Laserfiche WebLink
6.D. - Page 18 of 33 <br />Message rules can be very powerful to alert users of potential threats or to be careful about what <br />they might click on and endanger their system. Some of the vendors listed in Appendix B also <br />can "report" a suspected phishing attempt to an IT administrator. The Grand Jury's review <br />revealed that some of the Information Technology Services departments for local public entities <br />have installed message rules on their email servers to notify users of external emails.44 This is a <br />"best practice" which all local governmental agencies should consider. <br />Phishing emails are easy to create, as they do not take a high level of skill to provide the illusion <br />of legitimacy by mimicking web -site brands or using logos from Google images. They can also <br />easily spoof (fake) an email address to look like a trusted source.45 It can often be very difficult <br />to catch these risky emails, as the spoofed emails are cleverly disguised. A YouTube video <br />created by Cisco Systems illustrates the sophisticated approach a phishing email may take — <br />"Anatomy of an Attack7.46 It shows an attacker constructing a realistic identity deception email <br />and can be viewed at litlps: After you watch this <br />video please note, had an email filter caught this message and flagged it as external and warned <br />about clicking on links, the deception may have been caught. <br />What Does Excellent Cyber Defense Look Like? <br />Survey Question47: "What defenses do you currently employ to block malware? Please be <br />specific. (Firewall brand/model, Software filters/spam blocker, etc.) " <br />Five survey responders did not divulge the infrastructure of their environment. 17 responders <br />provided abbreviated details indicating they do have Cybersecurity protections in place. The <br />remaining 15 responses were explicit about their organizations' hardware and software defense <br />strategies. Below is a survey response that illustrates a well -protected environment using some <br />of the best practices of Cybersecurity: <br />"At the first layer, we use a PAN 220 Firewall with all subscriptions enabled, (URL Filtering, <br />AntivirusNulnerability, Wildfire, etc.), block all international countries both in and outbound. <br />Once traffic is passed for email, it passes through a Barracuda spam filter, filtering and scanning <br />phishing and virus emails, checks with External Reputation servers for known virus and <br />spamming servers, then passes to an on -premise exchange server. The exchange servers have <br />another layer installed, Symantec Antivirus, giving a third layer of scanning. All servers and <br />workstations have the latest version of the antivirus installed controlled by a centralized server. <br />Window patches are applied on a monthly basis to all servers and workstations, and servers are <br />retired once Microsoft ends support for an operating system." 48 <br />The survey respondent's best practices: <br />• Filtering incoming email for viruses, malware, and phishing attempts; <br />• Utilizing protection software from multiple vendors; <br />Utilizing multiple layers of defense; <br />44 Grand Jury interviews <br />45 Ibid <br />46 Cisco Systems, Ransomware - Anatomy of an Attack, litlps://www.voutLibe.com/watcli?v--4_iZR562GW7TI <br />47 Appendix A - Question #6 <br />48 Grand Jury Survey response <br />2019-2020 San Mateo County Civil Grand Jury 10 <br />139 <br />