Subscribe
  • Home
  • /
  • Malware
  • /
  • Sophos introduces Phish Threat Attack simulator

Sophos introduces Phish Threat Attack simulator


Johannesburg, 03 Feb 2017

Sophos has launched Sophos Phish Threat, an advanced phishing attack simulator and training solution that is fully integrated with the company's cloud-based security management platform, Sophos Central.

With centralised management and automated campaign analysis, Phish Threat dramatically reduces the time and resources required to affect real change in employee behaviour when faced with sophisticated and rapidly evolving cyber crime techniques.

Phishing remains one of the most common attack vectors for hackers who exploit end-user behaviour as the weakest link in a company's cyber-defences. Traditional online security training programmes are academic, blind to the current attack landscape and disconnected from the rest of IT security management, making it burdensome for IT managers to effectively integrate anti-phishing into routine risk assessments.

Sophos Phish Threat automates the entire training process and provides visual analytics to identify vulnerable users. The Sophos Phish Threat attack simulator and training platform is managed alongside other Sophos security solutions within Sophos Central to provide rapid risk detection and incident response.

"Phishing has evolved in lockstep with the 'Malware-as-a-Service' phenomenon," says Brett Myroff, MD of Sophos distributor, Netxactics. "For years, criminals have disguised attacks in e-mail and, today, SophosLabs sees phishing e-mails as a primary delivery method for ransomware payloads. Preventing users from succumbing to phishing attacks can seem like an uphill battle. However, with Sophos Phish Threat, IT managers now have sophisticated, integrated threat intelligence that combines the strength of Sophos security technologies with a product that tests, trains and analyses human vulnerabilities. This creates a very powerful solution for businesses struggling to keep ahead of organised cyber crime and unwary end-users."

Sophos acquired the Phish Threat technology in late 2016 from penetration test and risk assessment consultancy Silent Break Security and has since integrated the product into the Sophos Central platform. "I noticed a discrepancy between the way cyber-attacks were being conducted in the wild and what the private sector was calling a 'penetration test,'" says Brady Bloxham, founder and former CEO of Silent Break Security. "We built Phish Threat to replicate the mindset of a real attacker, using the complicated methods and techniques in use today. This means assessments are modelled after potential attacks that organisations may face from real hackers. We also wanted to make it more transparent and easier for IT to collate and analyse results - something we hadn't found in other tools." Bloxham and the core engineers who initially developed the technology have joined the Sophos Cloud Security Group.

Sophos Phish Threat enables IT managers to create authentic phishing simulation and training sessions, and initiates course corrections for their employees. This helps end-users better recognise what a phishing attack looks like and learn from their mistakes should they get lured into taking the bait. As attacks change with current events, changing seasons and attacker methodologies, Sophos Phish Threat constantly updates its testing framework to reflect real-world threats. IT managers can craft bespoke simulation campaigns for office locations worldwide, just as many cyber criminals are now designing threats tailored by geography.

Several Sophos products are already available through the Sophos Central management platform including the next-generation XG Firewall, Sophos Endpoint Security, Sophos Intercept X, Sophos E-mail Security, Sophos Server Protection and Sophos SafeGuard Encryption. Sophos Phish Threat is the latest addition to the Sophos Central management platform.

Share

NetXactics

Established in 1998, NetXactics is a South-African company that specialises in sales, marketing and distribution of IT and related products. Its approach is unique, focusing on long-term growth coupled with exceptional customer stability. NetXactics has attained a level 5 Generic BEE rating.

Editorial contacts

Adriaan du Plessis
Me Talk Pretty
(011) 782 1345
adpl@telkomsa.net