Less than 1 in 10 European hospitals protected from phishing

A new survey of European-based clinics and hospitals has revealed less than one in 10 institutions have correctly implemented basic phishing protection.

The new research by email security provider EasyDMARC reviewed the security policies of 2,000 clinics and hospitals based in Europe. It found that only 144, or 7.2% of the researched 2000 facilities, have correctly implemented and configured security policies to flag, report, and remove outbound phishing emails.

The survey reviewed the deployment of the Domain-based Message Authentication, Reporting and Conformance (DMARC) standard among European healthcare domains. First published in 2012, the DMARC standard enables the automatic flagging and removal of receiving emails which are impersonating senders’ domains, which is a crucial way to prevent outbound phishing and spoofing attempts.

EasyDMARC’s research found that only 32% of the reviewed domains had implemented the decade-old DMARC standard, of those institutions, only 144 (7.2%) had implemented a ‘reject’ policy that automatically rejects emails imitating a legitimate domain. More organizations that deployed DMARC had configured it to do nothing about impersonating emails, with 361 (18%) domains having no policy. 140 (7%) had configured DMARC to send impersonating emails into quarantine. Adoption is similar on the international stage, with DMARC adoption among the top 100 global clinics and hospitals sitting at 54%. 

Among the healthcare  institutions implementing DMARC in Europe, the research also highlights a failure to configure the standard once adopted adequately. For example, among the minority of domains tested that employ DMARC, 643 (32%) had incorrectly configured it. As a result, these organizations lacked visibility into any impersonating emails they received or blocked.

Gerasim Hovhannisyan, EasyDMARC CEO and co-founder says: “Impersonating email domains is one of the most effective ways cybercriminals bypass organizational cyber defenses through phishing, spoofing, and ransomware attacks. Far too many organizations are overlooking a vital tool in effectively preventing this present and persistent danger. 

“With stories of ransomware attacks increasingly dominating headlines, the apparent absence of domain authentication renders these organizations susceptible to breaches of highly sensitive, valuable and potentially costly data. Without the adoption of DMARC or similarly effective policies, the sector will continue to see an increase in cyber events and subsequent disruptions and losses.”




Featured Articles

Why CISOs Remain Crucial in the Age of Rampant Ransomware

As ransomware attacks escalate, the CISO has emerged as an indispensable guardian for the cybersecurity of companies

Q&A: Protiviti's Sameer Ansari on CISOs' Growing Challenges

Managing Director - Global Cybersecurity and Privacy Lead at Protiviti, Sameer Ansari discusses his views on the growing challenges CISOs now face

How Partnerships Proved Pivotal for UnitedHealth After Hack

When hackers hit UnitedHealth subsidiary Change Healthcare with a huge cyber attack, its partnership with Vyne Dental proved pivotal in managing fallout.

Transforming Cybersecurity: IBM & Palo Alto's AI Integration

Technology & AI

C-suite Indifference to Cyber Could Cost Business £145k

Operational Security

Why Avast Warn of Social Engineering in Cybersecurity

Operational Security