This week we discovered a hospital in Illinois using ExecProtect to enforce corporate communication policies within their organization. This post is about why they initially chose ExecProtect and how they used it to gain additional value.
ExecProtect, which is a concatenated version of Executive Protection, is a new feature we added to Paubox Email Suite Plus.
We built ExecProtect to combat advanced Display Name Spoofing attacks that are crippling organizations across the internet.
As a recap, Display Name Spoofing attacks appear to come from a person of authority (i.e. executive) within a company.
When this is coupled with:
The net effect is that if you see an email from your boss on your phone, you’ll probably open it immediately, not bothering to think about the actual email address it came from.
In other words, executives are being impersonated by bad actors to perpetrate fraud against their organizations.
Customers are choosing ExecProtect because it stops Display Name Spoofing attacks dead cold.
Instead of appending disclaimers like:
to the body or subject line of a Display Name Spoof attack, we designed ExecProtect to immediately quarantine the message and send an alert of the IT administrator.
This approach achieves two objectives:
In addition, we can see from this recent Reddit thread that appending disclaimers to these phishing attacks simply does not work.
The correct approach is stopping the phishing attack from ever reaching the user's inbox.
During a check-in with our customer in Illinois this week, we learned they are using ExecProtect to also enforce corporate email policy.
Here's the email policy the hospital wanted to enforce:
After enabling ExecProtect, valid email sent from executives' personal accounts like Gmail and AOL got immediately quarantined.
In other words, ExecProtect helped them achieve their organizational email policies.
In addition to Display Name Spoofing protection, our customer was able to leverage ExecProtect to achieve the secret bonus of policy enforcement for their organization's email.