile
Company web site 
More news from this company

Advertisement
More Tools and information
Search for suppliers of
Testing Software
Data Security Software
Courseware Software
Anti-Virus Software
Join the forum discussion at:
 Engineers Lounge
 Newsletters
Your Gateway to a Fast Changing World
Product News Alerts
Receive similar stories and other customized news to keep you in the know on the products shaping industry.
Subscribe Free Today
Subscribe   View Sample

Industrial Market Trends
Has Got It
  • Latest developments
  • Trends
  • Best practices
  • Opinions & Commentary
Get Ahead. Get IMT.
Subscribe Free Today
Subscribe   View Sample
 See more related product stories:
UTM Security Gateway targets medium to large enterprises.
Software displays signal conditioner data in real time.
Software for MSSPs offers customer and management insight.
Software enables device and heterogeneous system testing.
Software provides access control and identity management.
Software automates IT risk discovery and remediation.
PC Optimization Software targets Windows users.
Software provides centralized network security.
Software manages information and supplier risk.
Applications protect and manage software licenses.
Software removes/protects against spam and spyware.
Software protects vulnerable servers.
Anti-Spam Solution delivers email security in the cloud.
Software streamlines file backup and synchronization.
Software analyzes website/web application vulnerability.
Software automates mainframe security operations.
Software offers all-in-one defense against various threats.
Simulation Software promotes NDE analyses in parts modeling.
Test Management Software streamlines development time.
Software blocks malware and unauthorized software.


Intrepidus Group Introduces PhishMe to Help Organizations Deal with Growing Pandemic of Spear Phishing


Web-based User Awareness Training Solution Helps Companies Protect Vital Information From Cyber Criminals

NEW YORK, July 22 -- Intrepidus Group, a leading provider of information security services, today announced the release of PhishMe, a software solution that enables user awareness training to proactively thwart spear phishing attacks. The next-generation technology is an important weapon in the fight against the fast-growing and ominous threat of spear phishing and whaling attacks, a form of cyber crime that uses email-based "social engineering" to gain unauthorized access to corporate systems and confidential data.

Unlike mass-phishing perpetrators, who use spoofed emails to cast a wide net to fraudulently gather data from unsuspecting victims, spear phishing attackers target specific organizations and individuals. Unfortunately, this targeted and sophisticated technique has proven extremely successful in providing "hackers" access to financial data, corporate and military information, and trade secrets -- with the final goal, of course, financial or political gain.

"Emerging security threats to the corporate landscape put both the information and company as a whole at risk. Spear Phishing is a considerable danger as it is typically a non-random attack seeking specific confidential information," said Kenneth Tyminski, former CISO for Prudential Insurance Company of America. "The training-based approach of PhishMe helps to significantly reduce these targeted attacks through employee education, helping to safeguard sensitive networks from unauthorized access."

According to a recent report by iDefense Labs, a noted security and vulnerability research organization, there have been 66 distinct spear phishing attacks between February 2007 and June 2008, with the rate of attacks continuing to accelerate. The report goes on to say that spear phishing groups have claimed more than 15,000 corporate victims in 15 months, with victim losses exceeding $100,000 in some cases. Victims include Fortune 500 companies, financial institutions, government agencies, and legal firms.

"E-mail is critical to our business, but also a risk to the security of our network and information. Technical controls like firewalls and spam filters help, but only by making our employees part of our defenses can we be successful," said John Soltys, Information Security Manager at the Seattle Times Company. "By targeting our users in the same way attackers do and delivering an education message when the attack is successful we raise their awareness level and mitigate the risk. PhishMe's service simplified the administration of tests and provided more value than the in-house tests we've run in the past."

"Spear phishing groups are now incredibly sophisticated and, unfortunately, extremely effective," commented Robert Hansen (aka "RSnake"), a former member of the Anti-Phishing team at EBay and well-respected security blogger. "We're talking about experienced cyber criminals who have the skill and tools to pull off these schemes."

User Behavior Key to Defense

Several high-profile experiments have proven that user behavior provides the foundation for defense against spear phishing schemes. Mass-phishing campaigns are often caught by anti-spam or phishing filters. But spear phishing attacks, which are low-volume and closely resemble legitimate emails, often go undetected. That's why organizations have to rely on humans for detection and resistance.

"I often perform investigations for my clients where the initial point of entry into the victim's computer network comes from a phishing email," said Keith Jones, senior partner, Jones, Dykstra & Associates. "Phishme.com is a breakthrough service that provides corporate security teams with the ability to spread user awareness about this email plague by testing their own user base. Phishme.com provides the auditor with an extremely easy to use interface to conduct a phishing scenario and excellent reporting capabilities complete with summary graphics. I was able to complete a phishing scenario for our employees at Jones, Dykstra & Associates in less than 10 minutes of use. I will be highly recommending Phishme.com to my clients to help them continue their fight against phishing attacks."

In one experiment, New York's chief information security officer, William Pelgrin, and his team sent mock phishing emails to nearly 10,000 New York state employees. The messages appeared to be official notices asking them to click on Web links and provide passwords and other confidential information about themselves.

With the first run of the email 75 percent of employees opened the email, 17 percent followed the link, and 15 percent entered data. Pelgrin and his team let users who had proven vulnerable know they'd been scammed and then sent another mock spear phishing email. With the second run only 8 percent even opened the email. In an interview with the Wall Street Journal, Mr. Pelgrin said, "This is not a one-shot deal. I've got to reinforce that behavioral change to make it permanent."

And, in a study at Carnegie Mellon University, volunteers who had proven susceptible to mock phishing emails were presented embedded training materials, then sent another email. In the second run, the volunteers identified 64 percent of the phishing emails. This compares to a mere 7 percent identified by volunteers who had received teaching materials through other mechanisms.

Creating a Human Firewall

"Thinking like the attacker isn't natural for most people." says Aaron Higbee, CTO of Intrepidus Group, "Our job is to provide a do-it-yourself phishing framework with features real phishers can only dream about. Any phishing trend we see in the wild can be incorporated into PhishMe, only better." PhishMe is a software platform that lets organizations create a human firewall against spear phishing attacks by providing an easy-to-use system for facilitating the execution of mock phishing exercises and the delivery of user awareness training. Using PhishMe's built-in templates and WYSIWYG, (What-you- see-is-what-you-get) functionality, users can easily build real phishing attacks against employees within minutes, collect metrics on user behavior, and immediately present training material to employees that fall prey.

"Spear Phishing exploits human vulnerability. Thus our service focuses on the human element," said Rohyt Belani, CEO of Intrepidus Group. "We use techniques recommended by reputed bodies like SANS, and those found to be most effective by researchers at Carnegie Mellon University to train users in recognizing and thwarting targeted phishing attacks."

For more information, to view a demo or sign up for a trial account, go to http://phishme.com/.

About PhishMe

PhishMe is a software solution designed to help prevent damage, theft and loss caused by targeted (spear) phishing attacks. PhishMe facilitates and automates the execution of mock phishing exercises, provides clear and accurate reporting on user behavior, and most importantly provides targeted end user training. This method of delivering training materials is recommended by SANS and found to be most effective by researchers at Carnegie Mellon University.

About Intrepidus

Intrepidus Group is a leading provider of information security consulting services and software solutions. With offices in New York City and the Washington DC metro area, the company offers innovative solutions to help clients build employee awareness around common information security issues. Intrepidus Group's consultants conduct hands-on assessments of critical applications, networks and products to uncover vulnerabilities, and provide strategic and tactical recommendations to address identified issues.

Intrepidus and PhishMe.com are trademarks of Intrepidus Group. All other product and company names herein are or may be trademarks of their respective owners.

Company Information:
Name: Intrepidus Group, Inc
Address: One Penn Plaza
City: New York
State: NY
ZIP: 10119
Country: USA
Phone: 646-290-8355
FAX: 425-974-1514
http://intrepidusgroup.com




Click here for copyright permissions!
Copyright 2009 Thomas Publishing Company


 

Post a comment about this story

Name:
E-mail:
(your e-mail address will not be posted)
Comment title:
Comment:
 

Category Advertisements

Newsroom Advertisers




Visit Our New Web Site

Visit Our New Web Site

Visit Our New Web Site

Home  |  My Newsroom  |  Industrial Market Trends  |  Submit Release  |  Advertise  |  Contact NewsRoom  |  About Us
Brought to you by Thomasnet.com        Browse ThomasNet Directory

Copyright © 2009 Thomas Publishing Company
Terms of Use - Privacy Policy