Just one of the 50 biggest federal IT contractors have adopted an important email security measure to guard against phishing, according to a new study. The Global Cyber Alliance’s (GCA) survey of the who’s who of Beltway contractors, including Lockheed Martin, Booz Allen Hamilton, and AT&T, found that all but one – analytics firm Engility, failed to use the Domain-based Message, Authentication, Reporting and Conformance (DMARC) protocol to block phishing attempts. Only one other contractor, the engineering firm and consultancy Tetra Tech, was implementing the second-highest DMARC control, in which phishing emails are quarantined. Meanwhile, more than half the contractors had yet to implement any DMARC policy whatsoever, according to the study. Phishing is one of hackers’ favorite tools for breaching a network, and the federal government has been trying to defend against it for years. DMARC fights phishing by creating a public record for checking whether an email sender […]
The post Fed contractors aren’t using DMARC, new study finds appeared first on Cyberscoop.
Continue reading Fed contractors aren’t using DMARC, new study finds→