Millions of people and businesses could be leaving themselves exposed to email scams, impersonation and stolen passwords because of basic security mistakes, a cyber security expert has warned. Email accounts are particularly valuable to criminals because they can provide access to sensitive conversations, financial information and password-reset links for other online accounts.
Francis West, CEO of Security Everywhere, said five relatively simple steps could significantly improve email security, from turning on two-step verification to checking whether criminals can impersonate your business's email domain.
Email at the centre of personal and professional lives
He said: "Email is at the centre of so much of our personal and professional lives, which makes it incredibly valuable to criminals. If somebody compromises your email, the damage doesn't necessarily stop with that account. The good news is there are practical things people and businesses can do today to make themselves much harder to target."
For businesses, Mr West said the first step should be checking their Domain-based Message Authentication, Reporting and Conformance (DMARC) protection. DMARC is an email authentication system designed to help prevent fraudsters sending messages that appear to come from a legitimate company's domain.
DMARC and two-step verification
Mr West said: "Run a free DMARC check on your own email domain. If you're not sitting at the strongest 'reject' level, there may still be an opportunity for somebody to impersonate your domain."
"Only around 9% to 10% of UK businesses have their email locked down strongly enough to stop impersonation outright. More than three-quarters can potentially be spoofed straight into someone's main inbox rather than necessarily being caught by junk filters."
The next measure applies to both businesses and consumers: activate two-step verification on every important email account.
Mr West added: "A password shouldn't be the only thing standing between a criminal and your inbox. Two-step verification means that even if somebody manages to obtain your password, there is another security barrier they need to overcome. It's also the National Cyber Security Centre's number one recommendation and if you haven't turned it on already, you should."
Password hygiene and breach alerts
Using the same password for several websites can mean a breach at one company leaves numerous other accounts vulnerable. Mr West said: "Stop reusing passwords, especially on your main email account. If criminals obtain a password from one data breach, they'll often try those same credentials elsewhere."
"Use a password manager to generate unique passwords instead. It means one company's security breach doesn't automatically put all your other accounts at risk."
People should also find out whether their email address or account details have previously appeared in known data breaches. Mr West said: "Have I Been Pwned has logged 17.8 billion breached accounts across more than 1,000 breached websites. At that scale, assuming your details could have appeared somewhere isn't scaremongering."
"Use a free breach-notification service and set up alerts so you know when your details appear in newly discovered leaks. If a password you've reused has been compromised, change it immediately."
Verifying bank detail changes
Finally, Mr West warned that an apparently genuine email requesting payment to a new bank account should always be independently verified. He said: "Never act on a bank detail change request by email alone. Criminals can impersonate businesses or compromise genuine email accounts and wait for the perfect moment to redirect a payment."
"Call the person or company using a phone number you already had and confirm the details verbally. Crucially, don't call a number contained in the suspicious email because that could simply connect you to the fraudster."
"A two-minute phone call might feel unnecessary, but when you're transferring thousands of pounds, it could be the most valuable call you make."



