How Microsoft Copilot Has Evolved into Your Digital Co-Worker
Publish Date
06/07/2026
Categories
Blogs Hot Topic
Artificial intelligence is evolving at an incredible pace, and Microsoft continues to push the boundaries of what is possible with Microsoft 365 Copilot which has morphed from being an AI assistant to a genuine digital co-worker. The latest wave of updates brings more intelligence, deeper collaboration capabilities, enhanced content creation tools, and stronger governance features making Copilot an even more powerful workplace assistant.
For businesses across the Middle East looking to improve productivity, streamline workflows, and unlock greater value from Microsoft 365, these new capabilities offer plenty to get excited about.
One of the most impressive additions is Video Recap in Copilot Chat. Rather than simply generating a written meeting summary, Copilot can now create a narrated highlight reel featuring key moments from recorded meetings.
Instead of spending an hour watching a meeting recording, users can quickly review the most important discussions, decisions, and action points through a concise video summary. For busy professionals managing multiple meetings each day, this could prove to be a significant time saver.
Microsoft has also expanded Audio Recap capabilities, adding support for multiple new languages, making meeting insights more accessible for global and multilingual teams.
Microsoft’s Researcher capability continues to evolve rapidly. Users can now transform research outputs into different formats with a single click, including:
This means a piece of research can be instantly adapted for executives, project teams, or external stakeholders without requiring manual reformatting.
Even more exciting is the introduction of multi-model intelligence. New capabilities known as Critique and Council use multiple AI models to review, validate, and compare outputs before presenting results.
In simple terms, Copilot is no longer relying on a single AI perspective. It can now challenge its own conclusions, compare viewpoints, and strengthen the quality and reliability of research findings. This represents a significant step forward for businesses that rely on AI-generated analysis to support decision-making.
Excel users are seeing some of the most practical improvements. Through Work IQ, Copilot can automatically pull relevant context from emails, meetings, chats, and files to help it understand the wider business situation before making recommendations or edits. The result is more intelligent spreadsheet assistance that reflects current projects, priorities, and business relationships rather than simply analyzing rows and columns in isolation.
Microsoft has also removed another common limitation by enabling Copilot to perform multi-step edits on locally stored Excel files, meaning users no longer need to move workbooks to the cloud before taking advantage of advanced Copilot capabilities.
Content creation continues to be one of Copilot’s strongest areas. In Word, Copilot now automatically displays citations when using information from web sources or organizational data. This provides greater transparency and helps users validate information more easily.
In PowerPoint, Copilot can now standardize formatting across an entire presentation in a single action. Fonts, font sizes, and bullet styles can be aligned automatically, eliminating hours of manual slide clean-up and helping teams create polished presentations faster.
Meanwhile, Copilot Notebooks have received a major redesign, bringing together content, references, and conversations into a unified workspace that makes collaboration and knowledge management easier than ever.
Microsoft is also reimagining SharePoint with the introduction of AI in SharePoint. Users can now create sites, pages, libraries, and lists simply by describing what they want in natural language. At the same time, AI can automatically organize content by applying metadata and adapting document libraries as information changes. For organisations investing in AI, this is particularly important because better organized information leads directly to better Copilot responses and more effective AI agents.
As organisations adopt AI at scale, governance becomes increasingly important. Microsoft has responded with expanded Purview Data Loss Prevention (DLP) capabilities that help prevent sensitive information from being exposed through prompts or web searches. Administrators can now apply policies that detect sensitive information such as financial data or national ID numbers and prevent inappropriate use within Copilot. Additional controls allow organisations to manage trusted information sources, exclude specific web domains from AI grounding, and gain deeper visibility into how Copilot is being used across the business.
From intelligent meeting recaps and advanced research capabilities to smarter document creation and stronger governance, Copilot is helping organisations work faster, make better decisions, and get more value from their Microsoft 365 investment.
For businesses that have not yet explored Microsoft Copilot—or for those looking to maximize their existing deployment—now is the perfect time to take another look.
Want to discover how Microsoft Copilot can transform the way your organization works? Contact us today to learn more about licensing, deployment, training, and adoption services.

Strengthening Organizational Defenses in the Age of Rising Email Threats
Publish Date
21/01/2025
Categories
Blogs Events & Webinars Hot Topic Services & Solutions
Cybercrime is on a relentless rise, impacting all organizations everywhere. As detailed in the latest Mimecast State of Email and Collaboration Security (SOECS) Report 2024, email remains the leading attack vector for cybercriminals. In the past 12 months alone, businesses experienced a 95% increase in ransomware attacks, alongside escalating phishing and spoofing incidents.
The SOECS 2024 report emphasizes that while 96% of companies now have a formal cybersecurity strategy, most acknowledge their defenses are incomplete. Waiting to act increases exposure to risks such as ransomware demands, which have skyrocketed from an average of $212,000 in 2022 to $740,000 in 2023.
These trends signal an urgent need for businesses to bolster their cyber threat defenses.
Email-based threats are becoming increasingly sophisticated, fueled by generative AI tools that help cybercriminals craft realistic phishing attempts – 1 Billion emails were exposed in 2023, affecting countless organizations and individuals.
Mimecast’s findings reveal that:
These stats say it all. They highlight the critical importance of adopting a robust email security strategy. Businesses relying solely on native security tools often face significant vulnerabilities, with 37% of respondents saying the tools fail to block malware effectively.
While technological solutions are critical, human error remains a leading cause of breaches, accounting for 74% of cybersecurity incidents. Careless web browsing, oversharing on social media, and improper email usage are common issues. Yet only 15% of companies offer ongoing cybersecurity awareness training. This gap leaves organizations vulnerable and underscores the need for regular, adaptive training tailored to high-risk employees.
As hybrid and remote work models continue to expand, so does the attack surface presented by collaboration tools. Platforms like Zoom, Slack, and Google Workspace, though essential, pose new security risks. Seven out of 10 organizations report facing urgent threats from these tools, with many lacking sufficient safeguards.
To navigate these challenges, proactive measures are essential. Cobweb MENA, in collaboration with Mimecast, offers expert guidance to assess your organization’s cybersecurity vulnerabilities and implement effective solutions. Together, we provide:
Comprehensive Risk Assessments: Identify potential weaknesses and tailor solutions to your specific needs.
Join us in March for an exclusive webinar featuring Mimecast experts. Learn how to tackle cybersecurity threats effectively and discover pathways to robust protection.
By partnering with Cobweb MENA, you can secure your systems, safeguard your reputation, and avoid the devastating financial and operational impacts of cyberattacks.
Together, let’s turn the tide against cybercrime and ensure we all thrive in secure digital future.
Introducing Expedite V2: For Smarter Destination Management

Introducing Expedite V2: For Smarter Destination Management
Publish Date
02/12/2024
Categories
Blogs Hot Topic Services & Solutions
For DMCs time and accuracy are everything. AI-powered Expedite is now the cornerstone of DMC efficiency and with the launch of Expedite V2, we’re taking innovation to the next level. Designed to handle the evolving complexities of the travel and hospitality landscape, V2 is transforming how DMCs manage data, inventory, and seasonal demands.
Expedite V1 streamlined the painstaking task of extracting data from hotel contracts and populating DMC inventory systems. V2 is even smarter. It dynamically handles seasonal updates, including:
It the smart way to eliminate the need for manual updates, reducing human error and saving countless work hours.
Seasonal offers and promotions can be a DMC’s logistical nightmare, requiring hours of meticulous updates. Expedite V2 automates this process, ensuring your inventory reflects real-time changes without breaking a sweat leaving you to focus on delivering exceptional experiences.
Expedite’s AI-driven power can deliver:
Expedite V2 adapts to portfolio expansion and seasonal/promotional spikes. With machine learning at its core, it grows with your business, managing higher data volumes effortlessly.
By automating updates and inventory adjustments, Expedite V2 gives DMCs the freedom to focus on customers. It enables you to:
Expedite is reshaping the hospitality and travel landscape, delivering transformative gains that make DMCs more competitive and resilient.
Join the growing list of DMCs who are transforming their operations with Expedite V2. Book your free consultation today and see how V2 will make your business faster, smarter, and more resilient.
The future of destination management is here, and it’s powered by Expedite V2.
5 Ways Expedite Can Ease DMCs’ Rising Cost Challenges

5 Ways Expedite Can Ease DMC’s Rising Cost Challenges
Publish Date
28/11/2024
Categories
Blogs Hot Topic Services & Solutions
The recent Global DMC Partners’ 10th annual Connection revealed DMCs are struggling with 30% higher costs across airfares, accommodations, staffing, and more. Keeping up while delivering quality experiences is getting tougher. Budgets are ballooning just to maintain current offerings, making the need for streamlined efficiency and cost-saving solutions more urgent. Here’s where Expedite, our AI-powered, context-driven data management solution, is the game-changer DMCs need.
Imagine slashing contract processing times from 10 hours to just 45 minutes. That’s what a top hospitality client has already realized thanks to Expedite’s groundbreaking AI. DMCs can now reinvest time into enhancing service quality.
Expedite’s AI processes up to three contracts per hour – that’s a 24x improvement in output and supersonic times to market. Expect fewer bottlenecks and better management of peak travel and seasonal high volumes, all while maintaining service excellence.
Expedite’s advanced AI ensures impeccable data extraction and validation, significantly reducing human errors. DMCs can now trust their data, reduce rework, and make faster, more informed decisions.
Whether you’re dealing with seasonal demand spikes or expanding your portfolio, Expedite’s adaptive algorithms scale seamlessly with your needs. As your workload increases, the AI learns and optimizes, managing growing data volumes without sacrificing performance or reliability.
Expedite goes beyond just automation. It helps manage inventory efficiently, adjusts dynamically for seasonal offers, and handles ad hoc customer queries with ease meaning DMCs can elevate client experiences, provide prompt responses, and execute special promotions smoothly.
Expedite is reshaping the hospitality and travel landscape, delivering transformative gains that make DMCs more competitive and resilient.
Publish Date
10/09/2024
Categories
Blogs Hot Topic
In the dynamic world of IT management, streamlining tasks and enhancing efficiency isn’t just beneficial; it’s essential. Copilot, Microsoft’s generative AI assistant, is transforming how IT managers and professionals handle their daily workload. By integrating Copilot into your IT operations, you can elevate your productivity and precision to new heights.
As an IT manager, mornings can be hectic, filled with catching up on missed meetings and setting the day’s agenda. With Copilot’s integration with tools like Jira, you can have a prioritized list of tasks and updates ready before your first cup of coffee. No need to sift through countless emails or dashboards—Copilot does the heavy lifting, ensuring you start your day efficiently.
Preparing for stakeholder meetings can be overwhelming, requiring you to stay on top of every message, document, and task. Copilot’s seamless integration with communication platforms like Teams helps you summarize key points and action items. This ensures you enter each meeting fully informed and ready to engage effectively.
IT Managers are often bogged down with processing documentation, reporting, and preparing presentations. Copilot’s assistive features in Word and PowerPoint transform these manual, time-consuming processes into quick, effortless tasks. You can generate comprehensive proposals and presentations from your data, complete with key insights and actionable steps, all while maintaining focus on content that resonates with your stakeholders.
Analyzing IT strategies and technical reviews demands attention to detail and the ability to categorize information by impact, initiative, and financial implications. Copilot in Excel serves as your analytical partner, helping you summarize complex data into coherent, stakeholder-friendly tables saving you time and presenting data effectively.
As the working day nears a close, providing feedback on initiatives and projects is crucial. Drafting clear, concise, and actionable emails to stakeholders ensures continuous improvement and engagement. Copilot’s functionality within Outlook simplifies this process, keeping your projects on track and your team informed.
For IT managers, Copilot is more than just a tool—it’s a digital assistant that adapts to your needs, streamlines your workflow, and empowers you to focus on delivering value and innovation within your organization. Every minute counts, and Copilot ensures your business keeps pace and sets efficiency standards for the entire organization.
By integrating Copilot into your working day, you get more than just a license; you gain a competitive edge.
Interested in learning how Copilot can elevate your IT operations? Contact us for licensing details and expert Copilot consulting services to harness the full potential of your IT infrastructure management.

Publish Date
10/09/2024
Categories
Blogs Hot Topic
Microsoft’s artificial intelligence assistant Copilot is well known for its ability to cut through mundane tasks enabling people to draft content and summarise meetings quicker and in context but its newest version, which went live this year, has major implications for improving enterprise efficiency and productivity. Here’s how:
Copilot can help complete lines of code, debugging, or even writing entire functions and GitHub Copilot can help programmers simplify their coding process. So instead of spending time on routine coding tasks or searching for bugs in code, developers can focus on complex problem-solving and innovation.
Copilot applications like Jarvis and Copy.ai make it easier for writers to create copy. These tools help generate marketing copy and more so that writers can focus on research, strategy, and execution.
Corporate or contract law professionals can use Copilot to automate the review and drafting of legal documents. AI speeds up this normally time intensive task and lowers the chance of human error.
Copilot can help medical professionals in diagnosing conditions and creating personalized treatment plans. Combining Copilot with a medical database offers quick access to relevant information, which leads to faster and more accurate diagnoses and more effective treatment strategies. The result is improved patient care experiences.
Copilot can help customer service representatives deliver faster and more accurate support. AI can suggest the best responses or solutions by analysing customer queries and improving customer satisfaction. Copilot skims available information to provide a detailed summary and overview helping businesses maintain high service levels.
Using Copilot in education enables faster creation of learning materials and the ability to cater to individual learning styles. Currently, learning materials are created for mass consumption but not everyone learns at the same pace or at the same level. Through Copilot and adaptive AI, a more tailored approach to distance learning can be created so that students at all stages of the learning curve have content available to them through more accessible means.
Banking, investment, or insurance professionals constantly make decisions based on data. Using Copilot automation to improve the data analysis enables faster identification of trends and quicker strategic decision-making.
Copilot can optimize advertising campaigns and strategy planning to enable digital marketers to analyse their audience faster and with more depth. Automation can analyse data from a previous campaign and suggest improvements, target demographics, and content strategies that lead to higher engagement rates and ROI. Marketers can then consistently refine their efforts to reach wider audiences and gain maximum impact.
Automation delivers a competitive edge in logistics and distribution. Planning optimal routes, managing inventories, and predicting demand take considerable time and manpower. Through Copilot, operations are more efficient, costs are lowered, and operators can pivot to meet demands faster while preparing for future demand.
Architects and designers can use Copilot applications to enable more efficient design processes by providing real-time suggestions and automate parts of the design process. Professionals then have more time to explore creative solutions while project development and client presentations become much easier to shape.
Want to know more about how Copilot can supercharge your efficiency and productivity? Contact us for expert Copilot consulting. email: sales.uae@cobweb.com or call +971 4 455 3100.

Publish Date
04/09/2024
Categories
Blogs
As cyber attacks become more advanced and intricate, being clued up on the different kinds of threats you’ll face is vital.
There are a plethora of different attacks in the arsenal of the modern attacker, so knowing what you’ll be up against is important for any modern organisation. By preparing yourself and knowing what you’re up against, you can ensure that you’re secure.
That’s why in this article, we’re going to go over the eight most common forms of cyberattack that you’ll face in 2023, and how you can get started in protecting yourself today.
Phishing — the most common form of attack — is trying to trick someone to get their details. Usually using realistic-looking important emails from what would be a reputable source, a phishing attack aims to trick the victim into thinking that they’re someone else.
For example, common phishing attacks tend to be scammers pretending to be Amazon or a bank, trying to get card details off of unaware victims. These scams are easy to fall for if you’re not vigilant.
Malware is software that is used in a malicious manner. This will be software within your system that is usually built to do damage to your infrastructure. With this, hackers can easily cause significant damage throughout your system and steal your data.
Malware traditionally comes in the form of a trojan attack — named after the trojan horse, in which the malware is bundled with another piece of harmless software. This is an easy way to get the ‘payload’ (the virus) into your system to wreak havoc.
Enforcing security compliance throughout your organisation and educating on the dangers of downloading files from unknown sources is the best way to stop malware from entering your organisation.
Investing in good antivirus software throughout your business is also a way to stamp out malware at the roots. If you’re looking to get started with good antivirus software, get in touch with us today.
Denial of service (DOS) attacks are attacks that aim to simply disable the day-to-day infrastructure of a business. DOS attacks will usually send lots of requests to a server with the aim to overload it. This will deny service to your whole organisation and can be very crippling.
Tools like Azure DDOS Protect offer protection from DOS attacks by enforcing limits on the number of requests that can be sent to your server in one go. These attacks are simply stoppable by having the correct security — to make sure that you’re secure against DOS attacks, get in touch today.
Spoofing attacks are the type of attacks where the attacker masquerades as trusted personnel to push someone to do something. This attack uses social engineering to take advantage of a victim and manipulate them to the attacker’s ideal outcome.
IP Spoofing attacks are a specific kind of spoofing attack that comes with your typical DOS attack. This is when packets are altered to appear that they’re coming from a trusted network, to gain access to the server. This is why monitoring network activity within your organisation is crucial.
Credential stuffing is when an attacker uses stolen credentials to try to log into as many websites as possible. The aim is to target those who reuse credentials — when the credentials are breached on one website, credential stuffing allows the attacker to try to access other websites and accounts using the same credentials.
If a victim is successfully breached, a hacker could potentially gain control of every account they have — including work accounts. This is why encouraging and enforcing good password hygiene is crucial (as well as ensuring password changes are enforced throughout your organization).
Supply chain attacks are intricate attacks in which an attacker would target a third-party organisation to try to launch an attack into your system by infecting their services with some kind of payload.
This is usually to try to cause crippling damage to your organisation in a completely unexpected way or to cause damage to multiple organisations at once.
The aim of this is to access a secure system from a much less secure breach point, to try to gain access to the organisation and breach through the security that is currently protecting your system.
Insider threats are when an insider — someone within your organisation — does something to harm your organisation. This is uncommon, but can sometimes happen as part of revenge attacks or other forms of corruption.
The number of types of attacks that can occur from an insider is endless — from theft, to sabotage, and even physical violence, these can be hard to protect yourself against.
The best way to make sure that this isn’t a threat to you is to make sure to monitor staff and security and ensure that employees only have access to what they need to complete their tasks.
A man-in-the-middle (MITM) attack is when something is intercepting communications between two points. This can be either to collect information or possibly even sabotage the communication between two points.
This is an attack which is often not used due to the keyway to beat it — end-to-end encryption. End-to-end encryption is a must for any modern organisation, as it ensures that all data is transmitted between two points securely.
Cybersecurity knowledge is of utmost importance for any organisation looking to fend off any attackers and malicious users. By educating yourself and your organisation on these threats, you can ensure that your organisation is prepared and protected going forward.
There are software and tools available to help counteract cyber-attacks, and they can be a huge help in keeping your organisation secure. If you’re looking to get started with security tools, get in touch with us today. We’ll be able to help secure your organisation and ensure that your security posture is unbreakable.

Publish Date
04/09/2024
Categories
Blogs
In today’s digital age, email has become the backbone of business communication. With an astounding 361.6 billion emails sent and received daily—a figure projected to reach 392.5 billion within the next two years—it’s clear that email is indispensable in our professional lives. However, this massive reliance on email also presents a significant drawback: it has become the preferred entry point for cybercriminals aiming to infiltrate sensitive data, often leading to devastating consequences for businesses.
The email security landscape is deteriorating rapidly as cyber threats become increasingly sophisticated. Alarmingly, over 90% of cyberattacks begin with a simple email, with many attacks cleverly designed to bypass standard defenses like Microsoft’s. As cybercriminals up their game, it’s critical that businesses also strengthen their defenses.
At the forefront of this battle against email-borne threats is Mimecast, a leader in email security solutions. Recognizing the escalating dangers, Mimecast is harnessing the power of artificial intelligence to fortify its defenses with the new Mimecast Email Security Cloud Integrated (CI) solution. This cutting-edge tool is specifically designed to enhance and extend the protective capabilities of Microsoft 365, making it a vital asset for any organization looking to bolster its email security.
Mimecast’s approach to email security is all about flexibility and effectiveness. Whether a business requires advanced administrative controls for a complex email environment, or a quick-to-deploy solution optimized right out of the box, Mimecast delivers top-tier security tailored to meet diverse needs.
In a world where remote work has become the norm, employees and organizations are more vulnerable to email-based cyberattacks than ever before. Business Email Compromise (BEC) and other sophisticated threats are now rampant, as cybercriminals exploit the distractions and less secure environments of remote workers. With workers logging in from various locations—be it home, hotels, or coffee shops—sometimes even using personal devices, the risk of inadvertently opening a malicious email or clicking a harmful link has never been higher.
For IT and security teams, the challenge of securing email has never been more daunting. With attack volumes and sophistication on the rise, businesses need solutions that are both robust and easy to manage. Mimecast’s newest offering, Email Security CI, is an integrated cloud solution that enhances Microsoft 365 protections without requiring an MX record change. It deploys in just minutes and offers out-of-the-box optimization, making it an ideal choice for teams seeking to simplify their email security management while ensuring comprehensive protection.
Mimecast’s Email Security CI solution provides organizations with world-class security without forcing them to choose between different protection strategies. Whether a business opts for a secure email gateway or an integrated cloud email security approach, Mimecast ensures that their email remains secure against even the most advanced threats.
In a world where remote work has become the norm, employees and organizations are more vulnerable to email-based cyberattacks than ever before. Business Email Compromise (BEC) and other sophisticated threats are now rampant, as cybercriminals exploit the distractions and less secure environments of remote workers. With workers logging in from various locations—be it home, hotels, or coffee shops—sometimes even using personal devices, the risk of inadvertently opening a malicious email or clicking a harmful link has never been higher.
Organizations across all sectors and regions must prioritize email security to protect their data, their reputations and bottom lines. The stakes are high, and the consequences of a successful cyberattack can be catastrophic, potentially leading to financial loss, reputational damage, and in the worst cases, job losses.
It’s clear that the challenges in email security will only continue to grow. To help businesses stay ahead of these threats, Cobweb & Mimecast are jointly hosting an exclusive webinar on Wednesday, September 25th at 3 PM GST. Titled ‘Email Security 2024 – Threats & Cost-Effective Solutions,’ this webinar will delve into the most pressing cyberthreats targeting email and provide actionable insights on how to keep your business secure.
During the session, you’ll discover:
Attendees will also have the opportunity to access a free 30-day trial of Mimecast’s email protection and pose their most pressing security concerns to Mimecast’s experts.
Don’t miss out on this opportunity to strengthen your organization’s email security. Sign up below and take the first step toward safeguarding your business.

Publish Date
04/09/2024
Categories
Blogs
Over time, as cybersecurity solutions have become more effective, low-effort, high-volume cyberattacks are no longer successful for bad actors. In 2021, Microsoft was able to block over 9.6 billion malware threats and more than 35.7 billion phishing emails.
This increase in effectiveness is in part due to the advancements in AI technology used within modern cybersecurity solutions. This allows them to stop zero-day exploits and reduce the chance of businesses falling victim to a variety of attacks.
However, as these low-effort attacks are no longer viable for cybercriminals, some have shifted their focus away from targeting technology to hacking humans. These are known as social engineering attacks. In this blog, we will explore some key social engineering tactics, find out what is at risk if your business falls victim to one of these attacks, and what steps you can take to reduce your cyber risk.
Social engineering attacks are a broad category of cyberattacks that include some form of psychological manipulation to trick employees into sharing confidential or sensitive information. These attacks rely on human interaction and can be conducted via email, phone call, SMS, instant messaging or in-person communication.
Whilst a well-crafted social engineering attack does take time and expertise, they are a common method for cybercriminals, as it is easier to exploit vulnerabilities within humans than in software. For example, it is much easier to trick an employee into sharing their password, rather than brute forcing a password. Did you know that an 8-character password has over six quadrillion possible combinations?
The first stage of any social engineering attack is investigation. In order to craft an attack, the bad actor needs to have an understanding of the target organisation and employee. This stage is also known as open-source intelligence (OSINT) gathering, as the collection of data is gathered from publicly available sources. Some of these sources include public social media accounts, Google Maps images of office spaces, company websites and viewing EXIF data from images.
Once the bad actor has researched their target, the next stage begins, the hook. This is when the cybercriminal engages the target and starts manipulating them into forming a relationship or trusting them. A common method to develop this trust is reciprocity, whereby the bad actor gives the target some information or does a favour for them, knowing that in the future the victim will be more likely to reciprocate and share sensitive information.
Once the cybercriminal has been able to expand their foothold, they can execute the attack. This may include a phishing attack, credential theft, planting of malware or physically entering an office space. Depending on how effective the investigation and hook were, the target may not even realise they are under attack.
If this is the case, the final stage is to exit. This is where the cybercriminal removes traces of malware, covers their tracks and ends their relationship with the target individual.
To illustrate the potential fallout from a social engineering attack, and some of the common forms of attack, we have 3 recent examples.
In late 2021, email security provider INKY detected several phishing emails that were impersonating the United States Department of Labor (DoL). The phishing emails targeted stakeholders, asking them to submit a bid for a government project.
In order to ‘submit the bid’ they had to open the attached PDF and click the ‘BID’ button. This took the victim to a malicious website, with the same HTML and CSS as the real DoL website. From here, they were prompted to log in with their Microsoft 365 credentials, and upon submission, the hacker was able to harvest all the credentials, without the victim even knowing.

In 2019, the CEO of an unnamed UK-based energy firm was contacted by who they thought was their boss, demanding a €220,000 bank transfer to a Hungarian supplier. The call did not raise suspicion for the CEO, as the person on the other end of the phone had the same accent and intonation as his German boss. However, this was not the case, as it is believed that the voice on the other end of the phone was an AI-based voice generation software.
The attack was successful, and the money was transferred to a fraudulent account. This is a prime example of a novel social engineering attack, as it was only successful as the attacker had previously researched the victim, and crafted the attack to manipulate the CEO.
A few years ago, a Lithuanian man crafted the largest social engineering attack of all time. He created a fraudulent company, pretending to be a computer manufacturer working with Google and Facebook. He then targeted specific individuals within those two companies, invoicing them for goods and services that a real manufacturer had provided.
Over 2 years, the man was able to fraudulently obtain over $100 million from Facebook and Google and was only caught 2 years after the attack.
It can be difficult to protect your business against complex social engineering attacks, especially as security solutions cannot supply 100% protection against many of the tactics used in these attacks.
With phishing emails being the most common form of social engineering attack, businesses should look for a holistic email security solution. This will block potential phishing emails, protect against malicious URLs, perform file analysis on attachments, and enable DMARC.
However, email security and phishing prevention will not stop vishing attacks, in-person attacks, or phishing attacks not carried out via corporate email. In order to safeguard against these attacks, businesses need to have a strong cybersecurity education and awareness training program. This will ensure that employees are aware of common social engineer attack methods, and how to detect and report them.
Finally, it goes without saying that all businesses should have multifactor authentication enabled. This simple control can stop 99.9% of account compromise attacks and does not take long to enable. With MFA, even if an employee shares their password with a bad actor, they will not be able to log in without the additional authentication method.
For businesses without security expertise, social engineering attacks can be difficult to protect against. Especially if your business does not already have a comprehensive cybersecurity awareness training program.
If you are concerned about your organisation’s security posture, contact us today and we can help ensure you’re doing everything you can to reduce your overall cyber risk.

Publish Date
02/09/2024
Categories
Blogs Hot Topic
While the internet has many benefits for modern businesses, there are also some issues to be aware of within the online space. With this, it’s vital to be aware of the malicious actions that a bad-faith actor can take to, at worst, damage your company.
Emails are one of the most vulnerable points at which your company could be in danger. With many different attacks and vulnerabilities involving social engineering, even a simple click on a link within an email could cause tons of damage. But some methods are more dangerous than others.
In this article, we’re going to go over the difference between spam emails and phishing emails, and how you can protect your business from them.
Spam email (or junk mail) is a type of email that is quite common online. In fact, you probably have at least some spams within your email ‘Spam’ folder right now.
These kinds of emails are simply just a form of mass marketing, that is used to advertise a service (whether it be a legitimate service or a scam) for sale to a large number of people with ease.
Email spammers tend to acquire their victims’ email addresses from a wide range of sources and constantly bulk-send advertisements to their list of emails, not caring about who’s on there.
Commonly, you’ll see spam emails advertising adult websites, gambling websites, and insurance websites. These are usually scams, though it’s incredibly easy to tell that these emails are spam and will be put into your email client’s spam folder automatically, so you don’t have to manually delete them.
However, even newsletters and other opt-in emails from legitimate places are seen as spam. Generally, spam is just unwanted/unsolicited emails, and there’s nothing inherently malicious about another email saying that there’s a sale at a clothes shop — even if they can be annoying.
Phishing is much more dangerous and malicious, however…
A phishing email is an email that is designed to intentionally deceive the recipient into giving access to an account or service. This social engineering scam is one of the most dangerous online attacks, as it takes advantage of unsuspecting or vulnerable people first and foremost.
Unlike low-effort spam mail, these emails are designed to trick unsuspecting victims into handing over sensitive information such as passwords, bank information, and even administrative access to a business system in the worst case.
The key to phishing scams is that they look legitimate at first glance and are designed to trigger the recipient to panic. They’ll often say something like “Your account has withdrawn £1294.90” and look deceptively similar to an email from a bank — in the example of a bank phishing scam — and will redirect you to a fake login portal to try to get you to enter your bank login.
These emails are easy to spot to the trained eye — as we’ll go over further on — but even those who are experts can be tricked. For example, famous cybersecurity expert and scam exposer Jim Browning fell victim to a very realistic-looking phishing attack that temporarily restricted access to his whole YouTube channel.
This video is his recounting of the scam, and is a great example of the types of high-level phishing attacks that you may encounter:
With these attacks becoming harder to spot every day, it’s important to educate yourself on how to stop them. To do so, you need to know the key differences between general spam and phishing.
Otherwise, there isn’t much of a difference between the two, as phishing is generally considered to be a type of spam email. However, while spam is usually annoying and harmless, phishing is deadly and dangerous.
There are several steps that your business can take to protect itself from spam and (more importantly) phishing.
1) Recognise the Signs of a Phishing Attack
Phishing attacks will often have some telltale signs that will be able to signal to you that they’re coming from a malicious source.
Generally, when using your judgement, be suspicious of any email you receive in general. Make sure to do the correct research before taking action.
2) Ensure Company-Wide Training and Security Compliance
It’s great that you know the signs. But, if your employees don’t, they could fall victim to an attack without knowing.
By ensuring that everyone is prepared and knowledgeable about the risks of phishing, you protect your company.
3) Implement System-Wide Measures to Protect Your Company
Even with all of this, humans make mistakes. Sometimes, you’ll click a bad link by accident. Ensuring that there are systems in place for this is important.
With the looming threat of phishing and spam being a serious consideration for any business, knowing how to protect yourself is vital for the success of any business. Knowing the key risk factors and threats that could put your business in danger is important, as acknowledging these risks is the best way to stop them.
Are you looking to implement securities and strengthen your company’s vulnerability against social engineering attacks? Get in touch with us today! Our experts are here to help and can easily make sure that your company has every base covered.