Information Security

9 articles

Gmail Emails Going to Spam? Prevent Spoofing | Complete Beginner's Guide

Imagine if an important business message or a newsletter you put your heart into creating ended up in the recipient’s “Junk” folder. In fact, this problem is almost always caused not by the content of the email, but by the sender domain authentication configured in the DNS (Domain Name System). The DNS is a system that links domains to servers on the Internet, and it also serves as the foundation for determining the reliability of emails. In February 2024, Google significantly strengthened its sender guidelines. Businesses sending more than 5,000 emails per day are now required to implement all three of the following: SPF, DKIM, and DMARC. Furthermore, starting in January 2025, NTT Docomo will begin gradually displaying “spoofed email warnings” on emails that do not have sender domain authentication enabled. We are now entering an era where emails with incorrectly configured DNS settings simply won’t be delivered. However, there are likely quite a few people who are thinking, “SPF? DKIM? DMARC? What are those? I don’t really understand.” In this article, we’ll provide a thorough explanation of how these three technologies work, how they differ, and how to configure DNS—all presented in a way that’s easy to understand even for those with zero technical knowledge. Why is “sender domain authentication” necessary right now? Damage caused by phishing emails is increasing year by year, leading to financial losses for companies, data breaches, and even damage to their brand reputation. The sender domain authentication technologies known as SPF, DKIM, and DMARC are designed to counter these threats. SPF is a mechanism that verifies whether the sending server is legitimate. DKIM applies a digital signature to emails to verify “whether the email is a spoof” and whether the content has been tampered with. DMARC is a policy that determines how to handle emails that fail SPF or DKIM authentication based on the results of those checks. By configuring these technologies properly, you can significantly reduce the risk of spoofed emails. Let’s take a closer look at their importance. The Current State of Phishing Emails In recent years, damage caused by “phishing emails”—which impersonate real companies or individuals—has surged. There are cases where emails posing as business partners infect recipients with malware (a general term for software created for malicious purposes), leading to the leakage of personal information, or where emails instructing recipients to transfer funds to fake bank accounts result in financial fraud. What makes spoofed emails so sophisticated is that, from a technical standpoint, the “From” address can be freely altered. Attackers impersonate legitimate company domains to send emails that appear completely legitimate at first glance. It is extremely difficult for humans to distinguish these from genuine emails, which is precisely why incidents continue to occur. Furthermore, phishing emails pose a direct risk of brand damage. If your company’s domain is misused to send large volumes of phishing emails, it could significantly erode recipients’ trust. Furthermore, this could cause legitimate emails to be filtered into the spam folder, potentially disrupting important communications with customers. Impact of Gmail Sender Guidelines In February 2024, Google strengthened its “Sender Guidelines.” The guidelines are summarized as follows: Mandatory for all senders: Compliance with either SPF or DKIM. High-volume senders (5,000 or more emails per day): Compliance with all three—SPF, DKIM, and DMARC. Failure to comply may result in emails failing to reach Gmail users. Furthermore, in practice, DKIM is becoming virtually mandatory even for non-high-volume senders, as emails without DKIM are highly likely to be flagged by Gmail’s spam filter. [Reference] Gmail, “Guidelines for Email Senders”; NTT Docomo’s “Phishing Email Warning” Starting in January 2025, NTT Docomo began gradually displaying “phishing email warnings” for emails that do not comply with sender domain authentication. For businesses that send emails to individual users, compliance has become an urgent priority. [Reference] NTT DOCOMO, “Spoofed Email Warning Display” Return to Table of Contents How Are Emails Sent? (The Basics) To understand sender domain authentication, the first thing you need to know is the difference between the “Envelope From” and the “Header From.” The mechanism of email is easiest to understand by comparing it to the relationship between an envelope and a letter. Envelope From (Sender on the Envelope) This is the sender for delivery purposes. In postal terms, it’s the name written on the envelope. It is not displayed on the recipient’s screen. Header From (Sender in the Header) This is the sender displayed on the screen. The “sender information” we see on our email inbox screen refers to this one. Spammers exploit this. The Basic Structure of Email (Envelope From and Header From) Even if the sender on the envelope and the sender of the letter are different, the email will still be delivered. It’s also possible to change only the name that is displayed. For example, an email can be sent from one location while appearing to come from “info@大手銀行.co.jp.” This is the technique used in spoofed emails. SPF, DKIM, and DMARC are mechanisms designed to prevent this problem. For now, just remember that “there are two senders.” Back to Table of Contents What is SPF? (A Mechanism for Verifying the Sender’s IP) The first step in preventing spoofing is SPF. This is a mechanism where you register the servers authorized to send emails from your domain with DNS. When Gmail receives an email, it verifies whether the sender is legitimate. Let’s start by understanding this “sender verification” mechanism. Basic Concepts of SPF SPF (Sender Policy Framework) is a system that allows you to pre-register in DNS which servers are authorized to send emails from a given domain. For example, you would pre-register information in the DNS such as, “Emails from example.com are sent only from the server with IP address 203.0.113.1 (*for illustrative purposes only).” The recipient checks whether the IP address of the server that actually sent the email is included in that registered list. If the email is sent from an IP address not on the list, it can be judged as “potentially spoofed.” How SPF Works The SPF verification process follows these steps: The sender sends the email. The receiving server records the IP address of the server from which the email arrived. It queries DNS using the domain in the envelope “From” field (e.g., example.com). It compares the SPF record in the DNS TXT record with the actual sending IP address. If they match, the result is “SPF authentication successful (Pass)”; if there is a mismatch, it is judged as “Fail/SoftFail.” How SPF Works: The receiving server references DNS to verify the IP address. How to Read SPF Records (Reference) The actual SPF record is written in a DNS TXT record as follows: v=spf1 include:spf.google.com ip4:203.0.113.1 ~all Meaning of each element v=spf1: Declaration of SPF version 1 include:spf.google.com: Allow messages sent from Google’s mail servers (when using external services such as Gmail) ip4:203.0.113.1: Permits sending from this IP address ~all: Treats anything other than the above as a “SoftFail” (warning) (-all results in a complete rejection) The difference between ~all and -all lies in the severity of the response to an SPF failure. While -all (HardFail) recommends complete rejection, it is often recommended to start with ~all and monitor the situation, as legitimate emails may be falsely flagged when forwarding messages. Limitations of SPF Reading this far, you might think, “If I configure SPF, I can prevent spoofing.” However, SPF alone is not sufficient. In fact, SPF has structural weaknesses that are simply unavoidable. Does not verify the “From” header: SPF verifies the envelope “From” (the sender on the envelope). It does not verify the “From” header displayed in email clients (the sender of the message). In other words, SPF alone cannot prevent spoofing where the “Envelope From” is set to the legitimate domain, but the “From” header is forged. Cannot Handle Forwarding When an email is forwarded, the IP address of the forwarding server becomes the new “sender IP.” However, since the forwarding server’s IP is not registered in the SPF record, SPF authentication fails even though the email is legitimate. DKIM, which we’ll explain next, was introduced to address these weaknesses. Back to Table of Contents What is DKIM? (Digital Signature for Tamper Prevention) If SPF is a mechanism for verifying the “sending server,” the next step is a mechanism to verify whether “the email itself is authentic.” This is where DKIM comes in. Basic Concept of DKIM If SPF is a “list of authorized sending servers,” then DKIM is a “seal of authenticity.” The concept of DKIM is similar to affixing a company seal to an important document. The sender applies an “electronic signature” to the email, and the recipient verifies that signature to confirm that “this email was created by the genuine sender and has not been tampered with in transit.” How DKIM Works DKIM is a mechanism for applying an “electronic signature” to emails. While SPF verifies the sender’s IP address, DKIM verifies whether “the email was sent from a legitimate source (not a spoof)” and whether “the email’s content has not been tampered with.” DKIM operates using digital signatures based on public-key cryptography. The sender’s process is carried out as follows: Calculate a hash value from the email’s contents (headers + body). Encrypt the hash value with a private key to create a “signature.” Add the signature to the email as a DKIM-Signature header and send it. * A hash value is a fixed-length string generated by applying a special calculation (a hash function) to data; it is produced through a one-way (irreversible) transformation that cannot be reversed. The recipient’s process is carried out as follows: Retrieve the signing domain (d=) and selector (s=) from the DKIM-Signature header. Retrieve the public key from DNS. Decrypt the signature using the public key to extract the hash value. Verify that it matches the hash value of the received email body. *d= (signing domain) refers to the domain name that signed the email. This means “This domain is responsible.” *s= (selector) is the name (identifier) used to locate the public key. It allows a single domain to use multiple keys. How DKIM Works: Detects email tampering using digital signatures based on public-key cryptography. If the values match, “DKIM authentication succeeds,” confirming that the email has not been tampered with and was created by the authentic sender. Contents of the DKIM-Signature (for reference) The DKIM-Signature actually added to the email header has the following structure: DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=example.com; s=google; …omitted… bh=hash value; b=signature data Main parameters d= (domain): The domain that performed the signature. Important values used for DMARC alignment checks: s= (selector): The key used to look up the public key via DNS. a= (algorithm): The signing algorithm (rsa-sha256 is common). What is a selector? A selector is an identifier used to distinguish between multiple DKIM key pairs within a single domain. For example, if d=example.com and s=google, the receiving server will look up the DNS record google._domainkey.example.com to retrieve the public key. This allows you to manage multiple email services using separate selectors. Mechanism for Using Different Keys Across Multiple Services Limitations of DKIM It is often assumed that if SPF and DKIM are configured, “spoofing protection is complete.” However, DKIM also has weaknesses. Replay Attacks: DKIM cannot prevent “replay attacks,” in which a malicious third party intercepts an email with a valid DKIM signature and resends it to a different recipient. No Policy Control on Its Own: While DKIM verifies authenticity, it does not define policies for how to handle emails that fail authentication. DMARC handles the response to authentication failures. DKIM is a mechanism for verifying “authenticity.” However, it cannot determine how to handle emails that fail authentication. That role is fulfilled by DMARC, which we’ll explain next. Back to Table of Contents What Is DMARC? (The Command Center That Makes the Final Decision) SPF and DKIM now allow us to verify the “sender” and “whether the message has been tampered with.” But what happens to an email if either of these checks fails? DMARC is responsible for making that final decision. The Role of DMARC DMARC (Domain-based Message Authentication, Reporting, and Conformance) is the command center that receives the “results” from SPF and DKIM and determines how to handle emails that fail authentication. DMARC has the following three roles. Final Determination: It comprehensively assesses the authenticity of an email by combining the SPF and DKIM authentication results with alignment (discussed later). Policy Declaration: Specifies how the receiving server should handle emails when authentication fails. Receiving Reports: Allows you to receive aggregated reports showing who is sending emails from which domains. DMARC Policy: A DMARC record is a “rule for handling email” configured in DNS. It is displayed as follows: v=DMARC1; p=none; The “p” in the DMARC record stands for “policy” and specifies how to handle emails that fail authentication. Three Policy Levels DMARC allows you to set three policy levels. Policy Meaning Recommended Use none Monitoring only. Does not affect email processing. Initial investigation and monitoring phase. quarantine Sorts emails that fail authentication into the spam folder. Intermediate stage. reject Completely rejects emails that fail authentication. Full-scale operation. Reasons for a Phased Implementation You should not set DMARC to “reject” right away. There are two reasons for this. First, if you set the policy to “reject” without fully understanding all legitimate email delivery paths, even legitimate emails sent from newsletter services, internal systems, and external applications will be rejected. Second, if you set the policy to “reject” while SPF and DKIM configurations are incomplete, a large number of legitimate emails may be rejected. Recommended Steps: Start monitoring with `p=none` (use DMARC reports to identify sending paths). Once SPF and DKIM are configured for all paths, transition to `p=quarantine`. If no issues are found, escalate to `p=reject`. An important concept called “alignment” is involved in DMARC decisions. Next, let’s take a closer look at how this works. Return to Table of Contents What Is DMARC “Alignment”? So far, we’ve examined how SPF, DKIM, and DMARC work. However, there are cases where “authentication succeeds but DMARC fails.” The cause of this is alignment mismatch. Why Is Alignment Important? Alignment is a mechanism that verifies whether the domain used for authentication matches the sender (From) displayed on the screen. DMARC performs this check against both SPF and DKIM. SPF Alignment: SPF verifies the domain of the “envelope From” (Envelope From). DMARC checks whether the domain that passed SPF authentication matches the displayed “From” (Header From) domain. DKIM Alignment: DKIM verifies the “d=domain” included in the signature. DMARC checks whether the DKIM signature was successful and whether that “d=domain” matches the displayed “From” (header “From”) domain. The Difference Between “Relaxed” and “Strict” “Relaxed” and “Strict” are settings that determine the strictness of the alignment (domain match) check. They are specified within the DMARC record. “Relaxed” is a lenient check that allows subdomains, while “Strict” is a strict check that permits only exact matches. Unless there is a specific reason, using “Relaxed” is generally sufficient. DMARC is Valid if Either Condition is Met It is important to note that DMARC is considered a “PASS” (successful) if either the SPF alignment or the DKIM alignment passes. This means that even in cases where SPF authentication fails—such as when emails are relayed—DMARC will still pass as long as DKIM alignment passes. That is why it is crucial to “configure both SPF and DKIM.” Illustrated Guide to How DMARC Works Return to Table of Contents Frequently Asked Questions Here, we address some frequently asked questions. Q. Why does it end up in the spam folder? A. If SPF or DKIM is not configured or is configured incorrectly, the recipient’s mail server will deem the sender “untrustworthy” and route the email to the spam folder. Gmail, in particular, strictly handles emails that are not DKIM-signed. Q. Can “display name” spoofing be prevented? A. SPF, DKIM, and DMARC cannot prevent “display name” spoofing. For example, even if the actual sender is evil.com, as in “Taro Yamada attacker@evil.com,” the display name in the email client can be spoofed to appear as “Taro Yamada.” Implementing BIMI (Brand Indicators for Message Identification) is an effective countermeasure against display name spoofing. Q. Why does SPF authentication fail when an email is forwarded? A. When an email is forwarded, the forwarding server becomes the new “sender IP address.” However, since the forwarding server’s IP address is not registered in the original sender’s SPF record, SPF authentication fails. To work around this, the “SRS (Sender Rewriting Scheme)” mechanism rewrites the envelope “From” field during forwarding to ensure SPF authentication passes. DKIM is resistant to forwarding because the signature remains valid as long as the email body and headers are not altered during forwarding. Back to Table of Contents Summary In this article, we explained the mechanism of “sender domain authentication,” which is a common cause of emails ending up in the spam folder. SPF (Sender Policy Framework): A mechanism that declares the sender’s IP address via DNS to detect spoofed emails. While configuration is relatively simple, it has the limitation that it does not verify the “From” header, so there are cases where emails fail authentication due to forwarding. DKIM (DomainKeys Identified Mail): Uses digital signatures to verify the authenticity of an email and ensure it has not been tampered with. It is robust against forwarding and can also verify the “From” header domain. DMARC (Domain-based Message Authentication, Reporting, and Conformance): A mechanism that uses the results of SPF and DKIM to declare how to handle authentication failures (none/quarantine/reject) and receive reports. It is considered valid if either SPF or DKIM alignment passes. These three work together as a set. Each one alone is insufficient; only when combined do they form a robust sender domain authentication system. Start by “configuring SPF and DKIM” and “beginning DMARC monitoring with p=none.” Check out learningBOX’s feature list and pricing table now! Download materials ▼ You might also like! Related articles
blog

Protect against the Security Risks of Remote Working

Due to the spread of the novel coronavirus in 2020, telecommuting and remote work have become common ways of working. While many companies have not yet implemented telecommuting, there are likely many that are currently considering whether to do so in the future. When companies implement telecommuting, information security measures are essential. To prevent problems within your own company, it’s important to thoroughly understand these security measures. In this article, we’ll explain why information security measures are necessary for telework. We’ll also introduce the benefits of implementing telework and specific examples of security measures, so if you’re considering implementing telework, be sure to read this article to the end. The Need for Information Security Measures in Telework and Potential Risks While an increasing number of companies are adopting telework, many are facing challenges in ensuring security. According to a survey by the Ministry of Internal Affairs and Communications, 47.6% of responding companies stated that “ensuring security was a challenge when introducing telework.” [Source] Ministry of Internal Affairs and Communications, “Second Survey on the Actual State of Telework Security.” Failing to implement security measures when conducting telework can lead to various risks. To prevent financial losses to your company, it is important to understand the potential risks. There are four primary risks. Loss or Theft of Devices: When implementing telework, it is common for companies to provide laptops to employees. While there is little concern about device loss or theft when working from home, employees must be vigilant against such incidents when working in coworking spaces or similar locations. If a device contains customers’ personal information or other sensitive data, its loss or theft can lead to serious problems. Data Breaches: When working from home or at coworking spaces, employees typically use internet connections different from those in the office. Since security strength varies by connection, using a connection with weak security poses a risk of data breaches. Malware Infection: Devices provided in the office are generally equipped with antivirus software. However, it is not uncommon for devices used by employees for personal purposes to lack antivirus software. As a result, the risk of infection by malware, such as malicious viruses, increases. Communication Interception and Eavesdropping: Extra caution is required when using public Wi-Fi at places like cafes. Since free Wi-Fi is accessible to anyone, there is a risk that communications could be intercepted. In some cases, there is even a risk of eavesdropping, so it’s essential to exercise the utmost caution when using free Wi-Fi. Back to Table of Contents With the Right Information Security Measures in Place, Telework Offers Many Benefits! Although telework poses security risks, it also offers benefits for both employees and companies. Specific benefits are listed below. Reduced Commuting Time For employees, commuting time is a major source of stress. In particular, riding on crowded trains can be extremely stressful. If a company implements telework, employees will no longer need to commute and can use the time they save more productively. Additionally, this can lead to improved work efficiency. Preventing Employee Turnover: By creating an environment where employees can work from anywhere, companies can broaden their talent pool—for example, by recruiting people living in rural areas. Furthermore, there are cases where employees leave their jobs because commuting becomes difficult due to reasons such as raising children or caring for family members. If such employees can work remotely, it is possible to prevent them from leaving the company. Other benefits include cost savings from reduced office space and commuting expenses. Return to Table of Contents Examples of Information Security Measures for Remote Work When implementing remote work, it is essential for companies to implement security measures. Here are seven specific measures. Establishing Security Guidelines One effective approach is to establish security guidelines that clearly outline what the company expects employees to prioritize. It is crucial to formalize the key principles employees should keep in mind while performing their duties and ensure all employees are fully aware of them. Note that security guidelines are not set in stone once established; their content should be updated as circumstances change. Implementing Security Software: While formalizing guidelines is effective, another approach is to implement software that can provide additional security protection. If a device becomes infected with a virus, it could result in significant losses for the company. To prevent the worst-case scenario, be sure to install security software on all devices used for work. Strict Password Management: It is crucial to set passwords that are difficult to guess when entering them during work. Passwords such as birthdays, names, or consecutive numbers are easy to guess and can lead to unauthorized access. Therefore, we recommend setting strong passwords that combine letters and symbols. Promoting a Paperless Environment: While paper documents are easy to carry, they also carry the risk of theft or loss. If paper documents are stolen or lost while you are out of the office, it could lead to irreparable consequences. To eliminate the drawbacks of paper documents, it is essential to promote a paperless environment. Encryption of Personal Information: If your organization handles large amounts of personal information, be sure to encrypt the data itself. In companies that use cloud-based applications, employees may access personal information through these apps. Encrypting the data in advance helps protect against unauthorized access. Regular OS and App Updates: Since updates for operating systems and apps are released daily, be sure to install them as soon as possible. Update programs often include fixes for vulnerabilities. Failing to update leaves the system in a state of high security risk, so prompt action is essential. Implementing Security Training: Among the various security measures available, conducting security training is recommended to help employees understand the necessity of these measures. Security training curricula are often designed to cater to individuals with low security literacy. By taking the time to share case studies of information security incidents with employees, you can help them recognize the importance of security measures and aim to raise the overall level of security literacy throughout the organization. Back to Table of Contents Summary In this article, we discussed why information security measures are essential for remote work and provided examples of such measures. While remote work involves various security risks, it also offers many benefits. To promote diverse work styles and create a comfortable work environment, consider implementing remote work. When raising awareness about information security within your company, please make use of the information security training content available on “learningBOX ON.” learningBOX ON is a service that allows you to easily add essential corporate training content to learningBOX, an e-learning creation and management system. You can easily design original learning courses by combining this content with materials developed in-house. Content for information security and compliance training is available free of charge, so please make full use of it for your in-house training. ▼Also Recommended! Related Articles Return to Table of Contents
blog

Five ways to plan information security education│What is the purpose and necessity?

In today’s world, everyone involved in a company’s operations handles some form of confidential information, making information security training increasingly important. This is because even if hardware and software are properly maintained, a lack of security awareness among individual employees can lead to serious incidents caused by external attacks or human error. In this article, we will explain the necessity, objectives, and implementation methods of information security training. We will also introduce content and materials that will be useful for conducting training, so please use them as a reference. Basics of Information Security Training To protect companies from information security incidents caused by cyberattacks or mismanagement of information assets, it is crucial to conduct employee training aimed at strengthening security awareness. First, we will discuss the necessity, benefits, and objectives of information security training. The Necessity and Benefits of Information Security Training Thorough information security training for employees makes it easier to prevent data breaches before they occur. This is because data breaches caused by human error—such as “loss or misplacement,” “operational errors,” “management mistakes,” “configuration issues,” and “theft”—account for more than 60 percent of all incidents. This approach can also help mitigate risks such as liability for damages resulting from incidents and a loss of public trust. [Reference] “2018 Survey Report on Information Security Incidents” | Japan Network Security Association Return to Table of Contents Objectives and Roles of Information Security Training Ensuring Thorough Awareness and Compliance with Information Security Policies An information security policy refers to the guidelines for information security measures within a company or organization. It primarily outlines guidelines for conduct, plans and measures, as well as operational frameworks and regulations. To raise information security awareness within an organization, ongoing efforts and systems are necessary to ensure that all employees comply with the established policies. Possible methods include imposing penalties for violations, illustrating the potential harm to the organization, conducting tests to assess understanding, and strictly enforcing rules regarding the handling of personal information. Understanding Information Security Threats and Countermeasures In information security training, it is also important to share real-world examples to ensure employees comply with the established policies. For example, it is effective to explain online threats and the damage they can cause, basic countermeasures such as virus protection and vulnerability management, and the proper mindset for handling email and other tools. Return to Table of Contents: How to Systematically Plan Information Security Training Next, we’ll explain step-by-step how to implement information security training. Conduct information security training on a regular cycle to help improve your company’s information security literacy. Step 1: Set Training Objectives and Learning Topics Clarifying objectives from the outset makes it easier to ensure consistency in your efforts and results. Identify and organize past incidents and challenges related to information security within your company to help set these objectives. Additionally, by examining external case studies, you can anticipate risks that have not yet occurred but could arise in the future. Once you have set the objectives for information security training, determine the security knowledge and skills employees need to acquire to address these challenges, and select learning themes accordingly. Examples of learning topics include the following: Risks of information leaks; Confidentiality obligations; Types of confidential information; Threats posed by targeted phishing emails and countermeasures; Rules for using social media; The importance of managing information devices; Security risks associated with using cloud services and public Wi-Fi; The latest cyberattack techniques; Password management. Step 2. Selecting Training Participants Next, select the participants based on the training objectives and learning themes. Depending on the training content, you may determine the target audience by considering factors such as department, job title, role, and office location. Examples include full-time employees in the Sales Department and contractors involved in their operations, as well as full-time employees at the Tokyo office. Select all individuals involved in business operations as participants, regardless of employment status—including temporary staff, contract employees, part-time workers, and contractors. Step 3. Determine the Timing and Frequency of Training Next, determine the timing and frequency of the training to incorporate information security training into the schedule. Potential timing includes when new or mid-career employees join the company, when a security incident occurs at your company or another organization, or when internal policies change. The key is to conduct training at times when employee interest in information security is high. As for frequency, options include once a year, once a month, or once every half-year or quarter. Make your decision after considering the importance of the content and the frequency of personnel changes, and be sure to hold sessions regularly. Step 4. Select the Training Format and Prepare Content In the next step, consider the format for delivering information security training. Common options include in-person training, e-learning, and external seminars. Select the most appropriate method based on the training content, costs, and the participants’ level of literacy. E-learning is particularly recommended. This internet-based learning format allows learners to access an online server via a computer or tablet to take the necessary courses. Unlike in-person training, there is no need to gather participants in one location; as long as an internet connection is available, the content can be accessed anytime, anywhere, making it particularly suitable for companies that have adopted remote work. Once the training format has been decided, begin preparing the content. Create original materials or purchase existing content to ensure that participants can acquire the required knowledge and skills. With e-learning, depending on the service, it is possible to combine not only existing content but also materials produced in-house for delivery. Step 5. Conduct Follow-Up Based on Training Effectiveness Measurement After conducting information security training, measure its effectiveness through assessment tests and surveys. If the results indicate that certain employees have gaps in their understanding of information security, provide feedback and follow-up. Additionally, if your company has prepared its own training materials, it is important to review the content based on the results of the effectiveness measurement. Return to Table of Contents Content and Resources Useful for Information Security Training When conducting information security training, it is most efficient to combine external content and resources in a way that suits your company’s needs. Here, we introduce content and resources that can be utilized for information security training. IPA “Security Measures Guide” This is a document publicly available from the IPA (Information-technology Promotion Agency), which is under the jurisdiction of the Ministry of Economy, Trade and Industry. The IPA engages in activities such as human resource development aimed at strengthening competitiveness in Japan’s IT sector. It outlines specific security measures tailored to various purposes and situations—such as web conferences, remote work, and extended holidays—and is often used as training or handout material. [Reference] Security Measures Guide | IPA (Information-technology Promotion Agency) Ministry of Internal Affairs and Communications “Cybersecurity Site for the Public” The Ministry of Internal Affairs and Communications’ website provides content on cybersecurity measures for businesses and organizations. The curriculum is organized by role—such as executives, employees, and information management personnel—making it easy to implement company-wide information security training. All content is available for download as PDF files, so distributing these materials after training helps reinforce knowledge. In addition, videos are available for some courses, allowing participants to watch expert explanations repeatedly. [Reference] Cybersecurity Site for the Public | Ministry of Internal Affairs and Communications e-Learning Service “learningBOX ON” is a service that allows you to easily add essential corporate training content to “learningBOX,” an e-learning creation and management system. Another appealing feature is that you can use information security training materials free of charge and combine original materials with existing content for delivery. Back to Table of Contents: Promote Information Security Training to Build a Cyber-Resilient Company In this article, we explained the objectives and implementation methods of information security training. To reduce risks such as damage to a company’s reputation and liability for damages resulting from information security incidents, it is essential to enhance the security awareness of each and every employee. Implement information security training systematically to build an organization that is resilient to cyber risks. When raising awareness about information security within your company, we recommend the information security training content available on learningBOX ON. Compliance training content is also available for free, so please make full use of it for your in-house training. ▼ Also Recommended! Related Articles Return to Table of Contents
blog

How to Prevent Internal Fraud

“Internal misconduct”—in which personal information and information assets are leaked to outside parties by employees or contractors—continues to be a persistent problem. In recent years, even unintentional errors have sometimes been classified as internal misconduct. Even employees who believe, “I would never commit fraud,” may unintentionally become involved in internal misconduct. Therefore, companies must pay the utmost attention to internal misconduct and implement ongoing initiatives to raise security awareness within the organization. In this article, we will discuss the causes of internal misconduct and explain specific countermeasures. We encourage executives and HR professionals to use this as a reference. What Is Internal Misconduct? Internal misconduct refers to acts by individuals within an organization or company who remove, leak, delete, or destroy confidential company information or customer data. It also includes cases where information is inadvertently leaked. Security incidents resulting from information security violations can significantly damage a company’s reputation if reported in the media. In an era where the widespread use of social media and other platforms allows anyone to easily access information, every company needs methods to prevent internal misconduct before it occurs and implement effective countermeasures. In addition to data breaches, internal misconduct also includes embezzlement, illegal overtime, and unpaid wages. Return to Table of Contents: Background on the Focus on Countermeasures Against Internal Misconduct The amended Personal Information Protection Act came into effect in April 2022, making it mandatory for companies to report data breaches—a requirement that was previously only a “best-effort obligation.” Next, let’s examine the specific reasons why measures against internal misconduct are gaining attention. Society Perceives Internal Misconduct as a Threat A major reason for this focus is that society perceives internal misconduct as a threat. According to the IPA (Information-technology Promotion Agency)’s “Top 10 Information Security Threats 2020,” “information leaks caused by internal misconduct” ranked second in the organizational category. Precisely because it is perceived as a threat, it is not uncommon for companies to withhold public disclosure of internal misconduct even after it is discovered internally, out of fear that it will be reported in the media. Lack of Transparency in Contractors’ Security Measures Another factor is the lack of transparency regarding the security measures of business contractors. In the past, the following incidents have occurred as a result of organizations neglecting to oversee a contractor’s information management and outsourcing operations entirely: A contractor subcontracted the work to another company, leading to a leak of My Number information; an informational email was sent to the wrong recipients, resulting in the leak of email addresses for registered entities using related services; a USB drive containing residents’ personal information was taken without authorization by a contractor and later reported lost. If a company entrusts work to firms that underestimate the importance of information security or have not obtained third-party certification, there is a risk that such internal misconduct could occur. Furthermore, overseas contractors may not fully understand the risks of internal misconduct due to differences in culture and values, as well as security budget constraints. According to the “2015 Vormetric Insider Threat Report” by Vormetric, a leading provider of data security solutions, approximately 89% of overseas companies reported being vulnerable to internal misconduct. While outsourcing operations to third parties is an effective business strategy, companies must thoroughly manage security (including vendor management). Return to Table of Contents Types of Internal Fraud Internal fraud is not limited to information leaks or data breaches. The following actions may also be punished as internal fraud: Embezzlement Embezzlement is the act of misappropriating another person’s property that is in one’s possession in the course of business. Specific methods include the following: Misappropriation of Expenses Theft of Company Property Unauthorized Fund Transfers Personal Use of Company Credit Cards or Frequent Flyer Miles, etc. Internal misconduct is not limited to individual acts; it can also be carried out on an organizational level, involving senior management or external companies. Embezzlement of funds, regardless of the amount, can be considered an act that directly damages a company’s economic assets. Harassment: Harassment refers to the act of causing discomfort to another person through words or actions that go against their will. Specific types of harassment include the following: Power harassment, sexual harassment, maternity harassment, moral harassment, alcohol-related harassment, etc. Perpetrators of harassment often exploit their superior position, such as through hierarchical relationships or differences in status. A key characteristic of harassment is that it deals a blow to human resources, such as when employees who have been victimized are forced to take a leave of absence or resign. Violations of the Labor Standards Act Violations of the Labor Standards Act, such as unpaid overtime or unpaid wages, also constitute internal corporate misconduct. Violations not only damage a company’s credibility in the eyes of society but may also result in employees filing claims for damages. Furthermore, if a company refuses an on-site inspection by a Labor Standards Inspector or fails to submit a corrective action report, the case may be referred to prosecutors. Return to Table of Contents: Three Factors Leading to Internal Misconduct While we have touched on various forms of internal misconduct, information leaks have become a particularly serious concern in recent years. This can largely be attributed to the spread of remote work and social media. Corporate data breaches are caused by the following three factors: ① Technical Factors The first is technical factors. If a company’s internal information security is vulnerable, passwords may be compromised. This can allow employees who are not authorized to access information to do so, thereby increasing the risk of internal misconduct. Furthermore, some companies do not record activity logs. If a system is used that does not allow tracking of who accessed the information, it becomes difficult to detect or trace the path of the breach even if internal misconduct occurs, which can prolong the investigation. ② Human Factors (Intentional) The second factor is human behavior carried out with malicious intent. According to the IPA (Information-technology Promotion Agency)’s “Survey on Incidents Caused by Misconduct by Internal Personnel,” the factors contributing to internal misconduct include motives and pressures such as “being subjected to a dismissal deemed unfair” and “dissatisfaction with salary or bonuses.” It can be said that companies with dissatisfied employees are more prone to intentional information leaks. ③ Human Factors (Human Error) The third category involves human factors resulting from mistakes. This includes operational errors when handling information, as well as the loss of files or USB drives. Possible reasons for human error include a lack of knowledge or experience on the part of the individual involved, or being assigned tasks that exceed their capacity. Return to Table of Contents Specific Measures to Prevent Data Leaks What measures can companies take to prevent internal misconduct? Here, we will examine various specific countermeasures. Strengthen Internal Monitoring To prevent corporate data leaks before they occur, companies should strengthen their monitoring. Specifically, the following security enhancements are recommended: Managing entry and exit logs Managing records of device removal Sending security alerts Managing and monitoring access logs Detecting unauthorized access, etc. When strengthening internal monitoring, it is crucial to establish rules for mutual monitoring and distribute authority so that it is not concentrated in the hands of specific employees. Strengthening internal monitoring not only prevents employee misconduct but also reduces the burden on system administrators. Use an Internal Misconduct Checklist Creating checklists to verify whether important information is being managed and operated correctly, and whether employee training is being conducted appropriately, is also effective. If creating one in-house is difficult, you may download an externally provided checklist, such as the IPA’s “Guidelines for Preventing Internal Fraud in Organizations.” By actually listing and verifying items, you can conduct a fact-finding survey and identify areas where your company’s security needs to be strengthened. Reducing the Burden on Employees It is also important to consider ways to reduce the burden on employees. The busier the front lines are, the less time there is to conduct information security training for employees due to staff shortages. Rather than holding large-scale training sessions a few times a year, it can sometimes be more effective to create an environment where employees can participate in short, regular sessions. By introducing microlearning or e-learning, you can effortlessly raise employees’ security awareness during their spare moments. Back to Table of Contents Summary In this article, we discussed internal fraud. In today’s world, where countermeasures against internal fraud are an urgent priority, companies must take steps such as thoroughly implementing employee security training. When working to improve information security awareness within your company, please take advantage of the information security training content available on “learningBOX ON.” learningBOX ON is a service that allows you to easily add essential corporate training content to learningBOX, an e-learning creation and management system. You can easily design original learning courses by combining this content with content developed in-house. Content for information security and compliance training is available free of charge, so please be sure to utilize it for your in-house training. ▼ Also Recommended! Related Articles Return to Table of Contents
blog

Handling Confidential Information at Workplace

In the course of business operations, companies handle a wide range of information related to their customers, business partners, and others. It is not uncommon for the data and documents used in business to contain confidential or sensitive information. Since the leakage of highly sensitive information outside the company could lead to serious incidents, it must be handled with care. This article explains such “confidential information” and “sensitive information.” We’ll also explain the differences between the two and discuss measures to prevent data leaks, so please use this as a reference. The Difference Between “Confidential Information” and “Sensitive Information” In business settings, the terms “confidential information” and “sensitive information” are sometimes used interchangeably. While both lack clear definitions and are easily confused, their meanings are strictly distinct. First, we’ll explain the difference between confidential information and proprietary information. The Meanings of Confidential and Proprietary Information “Confidential information” refers to information subject to confidentiality when a non-disclosure agreement (NDA) is signed. Which information qualifies as confidential is determined by agreement between the parties entering into the contract. Furthermore, the scope of confidential information varies depending on the terms of the signed agreement. On the other hand, “confidential information” refers to all information that is of significant importance to a company or a government agency. In particular, confidential information within a company is also referred to as “trade secrets” or “internal company secrets” and must be handled with care. As with confidential information, it is essential to prevent its leakage to outside parties. Types and Specific Examples of Confidential Information and Sensitive Information Although “confidential information” and “sensitive information” have different meanings, the types of information they cover are the same. Such information can be broadly categorized into five types: “management information,” “financial and accounting information,” “research, development, and technical information,” “human resources information,” and “marketing and public relations information.” Types and Specific Examples of Confidential and Sensitive Information | Type of Information | Specific Examples | Business Information | Business plans, inventory information, M&A information, etc. | Financial and Accounting Information | Budget and sales information, loan information, joint venture plans, etc. | Research and Development and Technical Information | Design drawings, research reports, project specifications, etc. Human Resources Information Salary information, promotion information, transfer information, etc. Marketing and Public Relations Information Sales history, promotional information, customer information, business partner information, etc. As a prime example, personal information regarding customers and employees is generally considered to fall under confidential or sensitive information. Generally, personal information includes data such as names, ages, addresses, and gender, as well as data such as an individual’s purchase history and website browsing history. Synonyms with meanings similar to “confidential information”: The difference between confidential information and trade secrets. While there are no clear definitions for “confidential information,” “trade secrets” are defined by law. This is explained in Article 2, Paragraph 6 of the Unfair Competition Prevention Act. Under this law, “trade secret” refers to technical or business information useful for production methods, sales methods, or other business activities that is managed as a secret and is not publicly known. [Source] “Unfair Competition Prevention Act (Act No. 47 of Heisei 5)” e-Gov Law Search Trade secrets as defined by the Unfair Competition Prevention Act must meet three requirements. The first is “confidentiality,” which corresponds to the phrase “managed as a secret.” The second is “usefulness,” which corresponds to the phrase “is useful technical or business information.” The third is “non-public nature,” which corresponds to the phrase “not publicly known.” However, information regarding antisocial activities such as tax evasion, information disclosed as a patent, and information contained in publications does not qualify as a trade secret. [Reference] “Handbook on the Protection of Confidential Information: Toward Enhancing Corporate Value” (Ministry of Economy, Trade and Industry) The Difference Between Confidential Information and “Non-Public” Information “Non-public” information refers to confidential information that could result in losses if leaked outside the company. While such information may be shared with internal employees, it cannot be shared with external parties such as business partners or consumers. Specific examples include confidential documents such as meeting minutes and employment regulations. Confidential information is categorized by level of importance, with “Top Secret,” “Secret,” and “Confidential” classified in descending order of sensitivity. Specific information classified as “Top Secret” or “Secret” is considered to pose a greater risk of loss if leaked than “Confidential,” and access is restricted to only a select few within the company. Unlike “Confidential” information, “Confidential” information does not require the signing of a non-disclosure agreement. Additionally, while “Confidential” information can be shared internally, “Confidential” information may not be shared even within the company, depending on its level of importance. The Difference Between Confidential Information and Sensitive Information Sensitive information, also known as “sensitive data,” refers to personal information that requires particularly careful handling. If such information is leaked, there is a risk that individuals could be exposed to social risks, such as discrimination, or suffer psychological harm. Specific examples of sensitive information include information regarding an individual’s political views, religious beliefs, race or ethnicity, and place of birth or registered domicile. Care must be taken when handling this information to protect individual privacy. Unlike confidential information, sensitive information is not subject to non-disclosure agreements. Furthermore, while confidential information pertains to information held by companies or government agencies, sensitive information pertains to personal information. Return to Table of Contents Risks of Leaking Confidential and Sensitive Information What dangers does a company face if confidential or sensitive information is leaked? Here, we explain the risks posed by information leaks. Risk of Losing Public Trust and Credibility The discovery and spread of a data breach is a major issue that could undermine the trust of customers, business partners, and the public. If, in the wake of a violation or incident, third parties distort the information or spread misinformation on social media, there is a risk that the company will suffer reputational damage. Losing public trust and confidence in this way could pose a serious threat to the very survival of the company. Claims for Damages May Be Filed: In the unlikely event that a data breach at your company causes some form of loss to a victim, you may face claims for damages. Even in Japan, there have been cases in the past where large-scale personal information leaks occurred, resulting in companies paying compensation to their customers. The more sensitive the information, the more severe the damage caused by a leak is likely to be, so caution is essential. Back to Table of Contents: How to Prevent Leaks of Confidential and Sensitive Information To prevent information leaks, it is essential to strictly adhere to internal rules on a daily basis and maintain a secure IT environment. Finally, here are some key points for preventing leaks of confidential and sensitive information. Restrict or Prevent the Bringing In and Taking Out of Storage Media As a general rule, prohibit the bringing into and use of media capable of storing confidential and sensitive information within the company. For example, transporting data using USB flash drives or external hard drives carries the risk of loss or theft. Similarly, it is not advisable for employees to use their personal storage media for business purposes. It is also important to establish and clearly communicate rules restricting the removal of company-issued computers and the locations where they may be used. You may also consider implementing new management methods to keep information assets secure, such as requiring employees to submit a prior request whenever they need to take a device off-site. With the increasing prevalence of remote work, there is a growing need to establish stricter rules regarding these matters. Install and Update Security Software Install security software on company computers and other devices to protect your company’s IT equipment and network from damage caused by viruses and unauthorized access. Even devices that already have security software installed must be updated regularly. Keep the software up to date through updates to prepare for new cybercrime tactics. Raising Employee Awareness of Information Security To safely store your company’s confidential and sensitive information, it is crucial that every employee understands the basics of information security and handles internal information appropriately. Please consider conducting training sessions for systematic learning about information security. When doing so, be sure to incorporate methods for assessing employee proficiency, such as utilizing an e-learning system that includes learning management features. Back to Table of Contents: Understand the Difference Between Proprietary and Confidential Information and Implement Measures for Both We have explained the difference between proprietary and confidential information handled by companies. While proprietary and confidential information have different connotations, the types of information they cover are the same. Based on the points we’ve covered, strengthen your company’s security measures and aim for safe operations. When raising awareness about information security within your company, please make use of the information security training content available on “learningBOX ON.” learningBOX ON is a service that allows you to easily add essential corporate training content to learningBOX, an e-learning creation and management system. You can easily design original learning courses by combining this content with material developed in-house. Content for information security and compliance training is available free of charge, so please be sure to utilize it for your in-house training. ▼Also Recommended! Related Articles Return to Table of Contents
blog

Enterprise Cybersecurity
How to Prevent Cyber Attacks & Threats

Data management using information systems and the Internet has become an indispensable tool for businesses. While there is no doubt about its convenience, we must once again be mindful that there is another side to this. Since data management via the Internet connects us to the entire world, there is always the potential for external attacks. Information leaks caused by unauthorized access can tarnish a company’s brand image and cause significant damage, making robust security measures a major challenge for businesses. In this article, we’ll introduce the methods and key points of security measures implemented by companies. Let’s take this opportunity to review your company’s security measures once again. What Are Security Measures? Fundamentally, security measures refer to steps taken to ensure the safe use of the Internet and computers; they are also known as “information security.” In today’s increasingly digitized world, companies and organizations store vast amounts of information on their systems, including critical business secrets and the personal information of customers and employees. If this information is leaked or data is corrupted, a company can suffer significant reputational damage; in some cases, this may even lead to a decline in business performance or bankruptcy. Companies implement various security measures to protect their information assets. Back to Table of Contents: The Three Elements of Information Security Information security—which consists of measures to prevent information leaks and data corruption—is composed of three elements: “confidentiality,” “integrity,” and “availability.” Information security is sometimes referred to as “CIA,” an acronym derived from the first letters of these elements. Let’s examine each element in a bit more detail. Confidentiality: Ensuring that only authorized individuals can access information. Integrity: Ensuring that information is accurate and free from tampering, omissions, or additions. Availability: Ensuring that necessary information is accessible when needed until the intended purpose is fulfilled. It is crucial to keep these three elements firmly in mind when handling important information. Return to Table of Contents: The Difference Between Information Security and Cybersecurity In addition to information security, there is another type of security measure known as cybersecurity. Cybersecurity refers to measures taken against threats to information security. While information security focuses on how information is handled, cybersecurity focuses on countermeasures against so-called cyberattacks and similar threats. These two are not entirely distinct; rather, cybersecurity is a concept within the broader scope of information security. Now, let’s take a closer look at specific examples of what actually threatens information security. Back to Table of Contents: Examples of Specific Security Incidents Here are four examples of actual security incidents. Example 1: Malware Infection Malware is a general term for programs or software that cause harm to a user’s device. Ransomware and Trojan horses are also types of malware. If a device becomes infected with malware, important information may be leaked to external parties, or data may be destroyed, overwritten, or lost. Example 2: Information Leaks and Theft Information leaks can occur not only due to malware infections but also unintentionally as a result of changes in the work environment, such as remote work. Additionally, there are cases where employees take home computers or data containing confidential information, which are then stolen. Specific Example 3: Unauthorized Access Unauthorized access can lead to the leakage of confidential information, service outages, or website tampering. Specific Example 4: Equipment Failures Due to Disasters Natural disasters such as typhoons, earthquakes, or lightning strikes can render servers or power supplies inoperable, causing information systems to shut down. Back to Table of Contents: Security Measures Implemented by Companies So, what kinds of security measures do companies actually implement? Let’s examine the specific countermeasures for each scenario. Countermeasure 1: Protecting Against Malware Infection Using security software is an effective way to prevent malware infections. However, don’t assume you’re safe just by installing it; be sure to update it regularly to the latest version. New malware is constantly being created and becoming more sophisticated, so relying on outdated virus definition files is dangerous. Measure 2: Measures Against Data Leaks and Theft In addition to using security software, it is important to raise employee security awareness through training and other initiatives. Establish rules regarding the removal of documents and computers from the premises, and set certain restrictions on how employees handle information. Measure 3: Measures Against Unauthorized Access System vulnerabilities are the root cause of unauthorized access. To prevent unauthorized access, ensure proper account management and implement encryption technology. Additionally, installing a firewall to block unauthorized access is an effective measure. Measure 4: Measures Against Equipment Failures Due to Disasters and Other Events Natural disasters are unpredictable. It is necessary to take proactive measures on a daily basis, such as performing frequent backups and deploying backup systems. Data backups should be stored in a separate location. Furthermore, important documents should be kept in a safe or similar secure location to protect them from disasters. Return to Table of Contents: Information Security Measures SMEs Should Prioritize Information security measures are not just for large corporations. Small and medium-sized enterprises (SMEs) also need to implement robust security measures. However, implementing a wide range of information security measures, as large corporations do, is not realistic for small and medium-sized enterprises, which often lack sufficient budgets and personnel. So, where should you start? Below are three high-priority measures that can be implemented even with a limited budget. ① Strengthen PC Security Update software, such as the operating system, frequently to keep it up to date. We also recommend installing security software. Business-grade security software allows for centralized management of all company devices. It is recommended because it enhances the security of company computers by restricting access to non-work-related websites and limiting connections to external storage devices. ② Thorough Employee Training Security measures are meaningless unless every employee adheres to them. To ensure information security, it is essential to raise the awareness of each and every employee. Training is an effective way to thoroughly instill security knowledge in employees. Prevent information leaks by thoroughly educating employees on topics such as measures to prevent accidental email sending, avoiding weak passwords, not clicking on suspicious URLs, and proper use of social media. ③ Measures for Remote Work: While remote work has become widespread in recent years, working outside the office carries risks such as data leaks and virus infections. First, establish internal rules regarding the handling and removal of data during remote work. In addition to ensuring that antivirus software is installed on devices used for remote work, strictly enforce the use of secure connections when accessing the network. Make sure everyone is aware that using public Wi-Fi and similar networks poses a risk of virus infection and data leaks. Return to Table of Contents Summary In today’s increasingly digitized world, information systems and the Internet are indispensable for any company. While they offer significant convenience, it is important to be mindful of the associated risks, such as data leaks. If a system malfunctions and services are interrupted, the company’s reputation could be damaged, and business performance could be affected; therefore, robust and reliable countermeasures are essential. Information security covers a wide range of areas, including measures against unauthorized access, malware, and natural disasters; however, the first step is to thoroughly educate employees. Let’s raise employee awareness of information security and protect our company’s data. When disseminating information about information security within your company, please make use of the information security training content available on “learningBOX ON.” learningBOX ON is a service that allows you to easily add essential corporate training content to learningBOX, an e-learning creation and management system. You can easily design custom training courses by combining this content with materials created in-house. Content for information security and compliance training is available free of charge, so we encourage you to utilize it for your in-house training. ▼ Also Recommended! Related Articles Return to Table of Contents
blog

Data Breaches Threats and Countermeasures

In recent years, many companies have come to recognize that the risk of data breaches lurks right under their noses. This is because cybercrime tactics are becoming more sophisticated every year, and any company can potentially become a target. Additionally, there are cases where data breaches occur due to human error within the company, often stemming from a lack of employee training. Here, we will explain the risks that such data breaches pose to companies, measures to prevent them, and the response procedures to follow if one occurs. Let’s take this opportunity to review your company’s data breach prevention measures. List of Risks Posed by Data Breaches In recent years, stronger measures have become necessary to mitigate the risk of data breaches. Conventional security measures alone are often insufficient, and there have been numerous cases where serious data breaches have occurred. Contributing factors include the widespread adoption of remote work due to the spread of COVID-19 and the increasing use of mobile devices, including business-use smartphones and tablets. According to a survey by the IPA (Information-technology Promotion Agency), “attacks targeting new normal work styles such as remote work” have been ranked as a new information security threat since 2021. First, we’ll present a list of risks to watch out for. [Reference] “Top 10 Information Security Threats 2021” (Information-technology Promotion Agency, Japan) List of Risks Associated with Information Leaks Category Risk Examples of Actual Incidents Primary Risk Becoming a victim of impersonation or unauthorized use ・ Unauthorized use of customers’ credit cards ・ Hijacking of corporate social media accounts ・ Dissemination of phishing emails impersonating the company Facing Damages and Criminal Penalties ・ Offenders face up to one year in prison or a fine of up to 500,000 yen ・ Payment of 10,000 yen to each victim ・ Distribution of 500-yen gift certificates to all victims Website Defacement ・ Unintended advertisements are displayed ・ Users are automatically redirected to other sites ・ Visitors are infected with malware Secondary Risks Loss of social credibility ・ Business transactions with key customers are suspended ・ Market share shrinks ・ Negative reputation spreads on social media This leads to employee anxiety and distrust ・ An increase in resignations ・ Deterioration of the workplace atmosphere. Victimization by identity theft and unauthorized use. Identity theft occurs when a third party impersonates another person online to commit fraud. This leads to incidents where personal information—such as IDs, passwords, and email addresses—is misused. There are concerns about incidents such as emails impersonating the company being circulated, unauthorized use of customers’ credit cards, or the company’s social media accounts being hijacked. Liability for Damages and Criminal Penalties If a personal information leak is discovered, the company may face corrective orders or fines from the government. The amendments to the Personal Information Protection Act, which took effect in April 2022, strengthened these corrective orders and fines. Violating a corrective order is punishable by up to one year in prison or a fine of up to 1 million yen. In addition, data breaches may give rise to civil liability for damages. This is because a data breach constitutes a tort—an unlawful act that infringes upon the rights or interests of others. Furthermore, in some cases, companies have paid compensation in the form of gift certificates, electronic money, or reward points, separate from any monetary damages awarded. [Reference] “Regarding the Revised Personal Information Protection Act of Reiwa 2” (Ministry of Internal Affairs and Communications) Website Tampering There is a risk that malicious third parties will exploit vulnerabilities in a website to gain unauthorized access and tamper with its content without the owner’s knowledge. Caution is required because tampering can result in the display of advertisements unrelated to the company’s business, as well as tactics that redirect users to fake websites or infect their devices with malware. Damage to Social Credibility: Data breaches undermine trust from business partners and customers, leading to a decline in social credibility and brand image. There are also concerns about reputational damage on social media and a drop in stock prices. If the incident leads to an unavoidable suspension of business operations or service provision, it could result in significant financial losses. Leading to Employee Anxiety and Distrust Data breaches also have a significant impact within the company. Employees may begin to feel anxious or distrustful toward the company, which can easily lead to a decline in motivation at work. It is also important to note that the external response following an incident can lead to overwork and accumulated stress, which may result in an increase in employee turnover. Back to Table of Contents: Main Causes of Data Breaches and Examples of Measures to Reduce Risks What are the primary causes of data breaches in companies? Implement countermeasures tailored to each cause to ensure thorough information management within the company. Main Causes of Data Leaks The causes of data leaks can be broadly categorized into three types: “leaks due to internal human error,” “intentional leaks from within the company,” and “leaks resulting from external attacks.” To prevent data leaks before they occur, it is necessary to implement measures from multiple angles depending on the cause. Causes, Sources, and Contributing Factors of Information Leaks Category Main Causes Source Contributing Factors Internal Human Error ・ Leaving items behind or losing them ・ Careless conversations or social media posts ・ Errors in email or system operations ・ Full-time employees ・ Former employees ・ Contract workers ・ Part-time and temporary employees ・ Vendors and contractors, etc. ・ Carelessness, lack of knowledge, etc. Intentional: Unauthorized removal of data, unauthorized system manipulation, financial motives, distrust or dissatisfaction with the organization, etc. External: Malicious attacks, cyberattacks, malware infections, eavesdropping or theft, lone perpetrators or organized crime, pranksters, Domestic/International Offenders, etc. [By Cause] Examples of Measures Against Information Leaks Human errors—such as “loss or misplacement,” “operational errors,” “management mistakes,” and “theft”—account for over 60% of information leak causes. These figures were published in a 2018 survey conducted by the Japan Network Security Association. [Reference] “2018 Survey Report on Information Security Incidents” (Japan Network Security Association) Based on these results, it can be said that a relatively large number of data breaches could be prevented depending on employees’ knowledge and awareness of security information. Measures such as conducting regular training and establishing guidelines and rules are effective. The table below summarizes effective information security countermeasures by cause of human error. Please refer to it for guidance. Causes of Data Breaches Due to Human Error and Examples of Countermeasures Cause Examples of Countermeasures Management Errors ・ Do not connect personal computers to the company network ・ Always shred paper documents before disposal ・ Use separate email addresses for work and personal use ・ Do not leave your work computer unlocked when stepping away from your desk. Operational Errors ・ Implement a system to prevent accidental email sending. Implement a system to prevent accidental email sending. ・ Encrypt data before sending. Leaving Items Behind, Loss, Eavesdropping, and Theft ・ Do not leave belongings on train overhead racks. ・ Do not take company information home. ・ Do not use portable storage devices such as USB drives. • Do not post work-related information on social media. • Do not discuss work in public places such as elevators or bars. Return to Table of Contents Response Flowchart to Mitigate Risks in the Event of an Information Leak If an information leak occurs at your company, respond promptly by following the flowchart below. Finally, here is a response flowchart you should review in preparation for emergencies. Step 1: Assess the Situation and Report Immediately If you notice any signs of a data breach or identify its impact after it occurs, report it immediately to the person in charge. First, led by the person in charge, establish an internal response structure and define the policy and details for the initial response. At this time, please be careful not to inadvertently operate any devices, as this could destroy evidence that might be crucial for determining the cause. For example, do not delete any emails or files related to the incident. Step 2. Initial Response to Mitigate Secondary Damage Next, implement emergency measures to prevent the data breach from escalating and to mitigate secondary damage. Depending on the situation, measures such as temporarily suspending services may be considered. In the case of a personal information leak, it may also be necessary to contact the affected individuals and request that they change their passwords or suspend their use of the service. Step 3. Investigating the Cause and Disclosing Information: Conduct an investigation into the facts, identify the cause of the data breach, and then disclose accurate information. It is crucial to release information that is well-founded and highly reliable. Be careful to avoid releasing information that could cause confusion, such as vague details or speculation. Step 4. Reporting to Relevant Parties and Public Disclosure To fulfill its accountability regarding the data breach, the company must report the incident to relevant parties and make a public disclosure. In addition to notifying business partners and customers, it is also necessary to file reports with regulatory authorities, the police, and the IPA (Information-technology Promotion Agency). The timing of the public announcement should be determined after carefully considering whether there is any risk of the damage spreading further. Step 5. Development and Implementation of Measures to Prevent Recurrence Once the initial response is complete and business operations and services have been restored, the company must implement measures to prevent recurrence. Identify issues based on the causes of the data breach, implement countermeasures, and address matters such as compensation for victims and disciplinary actions against employees. Note that, depending on the content of the public announcement regarding recurrence prevention measures, there is a risk that third parties may become aware of vulnerabilities; therefore, carefully consider the scope of the disclosure. [Reference] “Key Response Points in the Event of a Data Breach” (Information-technology Promotion Agency, Japan) Return to Table of Contents Preparing for the Risk of Data Breaches We have introduced measures to prepare for the risk of data breaches and a response workflow to minimize damage. Human error by employees accounts for the majority of data breach causes. Enhancing in-house information security training is believed to help reduce these risks. Be sure to prioritize employee training to prepare for any potential incidents. When raising awareness about information security within your company, please make use of the information security training content available on “learningBOX ON.” “learningBOX ON” is a service that allows you to easily add essential corporate training content to “learningBOX,” an e-learning creation and management system. You can easily design original learning courses by combining this content with content developed in-house. Content for information security training and compliance training is available free of charge, so please be sure to utilize it for your in-house training. ▼ Also Recommended! Related Articles Return to Table of Contents
blog

Data Security Training with Elearning to Employees

Information leaks at companies are often caused by a lack of employee awareness, making information security training increasingly important. When aiming to reinforce knowledge through in-house training, we recommend utilizing an e-learning system. In this article, we’ll share examples of content for conducting information security training via e-learning and provide guidance on how to choose a service. We’ll also introduce services and resources that can help with content creation, so please use this as a reference. Types of E-Learning Content for Information Security Training Information security training is typically conducted through in-person sessions or e-learning. Since e-learning content for information security training covers a wide range of topics, you should select and prepare appropriate content based on your training objectives and budget. Examples of Information Security e-Learning Content Security incidents, including personal data breaches, can occur regardless of job function. The causes range from the loss of information assets to cyberattacks. Therefore, when conducting information security training, it is advisable to target all employees, regardless of their employment status or job title. The following is a list of examples of e-learning content for information security training. Understanding the Personal Information Protection Act and the Proper Handling of Personal Information; Rules and Risks of Social Media Use; Compliance; Threats from Targeted Phishing Emails and Countermeasures; The Importance of Information Asset and Device Management; Recent Cases of Information Security Incidents; ID and Password Management; The Importance of Supply Chain Security; Security Risks Associated with Cloud Service Use; Return to Table of Contents; e-Learning Content for Information Security Training Content: E-learning for information security training is available from a variety of services. What criteria should you use to select the right content to enhance company-wide security awareness through employee training? Here, we explain the key points for selecting e-learning for information security training. General-Purpose vs. Specialized Learning Areas: E-learning content is categorized into “general-purpose” and “specialized” types depending on the service provider. General-Purpose: General-purpose e-learning is characterized by offering a wide range of learning areas that are in high demand among companies. The content includes not only information security training but also business etiquette and harassment prevention training. If you want to select learning areas from a broad range of options based on your current needs, general-purpose e-learning is recommended. Specialized: Specialized e-learning services are characterized by offering content focused on specific areas. Therefore, specialized services are recommended if you want to improve the quality or frequency of training in a particular subject area. A typical example is a company that has established a policy to intensively strengthen information security training over the medium to long term. Based on your company’s specific information security challenges, choose a service that offers the learning areas you prioritize. Is Content Customization Flexible? The level of customization available in e-learning services varies by provider. Specifically, services can be categorized into two types: those where you use the provider’s original content without modification, and those where you can customize the content to suit your company’s needs. To optimize information security training content for your company, we recommend implementing a service that offers flexible content customization. Employee literacy levels and the specific expertise required for their roles vary from organization to organization. By choosing a service with excellent customization capabilities, you can refine training content based on employee understanding and participation, enabling continuous information security education. Do the Pricing Structure and Costs Fit Your Budget? The pricing structures and costs of e-learning services vary by provider. Specifically, there are services available for free, subscription-based models with monthly fees, one-time purchase models requiring only an initial fee, and models where a fee is charged each time a course is taken. When implementing an e-learning service, secure your budget in advance and verify that the pricing structure and costs of the service you are considering align with it. It is also important to actively take advantage of free trials to assess usability and cost-effectiveness. Back to Table of Contents: Useful Information for Information Security Training via e-Learning Finally, we will introduce content and services that are useful when conducting information security training via e-learning. Choose the service that best suits your needs based on the required features, scale of use, and frequency of use. IPA “Information Security Measures Support Site” The IPA (Information-technology Promotion Agency), which falls under the jurisdiction of the Ministry of Economy, Trade and Industry, makes materials related to information security measures available to the public. The IPA is an organization engaged in activities such as human resource development aimed at strengthening Japan’s competitiveness in the IT sector. This page introduces specific security measures tailored to various purposes and situations, such as web conferences, remote work, and extended holidays. You can download these materials for use as training or handout resources. Since they can be easily viewed without logging in, it’s a good idea to take a look. [Reference] Security Measures Guide | IPA (Independent Administrative Institution, Information-technology Promotion Agency) Ministry of Internal Affairs and Communications “Cybersecurity Site for the Public” This is a website operated by the Ministry of Internal Affairs and Communications that provides basic knowledge and measures for information security. For measures within companies and organizations, the curriculum is divided by role—such as executives, employees, and information management staff—making it easy to use even when conducting company-wide training. Additionally, the page features videos and materials from past online courses on information security measures. Since the PDF materials can be downloaded and distributed, they will help reinforce knowledge. [Reference] Cybersecurity Site for the Public | Ministry of Internal Affairs and Communications e-Learning System “learningBOX” learningBOX is a learning management system that enables companies to conduct employee training online. It covers all the functions necessary for e-learning—including the creation of training materials and tests, grading, and management of training history—and is useful for developing in-house information security training programs. Additionally, by using “learningBOX ON,” you can add existing training content to learningBOX. You can access content—including information security training, as well as harassment prevention, business etiquette, and compliance training—free of charge, and easily design original learning courses by combining it with your company’s own content. Up to 10 accounts can participate for free, so please feel free to give it a try when implementing information security training via e-learning. Back to Table of Contents: Boost Learning Efficiency by Implementing Information Security Training via E-Learning In this article, we’ve explained how to select content and services when implementing information security training via e-learning. In today’s world, where information management risks are becoming increasingly complex and diverse, companies are required to actively invest in information security measures. In-house training is one such measure, and conducting it via e-learning makes it possible to provide content tailored to employees’ literacy levels and job roles. Use e-learning for information security training to both reinforce knowledge and improve learning efficiency. With learningBOX ON, you can access not only information security training but also essential in-house training content—such as harassment prevention and compliance training—for free, so please make full use of it for your company’s training programs. ▼ Also Recommended! Related Articles Return to Table of Contents
blog

9 Ways to Prevent Information Leakage

Although the advent of the digital age has highlighted the importance of information management, there are still many cases where delays in taking appropriate action lead to data breaches. When a data breach occurs at a company, it can not only damage its reputation but also lead to situations that threaten the very survival of the business, such as claims for damages. To mitigate these risks, it is essential to implement preventive measures in advance. Therefore, this article explains the key points of data breach prevention measures and the main causes of such breaches. Specific Measures and Key Points for Preventing Data Breaches Companies manage a large amount of highly confidential information, and once a breach occurs, the consequences—such as a loss of trust from business partners and the payment of substantial damages—can be incalculable. To prevent such situations, implement data leak countermeasures by referring to the points below. Specific Examples and Key Points for Data Leak Countermeasures Target Specific Examples and Key Points Employees Establish guidelines and rules Conduct regular information security training Restrict or Prohibit the removal or bringing in of information and equipment Implement a system to prevent accidental email sending Prohibit the careless abandonment or disposal of information Prohibit the inadvertent disclosure of information to others External Parties Strictly manage information such as IDs and passwords Install and update security software Perform regular system updates and vulnerability checks Information Leak Prevention Measures for Employees・ Key Points: Establish guidelines and rules. To prevent human error, it is necessary to create and enforce rules in accordance with company-wide guidelines. Align the policies set by management with operational challenges on the ground through a two-way dialogue. When doing so, it is advisable to refer to the guidelines published by the IPA (Information-technology Promotion Agency). [Reference] “Guidelines for Information Security Measures in Small and Medium-Sized Enterprises, 3rd Edition” (Information-technology Promotion Agency, Japan) Conduct regular information security training It is also important to conduct regular information security training to enhance employees’ knowledge and awareness of information security. By ensuring that employees are constantly aware that they are always at risk of information leaks, regardless of their job duties, you can improve their security awareness. It is generally easier to mitigate risks by including all individuals involved in business operations—regardless of their employment status—in training programs. Restrict or Prohibit the Removal or Bringing In of Information and Devices To prevent information leaks caused by loss or theft, it is important to restrict or prohibit the removal of information assets and the bringing in of personal items. Additionally, operational rules must be established in preparation for cases where removal or bringing in is unavoidable, or when telework is implemented. Specifically, possible measures include requiring approval from a supervisor and limiting the types of information and devices that may be authorized for removal or bringing in. Implement a system to prevent accidental email sending To proactively prevent information leaks caused by accidentally sending emails or errors in attachments, implementing a system to prevent accidental sending is effective. These systems include features such as automatic sending only after approval by a supervisor, automatic CCing of recipients, and pre-send verification, all of which help strengthen information management systems. Prohibit Careless Leaving or Disposal of Information To prevent the leakage of confidential information, it is necessary to prohibit the careless leaving or disposal of information. This is because if information is left accessible to anyone or discarded in a way that allows it to be retrieved or read, it could be exploited by malicious third parties. Establish rules such as ensuring documents and computers are not visible from outside the workspace when stepping away, and physically destroying electronic media and credit cards before disposal. Prohibit Careless Disclosure of Information Even if information is handled and disposed of properly, leaks can still occur if employees disclose it verbally. Specifically, this includes cases where employees leak information obtained within the company via social media, blogs, or conversations with employees of other companies. Therefore, when conducting internal training on information security, it is crucial to instruct employees to strictly adhere to confidentiality obligations. Return to Table of Contents Key Measures to Prevent Information Leaks to External Parties Strictly Manage IDs, Passwords, and Other Information To avoid increasingly sophisticated external attacks, it is essential to strengthen the management of IDs and passwords. Be sure to strictly enforce basic precautions, such as avoiding easily guessable strings (like names), not reusing credentials, and not storing them in places visible to outsiders. Install and Update Security Software Installing security software is an effective measure against personal information leaks caused by cyberattacks. It can address new attack methods that are difficult to counter with standard OS features, thereby reducing the risk of security incidents. To stay ahead of constantly evolving attack methods and viruses, it is also important to remember to update your definition files. Perform Regular System Updates and Vulnerability Checks It is not uncommon for external attacks to target vulnerabilities in systems or applications. Therefore, to prevent information leaks by unauthorized parties, it is necessary to perform regular system updates and vulnerability checks. If a vulnerability is discovered, assess its severity and potential impact, and then take appropriate measures—such as implementing new security tools, suspending system use, or making system modifications. Return to Table of Contents: Main Causes and Contributing Factors of Data Leaks The main causes of data leaks can be categorized as human error or intentional misconduct by internal employees, and malicious attacks from external sources. Here, we will outline specific examples and contributing factors for each. Causes, Sources, and Contributing Factors of Data Breaches Category Main Causes Source Contributing Factors Internal Human Error ・ Leaving items behind or losing them ・ Careless conversations or social media posts ・ Incorrect use of email or systems ・ Full-time employees ・ Former employees ・ Contract workers ・ Part-time and temporary employees ・ Vendors and contractors, etc. ・ Carelessness, lack of knowledge, etc. Intentional: Unauthorized removal of data, unauthorized manipulation, financial motives, distrust or dissatisfaction with the organization, etc. External: Malicious attacks, cyberattacks, malware infections, eavesdropping or theft, lone perpetrators or organized crime, prank attacks, Domestic/international perpetrators, etc. Information leaks due to internal human error The main causes of information leaks due to internal human error include leaving behind or losing computers, documents, USB drives, and other storage media, as well as email errors such as sending to the wrong recipient or attaching the wrong file. Information may also leak due to careless conversations in public places. For example, caution is necessary in locations such as office building lounges, elevators, cafes, and bars, as there is a possibility that third parties may overhear your conversation. Statements such as “Our company is planning to go public soon…” “Next year’s new product will feature XX technology…”—statements like these should be avoided. Furthermore, careless posts on social media—such as sharing confidential information prior to its official release or posting customers’ personal information—can also lead to data leaks. Even when posting anonymously, one must be aware of the risk that the poster’s identity or the organization they belong to could be identified based on the content of the post. Intentional Internal Information Leaks: Intentional internal information leaks may include cases where information is taken by former employees. This can be driven by financial reasons or distrust and dissatisfaction with the organization. Information Leaks Due to External Attacks: The primary causes of information leaks resulting from external attacks are unauthorized access and malware infections. Malware refers to malicious programs or software that cause device malfunctions or information leaks. It can lead to the leakage of personal or customer information, as well as the misuse of IP addresses. Please also be aware of cases where information leaks occur due to eavesdropping in the office or theft resulting from unlawful entry. Return to Table of Contents: Response Methods and Procedures in the Event of a Data Breach In the unlikely event of a data breach, prompt action is required to minimize the damage. Here, we explain the response procedures step by step. Step 1. Assess the Situation and Report Immediately First, if you notice any signs of a data breach or its effects, report it immediately to the person in charge. Establish a response framework led by that person, along with the policy and details for the initial response. It is crucial to avoid careless actions—such as deleting emails or files—to prevent the destruction of evidence that could help identify the cause. Step 2. Initial Response to Minimize Secondary Damage Next, implement emergency measures to prevent the data breach from spreading and to minimize secondary damage. Countermeasures such as network isolation or service suspension may be considered. In the event of a personal information leak, you may need to contact the affected individuals and ask them to change their passwords or suspend their use of the service. Step 3. Investigating the Cause and Disclosing Information: In the next step, investigate the cause of the data breach. Examine the facts surrounding the breach using the 5W1H framework and make every effort to secure evidence. Additionally, once countermeasures have been clearly defined, the company is required to promptly disclose the information to help reduce similar incidents. Step 4. Reporting to Relevant Parties and Public Disclosure Next, consider whether it is necessary to report the incident to business partners, consumers, and relevant government agencies, or to make a public announcement. If transaction information or personal information has been leaked, the basic procedure is to notify business partners and the individuals concerned—unless there is a specific reason not to—and to offer an apology and warn them about the risk of secondary damage. If the number of affected parties or cases is extensive and individual notifications are impractical, the incident may be announced via the company’s website or at a press conference. Additionally, if criminal activity is suspected—such as demands for money or unauthorized access—report the matter to the police immediately. Step 5. Review and Implementation of Measures to Prevent Recurrence Finally, review and implement measures to prevent the recurrence of data breaches. This stage also involves reviewing compensation for damages to the affected parties and disciplinary actions against internal employees based on the investigation report. [Reference] “Key Response Points in the Event of a Data Breach” (Information-technology Promotion Agency, Japan) Return to Table of Contents Implement Data Breach Countermeasures to Reduce Security Risks Data breaches are a risk that can occur at any company. Since there are various possible causes—such as errors by internal employees or external attacks—comprehensive measures must be taken to prevent leaks before they occur. Take this opportunity to implement information leak countermeasures and work to reduce security risks. When raising awareness of data leak prevention measures within your company, please use the “learningBOX ON” information security training program. “learningBOX ON” is a service that allows you to easily add essential corporate training content to “learningBOX,” an e-learning creation and management system. You can easily design original training courses by combining this content with content developed in-house. You can access content for information security training and compliance training free of charge, so please make full use of it for your in-house training. ▼Also Recommended! Related Articles Return to Table of Contents
Find more about learningBOX