Exact impersonation isn’t an unsolvable problem: 5 takeaways from our chat with WHO

In a recent podcast we spoke with the CISO of the World Health Organization Flavio Aggio, and our CEO Rahul Powar, about the state of email security at the moment. They talked about changes they’re excited to see in cybersecurity, education around DMARC and their top recommendations to keep your email security posture at its best. In this blog, we’ve highlighted 5 of the key takeaways from this session. You can listen to the full podcast here.

1. Exact email impersonation is a network issue

Over 90% of cyber attacks start with a phishing email. These are becoming more sophisticated by the day, so it’s vital that businesses are gearing up to adopt DMARC. But out of the 47 million domains we’ve analyzed over the past few years, only 1.5% are fully DMARC compliant.

DMARC stands for ‘Domain-Based Message Authentication, Reporting & Conformance’ and is a protocol designed to protect your domain against impersonation. Implemented correctly, your brand is protected, email deliverability rates improve and your employees and colleagues won’t even know it’s there. But without it, your business is left open to a host of threats and dangers which sprout from domain impersonation.

When the COVID pandemic hit in March 2020, implementing DMARC became WHO CISO Flavio Aggio’s number one priority. WHO was a global beacon of guidance in this unprecedented time, and it was vital that they could communicate with media outlets and authorities securely. It’s no secret that cybercriminals prey on emotions to hook people in, and the fear created by a worldwide pandemic provided the perfect breeding ground for their targeted attacks.

By implementing DMARC swiftly, WHO made sure that no one could endanger public health or their reputation by impersonating their domain.

The benefits of DMARC are clear, from blocking email impersonation to protecting your supply chain, improving deliverability and securing your reputation. But we need to start viewing DMARC as a network solution. It’s not just about individual protection, it’s a standard that every organization needs to have to fill the gaps in the global supply chain and email communications.

2. Internet Service Providers could revolutionize the email eco system

Since adopting DMARC, Flavio’s message has been clear: that Internet Service Providers (ISPs) should make email authentication compulsory for all sending sources. If this was the case, the volume of processing these providers currently do would be slashed, and their business models would be revolutionized. But more importantly, the internet would be a safer place for everyone, and cybercriminals would have a much harder time carrying out impersonation attacks.

As Red Sift CEO Rahul Powar put it, ‘impersonation isn’t an unsolvable problem’. But in order to solve this problem, we need to acknowledge that email, without modern authentication standards layered on top, is not suitable for today’s internet.

So, it’s vital that we keep implementing the right protocols and machine-based solutions to suit our ever-evolving landscape. If we don’t, then our infrastructure could develop weaknesses and become more susceptible to sophisticated attacks over time.

3. When it comes to email security, knowledge is power

We’ve found that out of the Fortune 100 and 250 companies in the world, only 35% have fully implemented DMARC. So, a worrying 75% of these high value businesses brimming with customer data, capital and brand reputation, are at risk of domain fraud. Why?

Perhaps because there is a lack of education surrounding DMARC. The more you know about something, the better informed decisions you make. If these companies don’t have visibility of the scale of their problem and what’s going on around them, then there’s no incentive to do anything differently.

Ignorance is far from bliss, as demonstrated by the fallout from sophisticated cyberattacks on high profile organizations since COVID began. Companies worldwide need to be having what Rahul calls the ‘lightbulb moment’. This is when they can see the aggregate reports of where their domain is being fraudulently used, and then confidently take the steps to secure their domain and stop this. Companies who use OnDMARC, Red Sift’s gold standard solution for implementing DMARC, have easy access to all aggregate reports plus advanced forensics too, creating an additional layer of insight into their email landscape.

Even within the IT community, there seems to be some misunderstanding surrounding email impersonation, from exactly what DMARC does to the benefits of implementing it. There is also misinformation that circulates surrounding SEGs and unreliable ‘pseudo DMARC’ quick fixes. But one thing is clear; once organizations do understand the necessity of DMARC, they don’t go back. As Rahul put it, ‘every CISO I know who has worked in at least one organization with DMARC now can’t imagine working anywhere which hasn’t implemented it.’

4. The companies who don’t implement DMARC will bear the load in the future

It’s no secret that cyberattacks are constantly evolving. From the more primitive mass email attacks like the 2000 ILOVEYOU computer worm to the tailored, socially engineered spear phishing episodes we’re seeing now.

Hackers are getting smarter about who and how they target. But as more companies adopt a secure DMARC policy to protect their domains, the businesses who stay in the past will suffer a disproportionate number of attacks in the future. After all, this traffic needs to go somewhere.

5. There’s no silver bullet, but there is the Swiss Cheese Model

What technology can do for cyber and email security today is immeasurable, but as with most things, there’s no silver bullet solution or product which will solve all of the current and future challenges facing our industry. Instead Flavio talked about how we need to adopt a Swiss Cheese Model when it comes to our email and cyber security protection. This Swiss Cheese Model is essentially the practice of adding many layers of defence which each target different issues and overlap to reduce the risk of a single point of failure.

Building from the basics, companies should begin by implementing the widely-accepted protocols (like DMARC, BIMI, 2FA) which they know work and then build upon these based on their needs. Flavio suggests companies should ask two questions during this process:

  • Do we need the technology?
  • Is it worthwhile and will it have a large enough impact?

Once you’ve identified and implemented your additional security layers, these will work in sync to overlap and plug the gaps, ensuring the safest solution for your company’s data, money and reputation.

A final word

Every company has unique needs, and so to make the right choices for your security posture, you need to be asking yourself honestly what risk acceptance you’re willing to take. But with cybercrime and impersonation an ever-growing threat, all businesses are responsible for securing their circle of influence in the email network to a degree. Implementing the standards-based solutions like DMARC, 2 Factor Authentication, BIMI and Encryption is the least every company should be doing to secure the network we’re all a part of.

If we make these solutions robust and build them into the globally-accepted protocol, we can work to fortify our email security network for the future.

Want to start protecting your domain from impersonation and improving your deliverability today? Register for an OnDMARC free trial and get full visibility and control of what’s happening in your email landscape.

PUBLISHED BY

Sabrina Evans

26 May. 2021

SHARE ARTICLE:

Categories

Recent Posts

VIEW ALL
DMARC

Over 60% of healthcare organizations remain unprotected against data breaches

Sean Costigan

Introduction Red Sift’s analysis of healthcare organizations that reported large breaches to the Department of Health & Human Services (HHS) in 2023-2024 uncovered a troubling trend: post-breach, 61% remain unprotected against phishing and domain spoofing due to weak or nonexistent DMARC policies. DMARC (Domain-based Message Authentication, Reporting & Conformance) is a widely recognized security…

Read more
Awards

Red Sift wins 2025 Cybersecurity Excellence Award for OnDMARC

Jack Lilley

Executive Summary: Red Sift OnDMARC has been recognized with the 2025 Cybersecurity Excellence Award for its advanced email security solutions. By leveraging AI-powered tools like Red Sift Radar for security issues and Dynamic DNS Guardian for real-time monitoring, OnDMARC provides businesses with robust protection against phishing, spoofing, and business email compromise (BEC).  Key takeaways:…

Read more
Product Release

Red Sift’s Winter ‘24/’25 Quarterly Product Release

Francesca Rünger-Field

This quarter, we’re making security faster, smarter, and more proactive with updates that improve threat detection, reduce manual work, and prevent threats before they escalate. Highlights include: Brand Trust  Executive Impersonation: Detect unauthorized use of leadership identities By uploading and managing executive images in Brand Trust, security teams can detect and monitor unauthorized use…

Read more
AI

Enhanced logo detection with AI: A hybrid approach

Phong Nguyen

Executive Summary: Accurate logo detection is essential for protecting brands against misuse and fraudulent activities. Red Sift’s hybrid AI approach enhances detection precision, effectively balancing the reduction of false positives with the identification of genuine threats. This article: Introduction Logo detection is crucial for brand protection, helping identify logo misuse in lookalike domains and fraudulent…

Read more