Common E-mail Security Mistakes
These five bad habits can make your confidential information -- and that of your clients -- easy to steal
While e-mail is one of the most widely used business applications, it isnt a secure way to communicate, so the messages you receive every day are also a potential threat to your confidential and sensitive business information.
To help you protect your and your clients confidential information -- and to help you stay in compliance with state and federal regulations secure messaging solution developer Nveloped put together this list of common e-mail security mistakes.
Traditional e-mail isnt secure and does not have safeguards to protect your data or your clients data. And sending separate e-mails with password information doesnt provide more security -- its just as easy to intercept that message with the password.
Clicking a link or opening an attachment in an unexpected e-mail message can infect your computer or your business systems with malware. If you receive an unexpected message that asks you to take some action (for example, Click here to confirm your account details), check with the sender to verify that they sent the original message to you.
Also, in most e-mail clients, the link address shows up at the bottom of the window when you hover your mouse over the link. Thats a good way to verify whether the link is safe. If the sender and link address dont match up, its a good idea to check with your IT staff to confirm that the message is legitimate.
Your password is the most direct way for someone to get into your e-mail account, so choosing a password that is complex (not password) and keeping it safe is extremely important. Many organizations now implement password policies that require a certain level of password complexity and periodic changes, but users also need to avoid writing down their passwords on sticky notes or posting them in their office where others can see them.
In most e-mail clients today, there is a way to verify that the message actually came from the listed sender. In Gmail, for example, you can click on the small triangle next to the senders name, and it will show what e-mail server delivered the e-mail message. Messages that dont have this information arent necessarily bad or untrustworthy, but you should be a bit cautious before clicking the links because the message sender has not been authenticated.
There are many instances where an organization wants to communicate securely, but the partners they work with outside their organization continue to send information in a non-secure way. If you arent asking the other people and organizations with whom you communicate to also protect your sensitive data, it may still be at risk because your partners dont have the right safeguards in place.