Can the Microsoft 365 Platform Be Trusted to Stop Security Breaches?

20/08/2021 13:45 By Bill
Blog courtesy of KnowBe4
Written by Stu Sjouwerman
Lax security policies, a lack of security measures and solutions in place, and an expectation that Microsoft will address any security issues is putting organisations at risk.

Microsoft has gone to great lengths to ensure their Microsoft 365 platform offers modern security measures to keep their customers' data safe. But according to new data from cloud email security provider Hornet Security, 25% of organisations have reported a known email-based security breach, and it begs the question “why?”
According to Hornet Security, a lot of the issue resides with organisations not taking advantage of security features – whether from Microsoft or a third-party:
    • 33% of organisations are not using Microsoft’s multi-factor authentication (MFA)
    • Of those using MFA, 55% of organisations are not using Conditional Access which scrutinizes connection requests beyond just providing credentials and additional authentication factors
    • Only 43% leverage Microsoft’s data loss prevention policies to keep data from leaving the organisation
    • 68% of organisations expect Microsoft to keep email safe from threats

What’s interesting is that almost none of these features (with the exception of MFA) address the core issue – phishing and compromised credentials. For every organisation that has experienced a security breach, there’s a phishing email riddled with social engineering tactics and, more importantly, a recipient user who engages and activates attacker’s malicious content.

It’s imperative that organisations recognise the need to follow the attack kill chain and see one of the weakest links is the user who unwittingly enables threat actors by falling for phishing scams. Users that undergo continual Security Awareness Training are better equipped on a daily basis to see phishing attacks for what they really are and keep the organization safe by not playing their role in an email-based attack.

Request A Demo: Security Awareness Training

New-school Security Awareness Training is critical to enabling you and your IT staff to connect with users and help them make the right security decisions all of the time. This isn't a one and done deal, continuous training and simulated phishing are both needed to mobilise users as your last line of defence. Request your one-on-one demo of KnowBe4's security awareness training and simulated phishing platform and see how easy it can be!

Bill