Home > Ask the Security Channel Experts > Information Security Threats and Countermeasures Questions & Answers > How to secure PCs against phishing attacks
Ask The Security Channel Expert: Questions & Answers
EMAIL THIS

How to secure PCs against phishing attacks

Retired Expert - Russell Dean Vines EXPERT RESPONSE FROM: Retired Expert - Russell Dean Vines

Pose a Question
Other Security Channel Categories
Meet all Security Channel Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 27 September 2006
How do I secure my customer's PCs against phishing attacks?

>

A comprehensive answer to your question would require much more space than we have here, but there are a few general steps you should take to start. As Rachael Lininger and I detail in our book Phishing: Cutting the Identity Theft Line, the basic areas you need to consider are:

  • Customer education -- Your customers need to know how to recognize phishing emails, and how to prevent rootkits and keyloggers. They need to know that you will never email requests for account or other private information, like social security numbers. In addition to our book, there are many other sources for useful info on how to harden your customer's PC, including tips and steps right here at SearchSecurityChannel. These could include employing spoofstick-type plug-ins, using a different browser if possible (Firefox rather than IE), disabling active scripting and prompting for cookies.

  • Organizational education -- Your organization needs to review how it interacts and communicates with its customers; particularly, how it handles email communications and presents itself on the Web. This helps your customers differentiate between appropriate and inappropriate company communications. In email communications this means not including hyperlinks or attachments, not including or asking for personal information, and never using the full name of the user.

    Like any rule, of course these will be broken for corporate necessity, but awareness about phishing, its threat and solutions, needs to be continually instilled in your customer's consciousness.

    For more information read Chapter 6, Helping your organization avoid phishing, from Russell's book, Phishing: Cutting the Identity Theft Line.


  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Information Security Threats and Countermeasures
    Security for mobile broadband
    Understanding smurf attacks
    What are the network security risks of streaming video?
    Spyware removal from computers
    Malware removal without antivirus software
    Threat matrix and risk analysis resources
    Blade server security on a storage area network (SAN)
    Blade server security hardware advice
    Cross-site scripting vulnerability penetration testing
    When should automated penetration testing be supplemented with manual pen testing?

    Spam, antispam and phishing
    SonicWall to offer cloud-based antispam service
    Book Chapter: Web hacking
    What is the future of antivirus or antimalware software?
    Common injection attacks
    Checklist: Top five security assessment tools
    Penetration testing tutorial for service providers
    Nmap Tutorial: An introduction for VARs and security consultants
    Open source spam management for Outlook: SpamBayes
    Combating Dynamic Code Obfuscation
    Email security appliances that fight phishers and spambots

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    HomeNewsTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogsEvents
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2006 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts