{"id":4622,"date":"2024-09-20T07:45:49","date_gmt":"2024-09-19T19:45:49","guid":{"rendered":"https:\/\/ostermanresearch.com\/2024\/09\/20\/email-security-opswat\/"},"modified":"2025-03-10T11:07:13","modified_gmt":"2025-03-09T22:07:13","slug":"email-security-opswat","status":"publish","type":"post","link":"https:\/\/ostermanresearch.com\/2024\/09\/20\/email-security-opswat\/","title":{"rendered":"Email Security Threats Against Organizations in Critical Infrastructure sectors"},"content":{"rendered":"\n<p>Late in 2023 we started a conversation with OPSWAT, a cybersecurity vendor focused on the critical infrastructure sector, on undertaking a research project to assess the email security posture of critical infrastructure organizations. We have had the opportunity to do many research projects on email security in recent years, but while the others have included organizations in the critical infrastructure sector, this was the first project that focused exclusively on this cohort. Exciting times!<\/p>\n\n\n\n<p>The research programme:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Collected data from a global audience of critical infrastructure organizations, with representation across North America, EMEA, and APAC. The survey was balanced to get around 40% of responses from North America, 20% from EMEA, and 40% from APAC.<\/li>\n\n\n\n<li>Engaged with leaders within these organizations that have IT or security responsibility and knowledge of their email security posture. <\/li>\n\n\n\n<li>Drew on CISA&#8217;s list of <a href=\"https:\/\/www.cisa.gov\/topics\/critical-infrastructure-security-and-resilience\/critical-infrastructure-sectors\" target=\"_blank\" rel=\"noreferrer noopener\">critical infrastructure sectors<\/a>, such as chemicals, commercial facilities, communications, critical manufacturing, dams, and more. CISA says there are 16 sectors classified as critical infrastructure. CISA defines these sectors on this basis: <em>sectors whose assets, systems, and networks, whether physical or virtual, are considered so vital to the United States that their incapacitation or destruction would have a debilitating effect on security, national economic security, national public health or safety, or any combination thereof<\/em>. While this definition is US-centric, the same principle applies in other places, too.<\/li>\n<\/ul>\n\n\n\n<p>Once the research design was agreed, we worked on the survey questions, took this to field, and analyzed the data. You can get your copy of the results from the <a href=\"https:\/\/www.opswat.com\/osterman-report\" target=\"_blank\" rel=\"noreferrer noopener\">OPWAT website<\/a>. But here&#8217;s a preview:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Critical Infrastructure Remains a Target<\/strong><br>80% of critical infrastructure entities fell prey to email-related security breaches within the past 12 months, highlighting their attractiveness to cyber threat actors.<\/li>\n\n\n\n<li><strong>Lingering Vulnerability<\/strong><br>Despite advancements in cybersecurity, 48% of organizations lack confidence in their existing email security defenses, leaving them vulnerable to potentially devastating cyberattacks.<\/li>\n\n\n\n<li><strong>Noncompliance presents significant operational and business risks<\/strong><br>Shockingly, 65% of organizations are not compliant with regulatory standards, exposing themselves to significant operational and business risks.<\/li>\n<\/ul>\n\n\n\n<p>A major recommendation in the report is finding email security capabilities that &#8220;preclude and prevent threats&#8221; from finding their way into an organization&#8217;s email system. While this is critical for critical infrastructure organizations, it is no less so for those in other sectors.<\/p>\n\n\n\n<p>Check out <a href=\"https:\/\/www.opswat.com\/osterman-report\" target=\"_blank\" rel=\"noreferrer noopener\">OPSWAT&#8217;s site<\/a> for your copy.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Our research project with OPSWAT assessed the email security of critical infrastructure organizations globally, revealing that 80% experienced email-related breaches in the past year. Despite advancements in cybersecurity, 48% lack confidence in defenses, and 65% are noncompliant with regulations, posing operational risks.<\/p>\n","protected":false},"author":384585,"featured_media":4067,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[712027488,712027168,712027195],"tags":[712027522],"class_list":["post-4622","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-critical-infrastructure","category-cybersecurity","category-email-security","tag-research-reports-we-worked-on"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2025\/01\/opswat2025.jpg?fit=1100%2C360&ssl=1","jetpack_likes_enabled":true,"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/pcHAk4-1cy","_links":{"self":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/4622","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/users\/384585"}],"replies":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/comments?post=4622"}],"version-history":[{"count":1,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/4622\/revisions"}],"predecessor-version":[{"id":4642,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/4622\/revisions\/4642"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/media\/4067"}],"wp:attachment":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/media?parent=4622"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/categories?post=4622"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/tags?post=4622"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}