Go back

Securing Mailboxes in the Era of Persistent Threats: Insights from Recent Chinese State-Linked Hacks

Stating the obvious: Recent events reinforce the fact that the mailboxes inside of organizations continue to be a target and that even strong authentication controls are insufficient to prevent unauthorized access.

Industry Insights
July 18, 2023
4m read
4m read
4m listen
4m watch
4m watch
circles in a red background
speakers
speakers
speakers
authors
Chris Long
participants
No items found.
share

Stating the obvious: Recent events reinforce the fact that the mailboxes inside of organizations continue to be a target and that even strong authentication controls are insufficient to prevent unauthorized access.

It's time for organizations to adopt a strategy that goes beyond securing against mailbox compromise. Organizations should adopt an "assume breach" mentality and must include protections to mitigate the impact of a successful compromise.

Email was, is, and will continue to be one of the primary attack vectors and targets.

Email is the most widely used collaboration tool in the world. The wealth of information inside email accounts requires that we stop thinking of them as simple messaging applications and shift to recognizing them as the rich data repositories they have become. Traditional approaches, such as email gateways and phishing protection, do not offer protection for data at rest in a mailbox.

The shift from on-prem to cloud infrastructure has improved overall mail infrastructure security, however, it still hasn't addressed the need to protect the data inside mailboxes. As in other areas of digital transformation, the adoption of cloud-based email services like Microsoft 365 and Google Workspace presents an opportunity to rethink and apply proven security models.

Learning from the past

When trying to find solutions to problems, it is often helpful to consider how similarly complex challenges have been addressed in the past. The theft or loss of a company issued device was previously considered a perilous event. Because data was frequently stored unencrypted on hard drives, it was easily accessed and copied by any individual with possession of the device. Today, device theft and loss still occur but the data on the device remains protected because full disk encryption has become ubiquitous. Except in rare and extreme circumstances, the loss of devices now presents a negligible risk to organizations. The cost and effort required to defeat full disk encryption makes physical asset theft a path of considerable resistance and adversaries often search for alternative access to the information or goals they seek. As an industry, once we accepted that theft or loss of devices would continue to happen, we were able to find innovative ways to ensure that the risk from such an occurrence would be greatly reduced.

Securing the modern, cloud email environment

Unauthorized access to mailboxes, as opposed to physical devices, is a targeted and concerted effort for adversaries. At Material our mission is to make it prohibitively difficult for attackers to access sensitive email data post-compromise. We should operate with the assumption that mailbox compromise is no different than the loss of a physical device and shift to a strategy of protecting emails at rest. The powerful APIs exposed by email providers enables new and innovative mailbox protections. Material Security leverages these APIs to apply defense-in-depth for mailboxes by determining which messages contain sensitive content and requiring an additional, low-friction challenge to access them. Even with full control of an organization's mail infrastructure, such as in the high-profile example recently revealed by the US Commerce Department, adversaries would still be unable to access the content of sensitive emails protected by Material Security.

Protecting data at rest on physical devices is a requirement of modern information security programs. Now that the technology exists, protecting emails at rest in cloud environments must follow.

Frequently Asked Questions

Find answers to common questions and get the details you need.

No items found.

Related posts

Our blog is your destination for expert insights, practical tips, and the latest news in technology. Stay informed with our regular updates and in-depth articles. Join the conversation and enhance your understanding of the tech landscape.

blog post

The Composio Breach: One token, 10,242 doors

One compromised Gmail token gave attackers a skeleton key to 10,000+ customer credentials — and it's the same OAuth playbook security teams keep underestimating.

Rajan Kapoor, VP, Security
7
m read
Read post
Podcast

The Composio Breach: One token, 10,242 doors

One compromised Gmail token gave attackers a skeleton key to 10,000+ customer credentials — and it's the same OAuth playbook security teams keep underestimating.

7
m listen
Listen to episode
Video

The Composio Breach: One token, 10,242 doors

One compromised Gmail token gave attackers a skeleton key to 10,000+ customer credentials — and it's the same OAuth playbook security teams keep underestimating.

7
m watch
Watch video
Downloads

The Composio Breach: One token, 10,242 doors

One compromised Gmail token gave attackers a skeleton key to 10,000+ customer credentials — and it's the same OAuth playbook security teams keep underestimating.

7
m listen
Watch video
Webinar

The Composio Breach: One token, 10,242 doors

One compromised Gmail token gave attackers a skeleton key to 10,000+ customer credentials — and it's the same OAuth playbook security teams keep underestimating.

7
m listen
Listen episode
blog post

The Open Engine: Smarter Detection Explanations and API v1

Material's May updates make the detection engine more legible for every analyst, and give technical teams the programmatic access to put that intelligence to work outside the UI.

James Juran
5
m read
Read post
Podcast

The Open Engine: Smarter Detection Explanations and API v1

Material's May updates make the detection engine more legible for every analyst, and give technical teams the programmatic access to put that intelligence to work outside the UI.

5
m listen
Listen to episode
Video

The Open Engine: Smarter Detection Explanations and API v1

Material's May updates make the detection engine more legible for every analyst, and give technical teams the programmatic access to put that intelligence to work outside the UI.

5
m watch
Watch video
Downloads

The Open Engine: Smarter Detection Explanations and API v1

Material's May updates make the detection engine more legible for every analyst, and give technical teams the programmatic access to put that intelligence to work outside the UI.

5
m listen
Watch video
Webinar

The Open Engine: Smarter Detection Explanations and API v1

Material's May updates make the detection engine more legible for every analyst, and give technical teams the programmatic access to put that intelligence to work outside the UI.

5
m listen
Listen episode
blog post

Three Ways to Address the Expected HIPAA Encryption Requirements for Email

The fourth in a series on healthcare email security using HIPAA breach data and regulatory analysis.

Material Team
10
m read
Read post
Podcast

Three Ways to Address the Expected HIPAA Encryption Requirements for Email

The fourth in a series on healthcare email security using HIPAA breach data and regulatory analysis.

10
m listen
Listen to episode
Video

Three Ways to Address the Expected HIPAA Encryption Requirements for Email

The fourth in a series on healthcare email security using HIPAA breach data and regulatory analysis.

10
m watch
Watch video
Downloads

Three Ways to Address the Expected HIPAA Encryption Requirements for Email

The fourth in a series on healthcare email security using HIPAA breach data and regulatory analysis.

10
m listen
Watch video
Webinar

Three Ways to Address the Expected HIPAA Encryption Requirements for Email

The fourth in a series on healthcare email security using HIPAA breach data and regulatory analysis.

10
m listen
Listen episode
blog post

What It Really Takes to Unlock AI Adoption: Lessons from the Field

Security leaders from Material Security, Gopuff, and Cotool share hard-won lessons on AI adoption, data privacy, and building trust at scale.

Gian Gonzaga
4
m read
Read post
Podcast

What It Really Takes to Unlock AI Adoption: Lessons from the Field

Security leaders from Material Security, Gopuff, and Cotool share hard-won lessons on AI adoption, data privacy, and building trust at scale.

4
m listen
Listen to episode
Video

What It Really Takes to Unlock AI Adoption: Lessons from the Field

Security leaders from Material Security, Gopuff, and Cotool share hard-won lessons on AI adoption, data privacy, and building trust at scale.

4
m watch
Watch video
Downloads

What It Really Takes to Unlock AI Adoption: Lessons from the Field

Security leaders from Material Security, Gopuff, and Cotool share hard-won lessons on AI adoption, data privacy, and building trust at scale.

4
m listen
Watch video
Webinar

What It Really Takes to Unlock AI Adoption: Lessons from the Field

Security leaders from Material Security, Gopuff, and Cotool share hard-won lessons on AI adoption, data privacy, and building trust at scale.

4
m listen
Listen episode
Privacy Preference Center

By clicking “Accept”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. View our Privacy Policy for more information.

New