Loading
Web & Email Security Assessment for a Travel Company
Case Study  ·  Cyber Security

Web & Email Security Assessment for a Travel Company

We reviewed our client's web server that hosts the website and email applications to identify and mitigate security risks.

Scroll

Case Study: Web & Email Security Assessment for a Travel Company

A travel company was constantly receiving a vast amount of unsolicited emails that were flooding the company’s mailbox and negatively impacting staff productivity and communication with clients. They required a review of their website and server to mitigate the risk of a security breach.

The Challenge

To reduce spam email that was being successfully delivered through forms on the official website and conduct a review of its security configurations.

Our Approach

On the server side, we reviewed the server configuration and implemented spam filters, domain privacy protection, and DMARC enforcement. On the frontend, we implemented CAPTCHA challenges and obfuscated plaintext contact information. Finally, we conducted spam simulations and security awareness training for staff to mitigate the risk of breaches from unsolicited emails in addition to reduction of spam successfully delivered to the inbox.

Key Results Achieved

  1. There was a significant reduction in the spam emails received, particularly from bad bots.
  2. Employees became aware of social engineering attacks and gained the necessary skills to identify phishing and scam emails.
  3. The company adopted a zero-trust approach in relation to information security.

Key Terms

DMARC - Domain-based Message Authentication, Reporting and Conformance
CAPTCHA - A challenge-response test used to distinguish human users from bots
SETA - Security Education, Training, and Awareness
Obfuscation - Information-hiding technique
Config - Configuration

Summary of Focus Areas

57%

Web Server Audit

29%

Email Server Audit

14%

Internal Process Audit
Key Procedures Performed
Blacklisting
Spam Filtering
Server Config Review
Bad Bot Management
Security Education
Obfuscation
Next — Digital Forensics Digital Forensics & Fraud Invesgitation for INGO
Services That May Interest You

Leverage Our Expertise to Solve Similar Challenges in Your Business

arrow_outward
Web & Email Security Assessment
arrow_outward
Managed Vulnerability Disclosure Program (VDP)
arrow_outward
Cyber Security Incident Response