1. Home
  2. Computing & Technology
  3. Internet / Network Security

Protect Your Business From Phishing Scams

5 Simple Steps For Companies To Avoid Being Phishing Victims

By Tony Bradley, CISSP-ISSAP, About.com

Businesses are victims of phishing scams as well. Companies need to take steps to protect their domains and their reputations from being exploited for phishing attacks.

“Companies that are concerned about their customers being attacked with phishing scams should CLEARLY and frequently announce or publish their policy on customer communications. My satellite service provider, for example, sends out an Email saying "We will never contact you and ask you for credit card information or account information. If there is a problem with your account you can contact us via the support number listed on our website... etc." according to Marcus Ranum.

Ed Skoudis agrees with that and went into some further detail, defining the following five steps that companies can take to protect their customers and try to ensure they are not targeted by phishing scams:

  1. Never EVER EVER send unsolicited e-mail to clients asking them for their userID and password, or having them login to the site. They should have a strict policy about this.

  2. Educate your users about the policy above.

  3. Make it easy for users to report phishing scams, and work diligently to get phishing sites shut off. Typically, you can work with the ISP that gives the phishing website Internet connectivity.

  4. Keep your web application secure. We're starting to see Cross-Site Scripting attacks used in conjunction with phishing, so make sure your XSS defenses are sound.

  5. A popular attack lately is to direct the user to a legit site, and then pop a frame up on top of that site that belongs to the phisher. Prevent phishers from popping frames up on top of your legit pages to fool users, by incorporating this script at the top of every page you serve:

    <script>if(frames){if(top.frames.length>0)
    top.location.href=self.location;}</script>

Explore Internet / Network Security

More from About.com

  1. Home
  2. Computing & Technology
  3. Internet / Network Security
  4. Email and Phishing Security
  5. Protect Your Business From Phishing Scams

©2008 About.com, a part of The New York Times Company.

All rights reserved.