Skip to content

BEC Attacks Double in 2023, Costing Organizations $125K Each

BEC attacks are on the rise, with hybrid work exacerbating the issue. Strong security awareness and network defenses are crucial to protect organizations from these devastating scams.

In this picture we can see a close view of the identity card. In the front we can see american flag...
In this picture we can see a close view of the identity card. In the front we can see american flag and "Critical Licence" written.

BEC Attacks Double in 2023, Costing Organizations $125K Each

Business Email Compromise (BEC) attacks pose a growing threat to organizations, with a significant increase in 2023. According to security firm Proofpoint, these attacks have doubled, reaching an average of 10.77 per 1,000 mailboxes. The shift to hybrid and remote work has exacerbated this issue, making security awareness and robust network defenses crucial.

BEC attacks can be devastating, with the FBI reporting average costs exceeding $125,000 per successful incident. To mitigate this risk, organizations must adopt a multi-faceted approach. This includes continuous monitoring and risk-based access decisions to detect and contain threats within the network.

Modern security awareness programs play a vital role. They should simulate real-world scenarios and teach employees to identify email red flags and social engineering tactics. This empowers employees to recognize and combat phishing attacks, including BEC scams.

Key to this approach is the principle of least privilege access. This limits potential damage by granting users only the necessary access to perform their jobs. Additionally, multi-factor authentication (MFA) is a cornerstone of the zero-trust security model. It provides additional verification for access to resources, minimizing the impact of BEC scams by continuously authenticating users and devices.

In conclusion, the rise in BEC attacks underscores the need for robust security measures. A combination of zero trust principles, employee training, network segmentation, and least privilege access is essential. By investing in these areas, organizations can better protect themselves from the significant financial and reputational risks posed by BEC attacks.

Read also:

Latest