Feeds

The importance of 'whole journey' email encryption

Leave no weak spots

Protecting against web application threats using SSL

It is very rare for an organisation to mandate less security in its IT systems. In fact, the relentless march of new threats places pressure on us all to increase our levels of security, to ensure we can match new and emerging attacks.

Email is one of the most potent business tools that we have, but also one of the most vulnerable systems for attack.

The volume of organisational "smarts" that can travel out of the virtual front door (or the back door from rogue inside abuse) via email can be staggering. Quotes, legal information, contracts, customer data and just about every type of document you can think of will be transported via email.

After all, traditional "snail mail" is all but dead for day to day commercial communications.

Securing email systems must be at the top of any corporate security expert's to-do list, but as with most IT problems there are many different approaches you can take.

One interesting debate is that of precisely when and where to encrypt your email traffic. Is it at the client or is it at the gateway prior to sending to the recipient? Or maybe the encryption is only from the gateway to the recipient client?

From gateway to gateway

The majority of organisations are happy with the placing of an email gateway of some description that encrypts messages as they leave the corporate perimeter. These gateways are often appliances that process emails as they leave and enter the organisation as well as providing anti-malware support.

The problem with email gateway encryption is that emails are not encrypted until they get to the gateway. In other words, the gateway does not protect internal email or email that is travelling from the internal network towards the gateway. These emails will travel around the internal organisation network unencrypted and in plain text, vulnerable to prying malware or internal monitoring and snooping devices.

Some organisations may be comfortable with this, but those needing a higher level of email security need to look a bit deeper.

Why?

Well, malicious insiders will often make a point of going after internal email traffic as this is often seen as a soft target. In a large organisation thousands of plain text emails can be moving around the organisation at any moment in time. These can be accessible to anyone motivated enough to run a sniffing device on the network, and certainly any prying email systems administrator would have unfettered access. Even if an email is worthless outside an organisation, internally it may be priceless and cause significant controversy if its contents were revealed. Examples would include emails discussing redundancies and pay rises for a start.

Most vulnerable to outside interference would be the ubiquitous mobile user with a handheld device. Tour any financial centre and see the thousands of city whizz-kids passing data around in email form, with goodness knows what data being passed in plain text. Unless emails are secured before they leave a handheld device, organisations leave a big gap in their security measures here.

By focusing solely on email gateway to gateway encryption, users risk exposing themselves to unnecessary risk of email intrusion.

Reducing the cost and complexity of web vulnerability management

More from The Register

next story
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
Early result from Scots indyref vote? NAW, Jimmy - it's a SCAM
Anyone claiming to know before tomorrow is telling porkies
TOR users become FBI's No.1 hacking target after legal power grab
Be afeared, me hearties, these scoundrels be spying our signals
Jihadi terrorists DIDN'T encrypt their comms 'cos of Snowden leaks
Intel bods' analysis concludes 'no significant change' after whistle was blown
Home Depot: 56 million bank cards pwned by malware in our tills
That's about 50 per cent bigger than the Target tills mega-hack
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
China hacked US Army transport orgs TWENTY TIMES in ONE YEAR
FBI et al knew of nine hacks - but didn't tell TRANSCOM
Microsoft to patch ASP.NET mess even if you don't
We know what's good for you, because we made the mess says Redmond
NORKS ban Wi-Fi and satellite internet at embassies
Crackdown on tardy diplomatic sysadmins providing accidental unfiltered internet access
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.