Email remains one of the most widely used tools for workplace communication. Because of this, it also holds the top spot on the list of security risks, according to Mimecast. Email’s expansive attack surface provides the perfect target for attackers to infiltrate systems and wreak havoc across businesses.

Implementing a robust email security program is key to keeping your data, users, suppliers, and clients safe. But in order to put these protections in place, you have to know what you’re up against. So, what are some of the biggest challenges you’re likely to face when implementing email security in your organization?

To answer this question, we turned to the CIO Experts Network, a community of IT professionals and technology industry experts. Here are the top email security challenges they say every IT leader should watch out for.

Human risk management

Experts overwhelmingly place human behavior at the core of their email security challenges. People are the lifeblood of every organization: but they can be an organization’s greatest source of risk. They take actions that can have consequences, like sharing corporate data, or clicking on links. They are constantly under attack, as adversaries target them with social engineering threats designed to trick them into making mistakes. And as a result of their critical role in our organizations, they have access to financial data, source code, and intellectual property.​

At the same time, some see employees as their greatest asset in the fight against email threats. And when it comes to risk, experts agree that people are the weakest link in the email security chain:

“Human error remains one of the biggest challenges. People are the greatest vulnerability to their own private data, often being tricked into revealing sensitive information or clicking on malicious links that launch malware. Cybercriminals understand and exploit this human weakness to their advantage.” –Scott Schober (@ScottBVS), president/CEO at Berkeley Varitronics Systems, Inc.

“Employees or temporary workers with access to our corporate email systems might misuse or accidentally expose sensitive information. Confidential client information can be inadvertently shared or leaked through email if it’s not properly managed or protected.” – Nitin Raina (LinkedIn: Nitin Raina), global chief information security officer at Thoughtworks.

On the other hand, employees can serve as your strongest safeguard — if they have the proper training.

“Security compliance and training must be integral to organizational, departmental, and employee goals,” said Peter Nichol (@PeterBNichol), Peter Nichol, Data & Analytics Leader for North America at Nestlé Health Science. “Doing so links behavior to performance and attaches consequences for non-performance; it gives employees a reason to care.”  

While technology has its place, he added, educated employees are the most important factor in the security equation. “Email security gateways, advanced threat protection, and email encryption all play a role,” said Nichol. “But an educated, committed employee standing watch over their organization is the most powerful defense.”

Hand-in-hand with human behavior, we come to the next challenge in implementing email security: company norms and expectations.

Corporate culture

Since email has been around for so long, experts say it’s employees’ first choice, even though there may be more secure communication methods available to them.

“Email is an old and very flexible tool that can be used to shortcut cleaner and better-defined automated business processes,” said Rob Hughes (LinkedIn: Robert Hughes), CISO at RSA.

He added that employee expectations can sometimes clash with business procedures, presenting a difficult balancing act.

“Employees may expect their employer to balance their own privacy, which is at odds with reviewing emails to identify hidden business processes,” he explained. “This can be an impossible challenge and must be resolved through a combination of culture shift (if needed), awareness, tooling, and business process adjustments.” 

Shifting from people to technology, the CIO Experts Network identified their next major challenge: keeping ahead of more advanced attacks.

Sophisticated email attacks

AI and evolving social engineering techniques have made it increasingly difficult for organizations to identify and protect themselves from advanced email threats, particularly as attackers shift their focus to delivering payloadless attacks.

“Implementing email security is a sticky wicket,” said Gene De Libero (@GeneDeLibero), principal at Digital Mindshare, LLC. “Companies face tough challenges like fending off sophisticated phishing and malware attacks, while integrating new security tools with existing systems. With the rise of AI-powered attacks and cloud-based email systems, the challenge is constantly evolving.”

Phishing emails, which trick users by impersonating legitimate companies, are consistently named as a top email threat because they’re so difficult to recognize, and business email compromise tactics have greatly evolved to evade traditional defenses.

“Spear phishing attacks are especially challenging because attackers carefully research their victims, often using social media posts to craft emails that appear relevant and convincing to the recipient,” said Schober. “Ironically, as I am writing this, I just received a business mail compromise (BEC) attempt to have an employee’s bank information changed for their pay. I had to read it three times before I noticed the email source was a spoof and complete fake.”

Integration with current systems and processes

With so many different platforms and systems to manage, many organizations struggle to integrate email security into both existing technology and business processes.

“Finding the right mix of gateway filtering, multi-layered security, user awareness and training, and real-time threat intelligence platforms is the daily challenge of security professionals,” said Nichol. “Equally challenging is identifying technologies that must seamlessly integrate with a company’s existing processes, policies, and security standards.”

The final challenge experts identified is the ability to secure your email while still providing a smooth user experience.

Balancing security with user experience

Will Kelly (@willkelly), a writer focused on DevOps and the cloud, believes that email security can be complex “as it requires carefully balancing robust protection and user convenience.” This complexity could affect productivity, “driving users to bypass security measures,” he added.

De Libero echoed the “delicate balance between tight security and user-friendliness” and recommended “aligning security with business goals” as the first step in striking this balance. He advised companies to “balance limited budgets against comprehensive security needs, while ensuring all departments — from IT to marketing to customer service — understand and follow email security protocols.”

He also highlighted the importance of complying with data privacy laws while maintaining smooth operations. “Meeting diverse stakeholder needs adds another layer of complexity, as security should support, not hinder, business objectives,” he concluded.

Wide-ranging challenges require a comprehensive solution

Secure email begins with a comprehensive, cloud-based solution that incorporates protection at every turn — from threat detection to user education. Look for a system that uses the power of AI to detect sophisticated intrusions like BEC, impersonation attacks, and malware threats while also fending off newer tactics like QR code attacks. When combined with continuous training and intervention, advanced email protection can help organizations shrink one of their biggest attack surfaces.

Time to clear your email security hurdles

In order to implement robust email security, organizations need to overcome complex, evolving challenges. By addressing these obstacles using a strategic, adaptive approach, IT leaders can protect their business from both current and emerging email threats.

Learn about how Mimecast can help you protect collaboration with a unified platform.

Share
Share