Beware of Email

If you’re like me, on some days, email seems to be your primary form of communication.  I’m not proud of that, but it’s the truth.  Second to email would be our internal instant messaging system.  With all of this electronic communication, I abide by the golden rule of never exchanging any confidential or sensitive information via email or instant message.  Why?  EMAIL IS TOO RISKY!

So let’s take a quick look at the top 10 risks of emails.

  1. Emails sent to external email addresses (clients, customers, vendors, etc.) are not secured during transmission since they traverse the public Internet.  
  2. Internal emails between co-workers could be at risk during transmission if your organization outsources email hosting.
  3. If your emails are on a vendor’s web server, your vendor may not have appropriate controls in place to protect your emails from unauthorized internal or external access.
  4. Emails on backup media may not be secure.
  5. Mobile devices or personal computers connecting to your mail server have mail downloaded on those systems.
  6. Employees can access web mail from personal computers and download files and information to those external systems.
  7. Malware can enter your internal network via emails sent from unprotected systems.
  8. If simple authentication is utilized (username & password), then phishing schemes, dictionary attacks or simple password guessing can allow intruders access to employee email accounts (see Phishing: Biggest Threat for Healthcare in 2015?).
  9. Damaging emails can put the company at risk should it become subject to litigation.
  10. Reputation Risk: The Sony Hack.

So how do you protect yourself?  The best protection is to NOT use email to exchange confidential or sensitive information.  Several secure email solutions exist, such as ZixCorp Email Encryption Services, Barracuda’s Email Security Service and Cisco Email Security, but each of the risks identified should be assessed before implementing any secure solution.


Image courtesy of cool design at