Welcome to The Cyberskinny!
Published Oct 23 2018 09:41 AM 2,272 Views

Welcome to my new blog, where we will savor tasty cybersecurity morsels from time to time. Topics may be industry-focused (Healthcare more often than not) or they may be industry-agnostic, but they will be cybersecurity-based. And they will be skinny. I haven't decided on a cadence yet so let's see where this goes. If you can pick out the secondary theme of today's tasty tapas, feel free to let the world know in the comments!


If you're reading this blog, you're probably familiar with this fact: Phishing is a problem. A big one.

Phishers around the world sit at their computers looking surly and muttering things like "I aim to misbehave". Then they send out massive, broad phishing email campaigns. I mean, who doesn't want a Nigerian prince to hook them up with some sweet coin?

The savvier ones take the time to identify juicy targets and begin to socially stalk (aka "engineer") them. They identify some poor Mrs. Reynolds and initiate a campaign to gain her virtual trust, generally with but one goal in mind: get those creds.  Once they have those creds, the nefarious game is afoot.

We've all likely seen the situation and the numbers but they're worth repeating.

Here's a good view of what the phishing attack spectrum looks like.

CS phishing spectrum.png


Do users bite? Yes. Yes they do. And the further attackers move to the right above, the higher the hook rate (and monetary gain) they achieve.

CS phishing numbers.pngSo how do we protect ourselves, our customers, our patients, our employees? Normally a lengthy discussion ensues at this point but in today's Cyberskinny we are going to discuss one thing in particular: Protecting users from Phishing at the front door - i.e. the email entry vector. Shiny.


As one of the largest and most heavily attacked email services on the planet, Microsoft's Office365 serves as an excellent petri dish for a phishing miss/catch rate study. Microsoft recently posted an excellent blog describing a market comparison of our now top-flight phishing protection as surfaced through Office365 EOP (Exchange Online Protection) and ATP (Advanced Threat Protection). I'll summarize the high points here as I think they bear repeating. You can check out the official blog for all the juicy details.

Microsoft tested phish catch rate (model captured here) for Office365 email accounts across two periods from Nov '17-Jan '18 and May '18-Sept '18. We compared our own solution (EOP/ATP) against 11 other email protection vendors. The volume of O365 email that Microsoft protects is staggering compared to the rest of the market, hence some normalization had to be applied (again, the blog has the gory details).


So how did it play out?

In January the results showed that… hmmm. Decent results, but subpar compared to the high bar that had been set across the market. Looks like we had some work to do. 

So the engineers in Redmond strapped on their orange/red/yellow woven hats and went to work.

Their progress was covered in a three-part blog series starting in March ("Schooling a Sea of Phish Parts 1-3", part 1 here) and the same testing methodology was run again from May to September. The results?

A massive improvement, putting Microsoft's EOP and ATP right at the very top of the heap in terms of phish catch rate (see bottom figure in this blog). This is indicative of Microsoft's massive signal in the Intelligent Security Graph (6.5 trillion signals per day) paired with ever-evolving machine learning and AI, supported by 3,500 security researchers and an annual $1B spend on security R&D.

If you haven't considered Microsoft to be one of your primary security partners (and two years ago I couldn't fault you), you should now.


So strap on your blue hat (and browncoat), fire up some EOP/ATP (here's how) and protect your O365 users with arguably the best solution in the industry. Ahhhh… Serenity.


I hope to see you back here again soon and remember… you can't stop the signal.


CS phish results.png


Version history
Last update:
‎Jul 12 2019 01:52 PM
Updated by: