Are you wondering how the DarkBeam platform can be used as part of your organisation’s regular cyber health check in order to prevent a cyber-attack? Read this case study of an organisation who left it too late.
By: Phil Gladwell
News, info & events

A missed opportunity
Imagine a situation where one of your employees is working on a laptop, or PC, and as they’re doing so there is an unknown person monitoring their every move; recording their every mouse click, every website they visit, and more importantly every keystroke they make. This includes their usernames and passwords to your organisation’s systems and databases.
The unknown person watching them type, studying their working practices, and getting to know your organisation’s tools, methods and procedures is not part of your management team. They are a hostile attacker who a few weeks prior sent a well crafted spear phishing email to your employee encouraging them to click on a link. One single click on that link has allowed a bad actor into your network to embed a keylogger virus. The attacker now has all the access they need, and on a large scale are harvesting your confidential material, your client database – including logins and passwords – and have free rein to disrupt your service. It may be months before you even know you’ve had an intrusion, by which time it’s too late. The damage is done, your reputation has taken a hit, and you are of course considering the financial penalties under GDPR.
For the attacker to successfully have mounted this attack they started by conducting hostile reconnaissance against your organisation. They surveyed your organisation’s security posture, examined your organisation’s digital footprint, and selected their target. They then registered a domain that looks very similar to your organisation’s domain, possibly with just one letter wrong or missing, or perhaps more ominously only created a mail server that looks remarkably similar to your domain. The attacker has then crafted a bespoke email to your employee having found their email address exposed online, and with the research they have conducted against you they have peppered their email with pertinent facts that at first glance makes the email seem genuine. Their email compels your employee to urgently click on the link, and that’s all it took. One click and the attached malicious software was active.
This is not always a hypothetical situation
Sadly for many organisations this is not simply a thought experiment, but a harsh reality. We were recently approached by one such company. Following the cyber intrusion, DarkBeam’s application conducted a non-obtrusive assessment of the organisation’s digital exposure and cybersecurity posture. In less than one minute the application had surfaced critical information for over 55 elements across 7 categories. Included in this information was a list of exposed email addresses found on the open web, as well as potential breached email addresses, critical issues with SSL certificates and therefore HTTPS. Crucially, included within the information surfaced, was a list of live domain permutations. Having generated a list of potential close match domain names, DarkBeam tests this list for live domains and mail servers. Live matches are surfaced to the user. In this instance the domain that sent the hostile email was identified by the DarkBeam platform.
How can DarkBeam prevent this situation?
If the DarkBeam application had been used prior to the attack, as part of the organisation’s regular cyber health check, the exposed email addresses could have been identified. SSL certificates could have been corrected, employees could have received accredited cyber awareness training, and – potentially most importantly in this case – the list of live domain permutations could have been blacklisted, therefore prohibiting the malicious email from ever reaching your employee.
The DarkBeam platform has been built by former military and police intelligence personnel, and designed to be used as a preemptive defence against an ever-increasing and constantly mutating cyber threat landscape. The DarkBeam platform is more affordable than you might think – for just £200+ VAT you can understand your cyber exposure and vulnerabilities, and therefore make intelligence lead decisions around taking mitigating action and improving your cybersecurity defences.
For more information regarding the DarkBeam platform and how it can help protect your business contact us today.