I have had a demo of KnowBe4, have scheduled in one for TitanHQ, but am looking for other vendors to provide phishing protection. I just need to find a solution to combat this nonsense, preferably one that prevents it either hitting the mailbox, or stops users dead in their tracks if they click links they shouldn’t.<\/p>\n
I have 160 users, using M365. We have (of course) no budget for this, so I am going to have to sell it to the CEO, although the CFO is on board, which is a start!<\/p>\n
I did like KnowBe4, as it has lots of useful admin ‘toys’, but the reality is the IT team has little time to play, so just preventing this stuff is key.<\/p>\n
Any further recommendations?<\/p>","upvoteCount":5,"answerCount":10,"datePublished":"2024-05-24T12:47:11.846Z","author":{"@type":"Person","name":"Neurotech","url":"https://community.spiceworks.com/u/Neurotech"},"acceptedAnswer":{"@type":"Answer","text":"\n\n
<\/div>\n
Neurotech:<\/div>\n
\nor stops users dead in their tracks if they click links they shouldn’t.<\/p>\n<\/blockquote>\n<\/aside>\n
A mail filter wont do this, if it’s go to the users mailbox, you need a web filter, proxy or NGFW to do this for malicious links,<\/p>\n
I would also add that tight firewall rules, especially outbound will also limit where users can go, for example, don’t allow outbound access on all ports, limit users to 80/443, so any websites with uncommon ports will be blocked, invalid certificates should also be blocked by the afore mentioned filters.<\/p>\n
Have you considered Defender for 365?<\/p>\n\n\n
<\/div>\n
Neurotech:<\/div>\n
\nWe have (of course) no budget for this<\/p>\n<\/blockquote>\n<\/aside>\n
EFA-Project, it will take a little configuring, but you can tune it to your needs.<\/p>","upvoteCount":3,"datePublished":"2024-05-24T19:54:07.468Z","url":"https://community.spiceworks.com/t/phishing-email-security-who/1079157/5","author":{"@type":"Person","name":"Rod-IT","url":"https://community.spiceworks.com/u/Rod-IT"}},"suggestedAnswer":[{"@type":"Answer","text":"
I have had a demo of KnowBe4, have scheduled in one for TitanHQ, but am looking for other vendors to provide phishing protection. I just need to find a solution to combat this nonsense, preferably one that prevents it either hitting the mailbox, or stops users dead in their tracks if they click links they shouldn’t.<\/p>\n
I have 160 users, using M365. We have (of course) no budget for this, so I am going to have to sell it to the CEO, although the CFO is on board, which is a start!<\/p>\n
I did like KnowBe4, as it has lots of useful admin ‘toys’, but the reality is the IT team has little time to play, so just preventing this stuff is key.<\/p>\n
Any further recommendations?<\/p>","upvoteCount":5,"datePublished":"2024-05-24T12:47:11.919Z","url":"https://community.spiceworks.com/t/phishing-email-security-who/1079157/1","author":{"@type":"Person","name":"Neurotech","url":"https://community.spiceworks.com/u/Neurotech"}},{"@type":"Answer","text":"
Have you looked into Mimecast?<\/p>","upvoteCount":1,"datePublished":"2024-05-24T12:53:37.866Z","url":"https://community.spiceworks.com/t/phishing-email-security-who/1079157/2","author":{"@type":"Person","name":"Ecrawf099","url":"https://community.spiceworks.com/u/Ecrawf099"}},{"@type":"Answer","text":"
I’ve used Mimecast & GoSecure and both worked fine. Both filter before it hits the users’ inbox.<\/p>","upvoteCount":2,"datePublished":"2024-05-24T17:50:42.826Z","url":"https://community.spiceworks.com/t/phishing-email-security-who/1079157/3","author":{"@type":"Person","name":"Ethan6123","url":"https://community.spiceworks.com/u/Ethan6123"}},{"@type":"Answer","text":"
I’ve used many different antivirus/email filtering systems and services over the years. About a year and half ago I ended them all and added Microsoft Defender for Office 365 P2 to our tenants and it has been working great. Even has some simulation training. \nThink they have a free trial for this so you can test it out on some users.<\/p>","upvoteCount":2,"datePublished":"2024-05-24T18:08:09.155Z","url":"https://community.spiceworks.com/t/phishing-email-security-who/1079157/4","author":{"@type":"Person","name":"MSouthworth","url":"https://community.spiceworks.com/u/MSouthworth"}},{"@type":"Answer","text":"
I think you should try mimecast and Go secure.<\/p>","upvoteCount":0,"datePublished":"2024-05-27T13:14:58.302Z","url":"https://community.spiceworks.com/t/phishing-email-security-who/1079157/6","author":{"@type":"Person","name":"spiceuser-jwx9h","url":"https://community.spiceworks.com/u/spiceuser-jwx9h"}},{"@type":"Answer","text":"
… but how do you contend with the URL being re-written, i.e. when you look at the e-mail, does it show you the URL it end up going to. My worry about using this feature in mimecast is, what happens in the following 2 scenarios:<\/p>\n
\nI want to write some code that inspects historic e-mails and need to be able to see URLs<\/li>\n We no longer use mimecast and all URLS are dereferenced?<\/li>\n<\/ul>\nTIA - JAC.<\/p>","upvoteCount":0,"datePublished":"2024-05-28T10:03:02.221Z","url":"https://community.spiceworks.com/t/phishing-email-security-who/1079157/7","author":{"@type":"Person","name":"jasonchapman6665","url":"https://community.spiceworks.com/u/jasonchapman6665"}},{"@type":"Answer","text":"\n\n
<\/div>\n
Neurotech:<\/div>\n
\nI have had a demo of KnowBe4, have scheduled in one for TitanHQ, but am looking for other vendors to provide phishing protection. I just need to find a solution to combat this nonsense, preferably one that prevents it either hitting the mailbox, or stops users dead in their tracks if they click links they shouldn’t.<\/p>\n
I have 160 users, using M365. We have (of course) no budget for this, so I am going to have to sell it to the CEO, although the CFO is on board, which is a start!<\/p>\n
I did like KnowBe4, as it has lots of useful admin ‘toys’, but the reality is the IT team has little time to play, so just preventing this stuff is key.<\/p>\n
Any further recommendations?<\/p>\n<\/blockquote>\n<\/aside>\n
But what was the decision to move to MS365 or O365 in the first place ? \nThe person or team doing this project should have projected the other costs like AV, email security, email backup etc ?<\/p>\n
Even for our smaller Org that have only 50 users, we bought MS Office 2016 via MSVL and then moved on to Exchange Online, then to Google Suites for Business (as lots of features like email retention, Google drive, Google shared folders & extreme large storage etc were out of the box).<\/p>\n
Lots of savings from using perpetual licenses vs subscriptions.<\/p>\n
Another large savings on security is not to use email clients like Outlook and also to use browser like Chrome with email ?<\/p>\n
Sad to say, with smaller Org, the budget is much smaller and time to look for savings instead of the “toys” where big boys are having ? But that also depends on what business your Org is in ?<\/p>","upvoteCount":0,"datePublished":"2024-05-28T10:40:32.537Z","url":"https://community.spiceworks.com/t/phishing-email-security-who/1079157/8","author":{"@type":"Person","name":"adrian_ych","url":"https://community.spiceworks.com/u/adrian_ych"}},{"@type":"Answer","text":"\n\n
<\/div>\n
Rod-IT:<\/div>\n
\n\n\n
<\/div>\n
Neurotech:<\/div>\n
\nor stops users dead in their tracks if they click links they shouldn’t.<\/p>\n<\/blockquote>\n<\/aside>\n
A mail filter wont do this, if it’s go to the users mailbox, you need a web filter, proxy or NGFW to do this for malicious links,<\/p>\n<\/blockquote>\n<\/aside>\n
Many mail filters do this. They substitute the URL in the message, and can perform on-demand scanning when a user clicks. This supplements URL protection scanning at the firewall and endpoint.<\/p>\n
Mail filters that just examine a URL when it passes thru are insufficient. URLs can be redirected at any time, and if you are only statically examining on mail accept, you will miss if it changes.<\/p>","upvoteCount":0,"datePublished":"2024-05-28T14:58:09.631Z","url":"https://community.spiceworks.com/t/phishing-email-security-who/1079157/9","author":{"@type":"Person","name":"phildrew","url":"https://community.spiceworks.com/u/phildrew"}},{"@type":"Answer","text":"
If you mean something like Microsoft Safelinks - yes, but they only work if the link is malicious or does something they know about. A dedicated proxy or filter will add another layer and can also block based on content, something a URL scanner cant do. Yet.<\/p>","upvoteCount":0,"datePublished":"2024-05-28T17:34:25.693Z","url":"https://community.spiceworks.com/t/phishing-email-security-who/1079157/10","author":{"@type":"Person","name":"Rod-IT","url":"https://community.spiceworks.com/u/Rod-IT"}}]}}
Neurotech
(Neurotech)
May 24, 2024, 12:47pm
1
I have had a demo of KnowBe4, have scheduled in one for TitanHQ, but am looking for other vendors to provide phishing protection. I just need to find a solution to combat this nonsense, preferably one that prevents it either hitting the mailbox, or stops users dead in their tracks if they click links they shouldn’t.
I have 160 users, using M365. We have (of course) no budget for this, so I am going to have to sell it to the CEO, although the CFO is on board, which is a start!
I did like KnowBe4, as it has lots of useful admin ‘toys’, but the reality is the IT team has little time to play, so just preventing this stuff is key.
Any further recommendations?
5 Spice ups
Ecrawf099
(Ecrawf099)
May 24, 2024, 12:53pm
2
Have you looked into Mimecast?
1 Spice up
I’ve used Mimecast & GoSecure and both worked fine. Both filter before it hits the users’ inbox.
2 Spice ups
MSouthworth
(Great and Powerful Admin)
May 24, 2024, 6:08pm
4
I’ve used many different antivirus/email filtering systems and services over the years. About a year and half ago I ended them all and added Microsoft Defender for Office 365 P2 to our tenants and it has been working great. Even has some simulation training.
Think they have a free trial for this so you can test it out on some users.
2 Spice ups
Rod-IT
(Rod-IT)
May 24, 2024, 7:54pm
5
A mail filter wont do this, if it’s go to the users mailbox, you need a web filter, proxy or NGFW to do this for malicious links,
I would also add that tight firewall rules, especially outbound will also limit where users can go, for example, don’t allow outbound access on all ports, limit users to 80/443, so any websites with uncommon ports will be blocked, invalid certificates should also be blocked by the afore mentioned filters.
Have you considered Defender for 365?
EFA-Project, it will take a little configuring, but you can tune it to your needs.
3 Spice ups
I think you should try mimecast and Go secure.
… but how do you contend with the URL being re-written, i.e. when you look at the e-mail, does it show you the URL it end up going to. My worry about using this feature in mimecast is, what happens in the following 2 scenarios:
I want to write some code that inspects historic e-mails and need to be able to see URLs
We no longer use mimecast and all URLS are dereferenced?
TIA - JAC.
Neurotech:
I have had a demo of KnowBe4, have scheduled in one for TitanHQ, but am looking for other vendors to provide phishing protection. I just need to find a solution to combat this nonsense, preferably one that prevents it either hitting the mailbox, or stops users dead in their tracks if they click links they shouldn’t.
I have 160 users, using M365. We have (of course) no budget for this, so I am going to have to sell it to the CEO, although the CFO is on board, which is a start!
I did like KnowBe4, as it has lots of useful admin ‘toys’, but the reality is the IT team has little time to play, so just preventing this stuff is key.
Any further recommendations?
But what was the decision to move to MS365 or O365 in the first place ?
The person or team doing this project should have projected the other costs like AV, email security, email backup etc ?
Even for our smaller Org that have only 50 users, we bought MS Office 2016 via MSVL and then moved on to Exchange Online, then to Google Suites for Business (as lots of features like email retention, Google drive, Google shared folders & extreme large storage etc were out of the box).
Lots of savings from using perpetual licenses vs subscriptions.
Another large savings on security is not to use email clients like Outlook and also to use browser like Chrome with email ?
Sad to say, with smaller Org, the budget is much smaller and time to look for savings instead of the “toys” where big boys are having ? But that also depends on what business your Org is in ?
phildrew
(phildrew)
May 28, 2024, 2:58pm
9
Rod-IT:
A mail filter wont do this, if it’s go to the users mailbox, you need a web filter, proxy or NGFW to do this for malicious links,
Many mail filters do this. They substitute the URL in the message, and can perform on-demand scanning when a user clicks. This supplements URL protection scanning at the firewall and endpoint.
Mail filters that just examine a URL when it passes thru are insufficient. URLs can be redirected at any time, and if you are only statically examining on mail accept, you will miss if it changes.
Rod-IT
(Rod-IT)
May 28, 2024, 5:34pm
10
If you mean something like Microsoft Safelinks - yes, but they only work if the link is malicious or does something they know about. A dedicated proxy or filter will add another layer and can also block based on content, something a URL scanner cant do. Yet.