Connect with us

Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website. .

Top Stories

NTT Security launches phishing service to test security posture of board members

NTT Security launches phishing service to test security posture of board members

Initial results show that would-be attackers can access critical data in just 10 minutes

NTT Security, the specialised security company and centre of excellence in security for NTT Group, is expanding its suite of phishing attack simulation services with the use of special social engineering techniques to check whether senior executives pose a security risk.

The ’Management Hack’ service is specifically designed with C-level executives in mind, such as the CEO, CFO or even CIO. Cyber criminals are increasingly attracted to this level within an organisation as senior executives are more likely to have unrestricted access to highly confidential company data, including financial information, which makes them a valuable target. Senior executives also benefit from special privileges, with security policies or standards suspended or relaxed for example to simplify login – often with fatal consequences.

NTT Security will first coordinate with the client – typically a CISO or the Head of IT – and simulated, personalised social engineering attacks are then carried out, with the individuals involved unaware they are being targeted. NTT Security then analyses how executives respond, identifies specific weaknesses, and recommends appropriate measures, such as security awareness training.

NTT Security’s Management Hack service includes verification of IT security, physical security (property protection) and human error analysis. Using social engineering techniques, such as phishing and personalised spear phishing combined with malware or brute force attacks on passwords, a simulated attack involves a five-step approach:

  1. Building a phishing website that simulates a customer or a website known to the customer
  2. Designing a phishing e-mail that leads to the phishing website
  3. Sending the phishing emails to the client’s senior management
  4. Intercepting login information or other sensitive information
  5. Producing a detailed report with statistics on the current security situation and measures to improve a company’s security posture.

A number of management hacks have been carried out by NTT Security in Scandinavia already with surprising results. Kai Grunwitz, Senior VP EMEA, NTT Security explains. “In many cases, we were able to access critical data, such as confidential business plans, mergers & acquisitions documents, domain controllers, usernames and passwords, in just 10 minutes.”

NTT Security’s new service is aimed at increasing security awareness at the executive and senior management level, but also in helping to establish a strong security culture across the entire organisation. “Our initial projects have shown that there is a need for action on the part of the company involved,” adds Kai Grunwitz. “It seems the degree of maturity in terms of cybersecurity at the senior management level is still relatively low.”

Once a simulation attack is completed, NTT Security analyses the results together with the client in workshops. NTT Security can then work with the company to help design and implement a comprehensive company-wide security strategy, which incorporates the management level, and will protect against real-life social engineering attacks in the future.

Global Banking & Finance Review

 

Why waste money on news and opinions when you can access them for free?

Take advantage of our newsletter subscription and stay informed on the go!


By submitting this form, you are consenting to receive marketing emails from: Global Banking & Finance Review │ Banking │ Finance │ Technology. You can revoke your consent to receive emails at any time by using the SafeUnsubscribe® link, found at the bottom of every email. Emails are serviced by Constant Contact

Recent Post