惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Recent Announcements
Recent Announcements
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Last Week in AI
Last Week in AI
Scott Helme
Scott Helme
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
L
LINUX DO - 最新话题
S
Security @ Cisco Blogs
Webroot Blog
Webroot Blog
S
Security Affairs
H
Hacker News: Front Page
TaoSecurity Blog
TaoSecurity Blog
W
WeLiveSecurity
G
GRAHAM CLULEY
T
Tenable Blog
Schneier on Security
Schneier on Security
S
Securelist
Cyberwarzone
Cyberwarzone
P
Privacy International News Feed
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
S
Schneier on Security
Hacker News - Newest:
Hacker News - Newest: "LLM"
Recent Commits to openclaw:main
Recent Commits to openclaw:main
O
OpenAI News
N
News and Events Feed by Topic
AWS News Blog
AWS News Blog
C
Cisco Blogs
T
Threat Research - Cisco Blogs
S
Secure Thoughts
大猫的无限游戏
大猫的无限游戏
C
Check Point Blog
The GitHub Blog
The GitHub Blog
G
Google Developers Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
美团技术团队
Martin Fowler
Martin Fowler
Microsoft Security Blog
Microsoft Security Blog
L
LangChain Blog
Apple Machine Learning Research
Apple Machine Learning Research
爱范儿
爱范儿
D
DataBreaches.Net
博客园_首页
MyScale Blog
MyScale Blog
博客园 - 叶小钗
博客园 - 三生石上(FineUI控件)
P
Proofpoint News Feed
J
Java Code Geeks
SecWiki News
SecWiki News
P
Palo Alto Networks Blog
Know Your Adversary
Know Your Adversary
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org

Human Risk Management Blog

The Open-Source Paradox: Navigating the New Frontier of AI Supply Chain Risk Introducing The Hybrid Nudge Experience: Outbound Email Security Built for Your Risk Appetite Elevating the SOC Experience: Smarter Automation, Richer Threat Intelligence, and AI-Native Investigation New Phishing Tools Enable Attackers to Easily Bypass Multifactor Authentication From Inbox to Encryption: How Ransomware Delivery Has Evolved Attackers Exploit AI Hallucinations to Send Users to Phishing Sites Warning: ARToken Phishing Kit Automates BEC Attacks The New Face of AI Risk Trust Nothing: Tips to Secure AI Tools and Agents CyberheistNews Vol 16 #29 ClickFix Social Engineering is Now the Leading Malware Delivery Method Beyond the Checkbox: How a Proactive Partnership Led to Turnkey Hazing Compliance Trust, Verify, Protect: Modernizing Email Security for the Cloud Report: Social Engineering Remains a Central Part of AI-assisted Attacks ClickFix Social Engineering is Now the Leading Malware Delivery Method CyberheistNews Vol 16 #28 Your 2026 Phishing by Industry Benchmarks: The Findings on Human Risk Scammers Can Use AI Tools to Pinpoint Your Location Based on a Photo Report: Attackers Are Using AI to Automate Social Engineering Your KnowBe4 Fresh Compliance Plus Content Updates from June 2026 From Awareness to Digital Workforce Security Your KnowBe4 Fresh Content Updates from June 2026 Threat Actor Uses Phishing to Breach Orgs for Ransomware Gangs Invoice Phishing Attacks Are Abusing the Shop App Phishing Campaign Impersonates Interpol to Deliver Ransomware Prompt Injection and the Rise of Agentic Risk Hyper-Targeted Social Engineering Needs Real-Time Video Response Your Email is Protected. Is Your Teams Chat? CyberheistNews Vol 16 #27 [HOW TO] Your Cybersecurity Starts at Home on World Social Media Day 2026 Phishing by Industry Benchmarking Report: Findings on Human Risk Static DLP Is Leaving You in the Dark: Why It’s Time for Intelligent, Self-Serve Outbound DLP and Misdirected Content Analysis INC Ransomware Gang Targets the Legal Sector Cybercriminals Are Targeting the FIFA World Cup 2026 Why Bite-Sized Security Awareness Training Matters in an Age of TikTok and Digital Distraction Happy 3rd Birthday to Our KnowBe4 Community! Phishing Exposes Employee Data at 86% of Fortune 100 Companies Shadow AI Is Not Shadow IT With a Better Marketing Budget CyberheistNews Vol 16 #26 A New Extortion Scam Uses IT Impersonation to Breach Organizations Cybersecurity Starts At Home This World Social Media Day FTC Report: Americans Lost $3.5 Billion to Imposter Scams Last Year Report: Device Code Phishing is Surging Report: Online Shoppers Increasingly Ignore Scam Warning Signs Security Training Needs Google Maps, Not Christopher Columbus Turn Account Takeover Into Real-Time Security Coaching Extortion Gang Sends In-Person Attackers to Exfiltrate Data Attackers aren’t loyal to any collaboration channel CyberheistNews Vol 16 #25 [The AI Tell] How To Expose Machine-Written Phishing Fast Social Engineering Attacks Abuse Workplace Collaboration Tools New Extortion Brand Uses IT Impersonation to Breach Organizations APWG Report: Social Media Phishing is Surging Cybersecurity Awareness Training for AI: Key Focus Areas Americans Lost $900 Million to AI-Powered Scams Last Year What AI Can’t Hide When It Writes a Phishing Email Your AI Agents Are Eager to Please And Easy to Exploit From 1% to 26%: How AIDA Orchestration Fixes the Remedial Training Gap Best AI Agent Security Tools for SMB and Enterprise in 2026 4 Hot Summer Travel Tips To Avoid Scams CyberheistNews Vol 16 #24 [FBI Alert] Lock Down Your Microsoft 365 Device Code Flows Now The Role of Agentic AI in Phishing Security Training A Credit Score for Cyber Behavior Agentic AI Security in 2026: What to Know How to Secure AI Agents: 4 Best Practices An Overview of Email Compliance Regulations and Reporting Report: AI-Assisted Fraud is Surging Attackers Use Spoofed ChatGPT Site to Deliver Malware I Love Device-Bound Session Credentials, But They Are Still Phishable and Hackable Nearly Two-Thirds of CEOs Cite Cyberattacks as Their Top Concern A Look at Spam vs. Phishing: 4 Key Differences KnowBe4 Wins Multiple 2026 TrustRadius Top Rated Awards Cyber Insurance for Mid‑Market Organizations in Southeast Asia KnowBe4 Earns Multiple 2026 Buyer's Choice Awards from TrustRadius The New Frontier: Securing Japan’s Hybrid Digital Workforce (2026 & Beyond) CyberheistNews Vol 16 #23 Now Phishing Attacks Use Real Hotel Reservations to Target Travelers Report: AI-Enabled Social Engineering Attacks Are on the Rise Your KnowBe4 Fresh Compliance Plus Content Updates from May 2026 FBI: Kali365 Phishing Kit is Targeting Microsoft 365 Accounts KB4-CON - AI Is Everything How to Secure AI Adoption In Your Organization Your KnowBe4 Fresh Content Updates from May 2026 The Silent Invitation: A Deep Dive into Calendar Invite Phishing Cyber Insurance for Mid‑Market Organizations in Southeast Asia Chinese-Language Phishing Kits Are Growing More Advanced Phishing Attacks Are Using Real Hotel Reservation Info to Target Travelers Warning: Scammers are Exploiting Geopolitical Unrest Athletes Are Increasingly Targeted by Social Engineering Attacks AI Agent Governance Part 3 - Runtime Governance: The Hidden Performance Cost of Agentic AI AI Agent Governance Part 2 - What Good Looks Like: Governing AI Agents in Practice 8 Ways to Reduce False Positives in Email Security Ransomware Attacks Drive a Surge in Cyber Insurance Claims My Favorite 5 KnowBe4 Agents Perry Carpenter KB4-CON 2026 Q&A: Deepfakes & Deception Free Gift Fallacy: How Attackers Harvest Credit Cards via Fake Surveys When Global Conflict Becomes a Cyber Weapon: How Iran Tensions and Other Stressful Events Fuel Social Engineering Attacks CyberheistNews Vol 16 #21 [Heads Up] GitHub Breach Shows Developer Tools Are Social Engineering Targets Alert: Extortion Groups Are Using Phishing Kits to Automate Their Attacks Beyond the Chatbot: Why Your AI Agents are Your Newest (and Most Vulnerable) Colleagues Report: Adversarial Use of AI is Evolving
5 Essential Cybersecurity Defenses for Cloud Email Security
Erich Kron · 2026-07-03 · via Human Risk Management Blog

Erich Kron, CISO Advisor at KnowBe4Cloud email has become the center of modern business. Regardless of your organization's industry or size, email connects employees, customers, vendors, executives, financial systems and critical business processes.

Unfortunately, attackers know this too.

For cybercriminals, compromising an email account is often like finding the master key to a building. Once inside, they may be able to steal information, impersonate employees, redirect payments, spread malware or gain access to other systems. There is an inherent trust we have with internal emails that the bad actors cannot touch using external emails, and, let’s face it, most organizations filter and check emails generated outside of the organization far more than some from within.

The good news is that protecting cloud email does not require a magic product or some mythical security solution that solves every problem. Like most areas of cybersecurity, success comes from building multiple layers of defense that work together.

Here are five critical cybersecurity defenses organizations should implement as part of their security program that protects their cloud email environments.

1. Use Phishing-Resistant Multi-Factor Authentication

If passwords were enough, we would not have so many account compromises. Sadly, it's not 1995 anymore, and we cannot simply rely on a single method of authentication.

Multi-factor authentication (MFA) remains one of the most effective security controls available, but it is not a silver bullet. Attackers have become increasingly skilled at bypassing traditional MFA methods. Push notification fatigue attacks, stolen one-time passcodes and adversary-in-the-middle phishing kits have made basic MFA less effective than it once was.

That does not mean MFA is no longer valuable. It means organizations should aim for stronger forms of authentication whenever possible.

Phishing-resistant MFA solutions such as FIDO2 security keys, passkeys, smart cards and certificate-based authentication make it significantly harder for attackers to steal credentials and reuse them. These methods are designed to verify not only the user but also the legitimacy of the website or application requesting authentication. No, it is still not a 100% foolproof cure for credential theft, and it should never replace the need for unique and complex passwords, but it is an effective speed bump in the middle of the freeway of cybercrime.

Organizations should require MFA for all users and prioritize phishing-resistant methods for administrators, executives, finance personnel, HR staff and anyone with access to sensitive information.

Just as important, disable legacy authentication protocols that can bypass MFA protections altogether. Old authentication methods often sit quietly in the background until an attacker discovers them. Think of them as a side door that nobody remembers exists until someone uses it to break in. Remember, your most insecure authentication method makes the other, better choices obsolete.

2. Implement SPF, DKIM, and DMARC

One of the oldest tricks in a cybercriminal's playbook is pretending to be someone else.

Attackers frequently impersonate executives, vendors, business partners and trusted brands because people are naturally more likely to trust familiar names.

This is where SPF, DKIM and DMARC become critical.

While the acronyms may sound like something a cat walked across a keyboard to create, they serve an important purpose and can be fairly easy to set up. No, it does not keep attackers from typo squatting domains that look similar to yours, but it will stop it from looking like the email came from your legitimate domain name.

SPF identifies which servers are authorized to send email on behalf of your domain. DKIM uses cryptographic signatures to verify that messages have not been altered. DMARC brings these technologies together and tells receiving mail systems how to handle messages that fail authentication checks.

In simple terms, these controls help prevent attackers from sending messages that appear to come directly from your organization.

Many organizations begin with monitoring and gradually move toward stronger DMARC enforcement policies. That approach allows security teams to identify legitimate systems that send email before enforcing stricter controls.

While email authentication will not stop every attack, it significantly raises the bar and reduces one of the easiest methods criminals use to impersonate organizations.

3. Focus on Preventing Account Takeover

Once attackers gain access to a legitimate mailbox, things can get complicated very quickly.

A compromised email account provides attackers with something they value immensely: trust.

Instead of pretending to be an employee, they become the employee.

From there, attackers may monitor conversations, redirect invoices, steal sensitive information, reset passwords, launch phishing attacks against coworkers or create forwarding rules that quietly send copies of emails to external accounts.

The most effective defense is assuming that stolen credentials will eventually happen and building controls that detect suspicious activity quickly.

Organizations should take advantage of capabilities such as:

  • Conditional access policies
  • Impossible travel detection
  • Suspicious login alerts
  • Monitoring for inbox forwarding rules
  • Detection of new MFA registrations
  • Restrictions on external forwarding
  • Risk-based authentication policies

It is also important to monitor third-party application permissions. Attackers increasingly use malicious OAuth applications to gain access to mailboxes without needing to continually steal passwords. In some cases, users willingly grant access because the request appears legitimate.

The goal is not perfection. The goal is rapid detection, limited attacker access, and reduced opportunities for persistence.

4. Deploy Advanced Email Threat Protection

Modern phishing attacks are not always obvious.

Gone are the days when every malicious email contained broken grammar, strange formatting and a foreign prince offering millions of dollars in exchange for assistance.

Today's phishing attacks can be convincing, well-written and highly targeted. Some use QR codes. Others leverage compromised accounts. Many contain no malware at all.

Business email compromise (BEC)attacks often rely entirely on trust and persuasion.

That is why advanced email protection should evaluate much more than simple signatures or known malicious attachments.

Effective solutions analyze factors such as:

  • Sender reputation
  • Domain age
  • Authentication results
  • Message content
  • Link behavior
  • Attachment behavior
  • Communication patterns
  • Impersonation indicators

Capabilities such as URL rewriting, attachment sandboxing, QR-code detection, impersonation protection and automated message removal can significantly reduce organizational risk.

One mistake many organizations make is focusing exclusively on inbound email. Internal email deserves attention too as well as internal email being sent externally.

Once attackers compromise an account, they frequently use it to target coworkers. Messages originating from trusted internal accounts often appear far more convincing than messages from unknown external senders.

Attackers may leverage internal email accounts to exfiltrate data as well, so looking for abnormal patterns of outbound email, or email containing potentially sensitive information, is also critical. It can also make a big difference in accidental data exposure from employees. We have all misaddressed an email at some point, and if the wrong data is enclosed, that can also be a significant problem.

5. Train People and Strengthen Business Processes

Technology plays a critical role in security, but people remain one of the most important layers of defense.

That does not mean blaming users.

The idea that employees are the problem has never been particularly helpful. Attackers are professionals at what they do. They spend their time studying human behavior, business processes and organizational relationships. They know how to create urgency, exploit trust and pressure people into making quick decisions.

Security awareness training should focus on helping employees recognize realistic threats, including:

  • Credential phishing
  • Business email compromise
  • Vendor impersonation
  • Payroll diversion scams
  • QR-code phishing
  • MFA fatigue attacks
  • Suspicious file-sharing requests
  • Malicious application consent requests

Training alone, however, is not enough. Just providing information is not enough; make sure you are working on changing employee behaviors.

Organizations should also build secure business processes that reduce the impact of a successful phishing attack.

For example, changes to payment information, such as wire transfers or invoice payments, should always be verified through a trusted secondary communication channel. Requests for wire transfers, gift card purchases or sensitive employee information should follow established approval procedures.

One of the most effective security controls is often surprisingly simple: slow down and verify.

Cybercriminals thrive on urgency. Good security processes remove that advantage.

Organizations should also make reporting suspicious messages easy. Employees who report potential threats are actively contributing to the organization's defense and should be encouraged to continue doing so.

Bonus Defense: Prepare for Recovery

Many organizations assume their cloud provider automatically protects everything forever.

That assumption can become very uncomfortable after an incident.

Understanding retention policies, recovery options, legal hold requirements and backup capabilities is essential. If email data is deleted, encrypted, altered or otherwise compromised, organizations need a reliable way to recover critical information.

Backups are not particularly exciting, but neither are fire extinguishers. You still want both available when things start getting interesting.

Final Thoughts

Cloud email remains one of the most attractive targets for cybercriminals because it provides access to information, identities, business processes and trust.

Protecting it requires a layered approach.

Phishing-resistant MFA helps make stolen passwords less valuable. Email authentication technologies make spoofing more difficult. Account takeover protections help identify compromised users. Advanced email security reduces exposure to malicious messages. Security awareness training and strong business processes help employees make safer decisions.

No single control will stop every attack.

That is why effective security has always been about layers.

Attackers look for the easiest target available. The more obstacles an organization places in their path, the more likely they are to move on and look elsewhere, and that is a win worth pursuing.