Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Don’t be the weakest link: protecting your supply chain from targeted malware attacks

by The Gurus
September 7, 2016
in This Week's Gurus
Share on FacebookShare on Twitter

Every senior manager knows that falling prey to a malware attack could yield catastrophic results. But what if that malware spread beyond your own systems, taking your partners, customers and supply chain down with you?
Cybercriminals have been busy over the past year, carrying out an alarming number of malware attacks varying the payload from types that enable access to confidential client or personnel data to a recent wave of ransomware attacks. Yet despite a growing awareness, these attacks continue to be successful. With file-based attacks accounting for 94 per cent of successful data breaches, a growing number of organisations have admitted that they are helpless to prevent future attacks. The answer, so far, has been to focus instead on detecting and responding to malware after it has already made its way onto the organisation’s system. At the same time, an equally important concern is beginning to gain the attention of those managing the security of their organisation’s reputation.
Security surrounding outbound emails is becoming a higher priority for IT professionals, as the fear of infecting a business partner, supplier or customer via corrupted attachments is becoming a reality, especially in organisations like law firms, who employ Lawyers and Partners that send and receive hundreds of emails and file attachments to and from their clients each day. Needless to say, any organisation implicated in the unwitting spread of harmful malware could face irreparable damage to its reputation, inevitably losing the trust of important clients and partners and feeling the consequential damage to profits.
The amount of goodwill that can be lost shouldn’t come as a shock, considering the potential cost of suffering a data breach:
High-profile incidences in recent years have led to a shake up of Regulation which will introduce steeper fines and even publicly name companies who suffer data breaches.  Growing concern from increasingly cyber aware consumers have all created a heightened sense of caution for companies in all sectors. As a result, any organisation suspected to be unknowingly sending malware to its partners and clients will have difficulty in maintaining any sort of relationship, or at best be in a weaker position commercially.
Finding a clear answer
In response to these concerns, many organisations are turning to digital signatures to authenticate document origins, and encryption as a means of securing their email communications. While these security methods offer some solace, by protecting the contents of a message from being intercepted and accessed by an unknown third-party, relying too heavily on encryption and digital signatures provides less than perceived protection should the endpoint generating the document become compromised at any point.
In this case, all that encryption will accomplish is securely delivering an infected file – which could potentially have even greater ramifications from the recipient if their system were to become infected. With hackers becoming increasingly adept at operating unseen, through a combination of advanced, timed embedded malicious code and highly-targeted social engineering, an increasing number of organisations are becoming unwitting accomplices in the spread of malware, regardless of how confident they are in their inbound and outbound security solutions.
With this in mind, the validation and integrity of outbound files should be a main objective for ensuring trust and security of any organisation. Any business process that requires encryption or digital signatures applied to files, must ensure they are validated, their integrity guaranteed, and then signed in order to ensure any risk of spreading malware is nullified.
In order to be seen as trustworthy by clients, organisations must be able to ensure their clients that only clean versions of original files to leave – and enter – their systems. 
The uncompromised solution 
Available to the market are innovative technologies take a brand new approach to ensuring the validity of outbound files – whether they be PDFs, Word, PowerPoint or Excel files.
Typically, these solutions makes no assumption about the integrity of outbound files. Instead of simply encrypting files before they are sent, they either create an image based replica or regenerate a brand new version of the original that is guaranteed to be free of any malicious code in real time.  Being email security platforms, these solutions need to be as near wire speed as possible, whilst breaking each file down to byte-level, so it can be fully analysed and rebuilt with only code that is known to be safe.  This is cutting edge technology, that organisations are actually finding works, allaying their general mistrust of cyber security solutions being effective.
This new and innovative approach runs contrary to legacy cybersecurity solutions, which instead look only for elements that are known to be malicious, or have a signature to block anything bad. The benefit of the “known good” approach is that it doesn’t need to rely on constant updates, which would typically need to be released each time a new macro or other exploit is discovered.
By implementing a different solution as part of a layered security approach to supplement conventional encryption and digital signatures, organisations can be assured any file they are sending to a client or partner is not just protected, but more importantly, uncompromised.

ShareTweet
Previous Post

Data ripple effect: UK customers severely underestimate the quantity of personal data stored about them

Next Post

Security Serious Week 2016 brings together cyber security industry to inform, reward and inspire

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol