TALKING business

''

//////////////////////////

Here's why it works. Traditional security tools work by analysing emails in isolation, measuring them against static blacklists of 'known bads'. By way of analogy, the gateway tool here is acting like a security guard standing at the perimeter of an organisation's physical premises, asking every individual who enters: 'Are you malicious?'

The binary answer to this sole question is extracted by looking at some metadata around the email, including the sender's IP, their email address domain and any embedded links or attachments. They analyse this data in a vacuum, and at face value, with no consideration towards the

"

AS EMAIL THREATS GET EVER MORE SOPHISTICATED, THE 'INNOCENT UNTIL PROVEN GUILTY APPROACH' IS NOT ENOUGH.

relationship between that data, the recipient and the rest of the business. They run reputation checks, asking 'have I seen this IP or domain before?' Crucially, if the answer is no, they let them straight through.

To spell that out, if the domain is brand new, it won't have a reputation and as these traditional tools have a limited ability to identify potential harmful elements via any other means, they have no choice but to let them in by default.

These methods barely scratch the surface of a much wider range of characteristics that a malicious email might contain. And as email threats get ever more sophisticated, the 'innocent until proven guilty approach' is not enough.