ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

The shortcomings of email security

Justice Levine at Guardian Digital asks: Why do so many cyber attacks still begin with an email?

 

Email is the preferred method of business communication, which has only been magnified by the remote work environment because of the pandemic. And while cyber attacks are increasing across the many threat vectors, email still remains the most common channel for targeted attacks. 

 

Over 90% of modern cyber attacks are initiated via email because cyber criminals are readily taking advantage of increased reliance on business, along with common weaknesses in traditional methods of securing business email.

 

As attackers continue to advance and increase the sophistication of their methods and techniques, static, single-layered email security defenses like endpoint security solutions and Microsoft 365 email security limitations provide inadequate protection for organisations. As a result, many companies remain highly exposed and are often unaware that their security solutions are inadequate until they are breached. 

 

So why does email remain the preferred method of attack among cyber criminals in 2022? 

 

Technology gaps in email security defenses

Technology gaps in email security defenses are resulting in low detection rates and high false positives.

 

Protecting against the different types of advances presents challenges, especially for threats such as advanced phishing and spear-phishing that leverage multiple evasion techniques, impersonation attempts, sophisticated ransomware attacks, account takeover, zero-day vulnerabilities, and more. 

 

Many email security systems are not equipped with the technology necessary to detect these sophisticated threats. Furthermore, widespread technology gaps often impact detection rates.

 

Hackers can easily evade programs that identify potential malware by modifying their code in ways antivirus software can’t detect, so relying on signature-based antivirus software is ineffective. Codes that are new or rare also cannot be detected if they aren’t logged in the database.

 

Hackers also use packers, programs that hide malware, which make it particularly difficult for analysts to access the original code and analyse it.

 

On the other hand, sandboxes are slow and often bypassed despite being a common approach for dynamic scanning. Advanced malware can be challenging as specific variants may require command lines in order to be executed. 

 

They may also be dormant until commands are executed, but are unable to run this type of malware as they lack command-line options and don’t allow enough time to detect the malicious command lines.

 

Limited system agility 

Limited system agility interferes with the detection of advanced and emerging attack vectors. Low detection rates can be the result of the fact that many systems lack the flexibility to learn and adjust threat detection techniques and algorithms due to changing attacks seen in the field. 

 

Technology requires this flexibility and agility to support new logic and rules added by the vendor and customers’ IT administrators to increase detection rates in order to be effective in protecting against evolving and emerging threats. New logic and decisions and new phishing site URLs can be dynamically deployed to instantly prevent future attacks.

Inadequate incident response infrastructure and resources

 

Having healthy communication between your company’s IT team, the security vendor, and the end-users is a necessary element. An Incident Response team’s key role is to achieve the best detection rate and lowest false-positive rates by keeping the window of communication open between all of the involved parties. 

 

Because of this, it is crucial that the response team has the expertise because of the challenges from companies to dedicate sufficient in-house time and resources to properly manage the growing number of incidents. Organisations cannot gain nor leverage the knowledge from the suspicious attacks that may have bypassed their system for continuous optimisation when Incident Response resources and infrastructure are lacking.

 

Messy and complex email protocols

Organisations regularly face the challenge of failure to properly configure protocols, such as SPF, DMARC, and DKIM which can affect the effectiveness of their email security. 

 

SPF, DKIM, and DMARC are standards that are put in place for systems and devices that work to improve communications, verify sender identity and confirm the legitimacy of email messages. An organisation can implement DMARC, but it can’t control how much security is integrated into each business partner’s individual system.

 

Lack of visibility

Lack of visibility makes it difficult to measure system performance. Key performance indicators are an important tool for an organisation to understand both the efficiency and accuracy of its business email security system. This is because they measure false positives and false negatives. However, setting up KPIs is not often an easy task for a company. 

 

False negatives are malicious emails that have found a way to bypass security, and not all solutions provide a proper way to view the statistics. This can cause many companies to have concern that their solution is underperforming without having any proof in data to back up the claim. 

 

The lack of visibility is mainly attributed to ineffective handling of the slow security incidents or proper support in solutions to retrieve the correct number of incidents.

 

The bottom line

In contrast with other communication channels, securing business email is more challenging for many reasons that can be difficult to resolve. That being said, with over 90% of all cyber attacks beginning with an email, email is also the most critical channel to secure. 

 

Bridging the email security gap has never been more necessary, and having the right tools at your disposal, can be achieved. The first step is to implement an email security strategy that meets all requirements to keep your business safe.

 


 

Justice Levine is the Communications Manager for Guardian Digital

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543